Recent Security News

  • Urgent: GitLab Patches Critical Flaw Allowing Unauthorized Pipeline Job Execution

    September 12, 2024 at 01:12PM GitLab released security updates addressing 17 vulnerabilities, including a critical flaw (CVE-2024-6678) enabling an attacker to run pipeline jobs as an arbitrary user. This is the fourth flaw patched in the past year. Users are urged to apply the patches immediately. There is no evidence of active exploitation, but caution…

    Read More

  • UK arrests teen linked to Transport for London cyber attack

    September 12, 2024 at 12:43PM The U.K.’s National Crime Agency has arrested a 17-year-old teenager in connection to the cyberattack on Transport for London, the city’s public transportation agency. Based on the meeting notes, the key takeaways are: 1. The U.K.’s National Crime Agency has made an arrest in connection to the cyberattack on Transport…

    Read More

  • Hackers targeting WhatsUp Gold with public exploit since August

    September 12, 2024 at 12:43PM Hackers are utilizing publicly available exploit code to target two critical vulnerabilities in the WhatsUp Gold network monitoring solution from Progress Software. Based on the meeting notes, it appears that hackers have been exploiting two critical vulnerabilities in the WhatsUp Gold network availability and performance monitoring solution from Progress Software…

    Read More

  • Google Chrome gets a mind of its own for some security fixes

    September 12, 2024 at 12:04PM Google has empowered Chrome’s Safety Check to take security decisions on the user’s behalf. This feature now automatically runs in the background, revoking unneeded permissions, canceling deceptive notifications, and notifying users about security issues. It also provides more control over website permissions and extensions, aiming to improve user safety and…

    Read More

  • Transport for London confirms customer data stolen in cyberattack

    September 12, 2024 at 11:20AM Transport for London (TfL) has reported a cyberattack on September 1 which compromised customer data such as names, contact details, email addresses, and home addresses. It appears that Transport for London (TfL) has concluded that the cyberattack on September 1 has affected customer data, specifically impacting names, contact details, email…

    Read More