Security News

Read about the latest security news. News about computer security malware, and other threats to your computer.

Critical flaw in Sophos firewalls enables remote code execution

A critical vulnerability in Sophos’ firewalls allows remote code execution or could give an attacker SSH access. The company has released security updates to fix the problem. The first critical vulnerability (CVE-2024-12727) allows an unauthenticated attacker to perform SQL Injection, thereby gaining access to a firewall database. If the firewall has a specific configuration and […]

Critical flaw in Sophos firewalls enables remote code execution Read More »

Microsoft Halts Rollout of Update for Exchange Server Spoofing Vulnerability

Microsoft has announced that it is stopping for the time being the distribution of a security update focused on a spoofing vulnerability in Exchange Server. This is due to customer issues that lead set transport rules to malfunction which is detrimental to mail delivery. The vulnerability (CVE-2024-49040) allows an attacker to weaponize the Exchange servers

Microsoft Halts Rollout of Update for Exchange Server Spoofing Vulnerability Read More »

Apple Under Fire for Limiting Web App Distribution to Top Developers

Apple recently unveiled a policy allowing developers to distribute iPhone apps directly from their websites, a move that has met with backlash due to its restrictive eligibility criteria. Developers are only considered for this ‘web distribution’ route if they have an app listed in the Apple App Store with over a million downloads and have

Apple Under Fire for Limiting Web App Distribution to Top Developers Read More »

Ledger Users Lose Hundreds of Thousands in Crypto to Phishing Attack

Ledger, a provider of cryptocurrency wallets, has reported a significant loss for its users. Criminals distributed a malicious version of the Ledger Connect Kit through a phishing attack on a former employee. This kit is a crucial JavaScript library that links Ledger crypto wallets to third-party applications, also known as wallet-connected websites.

Ledger Users Lose Hundreds of Thousands in Crypto to Phishing Attack Read More »

Proton Mail Launches Desktop App for Enhanced Email Experience

Proton Mail, a well-known email service provider, has expanded its offerings by launching a desktop application for macOS and Windows users. They also announced plans to introduce a version for Linux users in the early part of next year. Proton’s CEO, Andy Yen, stated that although many users typically access email through a browser on

Proton Mail Launches Desktop App for Enhanced Email Experience Read More »

Widespread Exploitation of Critical Apache Struts 2 Vulnerability

Global attackers actively exploit a severe vulnerability in Apache Struts 2, a popular open-source framework for developing Java web applications and websites. This alert comes from Australian and French authorities who anticipate widespread abuse. The Apache Foundation responded on December 7 with security updates to address this vulnerability, CVE-2023-50164.

Widespread Exploitation of Critical Apache Struts 2 Vulnerability Read More »

The Ultimate Guide to Removing Malware from Your Computer

[ad_1] The Ultimate Guide to Removing Malware from Your Computer The Ultimate Guide to Removing Malware from Your Computer Introduction Malware, short for malicious software, can have devastating effects on your computer’s performance, security, and your personal data. It can infect your system through various means, such as malicious email attachments, infected downloads, or visiting

The Ultimate Guide to Removing Malware from Your Computer Read More »