Month: December 2024

Adobe Patches Over 160 Vulnerabilities Across 16 Products

Adobe’s December 2024 Patch Tuesday updates address a total of more than 160 vulnerabilities across 16 products. Roughly 90 of the vulnerabilities were patched in Adobe Experience Manager. A majority are important-severity (medium based on CVSS score) and they allow arbitrary code execution. Some of the flaws can be exploited to bypass security features. CVE-2024-43711 […]

Explore More

Cleo File Transfer Tool Vulnerability Exploited in Wild Against Enterprises

Cybersecurity firm Huntress warned on Monday that an improperly patched vulnerability affecting several file transfer products from enterprise software maker Cleo has been exploited in the wild for at least the past week. Cleo is an Illinois-based company that provides supply chain and B2B integration solutions to more than 4,200 organizations.  The firm informed customers […]

Explore More

SAP Patches Critical Vulnerability in NetWeaver

Enterprise software maker SAP on Tuesday announced the release of nine new and four updated security notes as part of its December 2024 Security Patch Day. Marked as ‘hot news’, the highest severity in SAP’s notebook, the first new security note addresses three vulnerabilities in NetWeaver AS for JAVA (Adobe Document Services), including a critical […]

Explore More

Microsoft Bets $10,000 on Prompt Injection Protections of LLM Email Client

Microsoft is offering $10,000 in prizes as part of a new hacking challenge focused on breaking the protections of a realistic simulated LLM-integrated email client. The client, LLMail, includes an assistant that uses an instruction-tuned large language model (LLM) to answer questions based on emails and perform specific actions on behalf of the user. As […]

Explore More

Astrix Security Banks $45M Series B to Secure Non-Human Identities

Astrix Security, an early stage startup building technology to secure non-human identities and app-to-app connections, has bagged $45 million in a Series B funding round led by Menlo Ventures. The Tel Aviv company said the new financing included investments from Workday Ventures, Bessemer Venture Partners (BVP), CRV, and F2 Venture Capital, and brings the total […]

Explore More

Microsoft Rolls Out Default NTLM Relay Attack Mitigations

Microsoft has announced new default security protections meant to make it more difficult for threat actors to mount NTLM relay attacks against on-premises Exchange servers. As part of such attacks, threat actors target the NTLM (New Technology LAN Manager) authentication protocol by tricking the victim into authenticating to an arbitrary endpoint and then relaying the […]

Explore More

$50 Million Radiant Capital Heist Blamed on North Korean Hackers

A North Korean threat actor was responsible for the $50 million heist that Radiant Capital fell victim to in October, the decentralized finance (DeFi) project says. The incident occurred on October 16, after three developers got infected with malware and their devices were used to sign fraudulent transactions during a routine multi-signature emissions adjustment process. […]

Explore More

Let’s Work Together!
Just Drop Us a line - [email protected]

Subscribe to our Newsletter

copyright 2024 by Digital Creations LLC