Cyber-insurance and vulnerability scanning

Here’s how the results of vulnerability scans factor into decisions on cyber-insurance and how human intelligence comes into play in the assessment of such digital signals. Cyber-insurance has been an increasingly hot topic lately, with the cyber-insurance industry growing by 62 percent last year following an apparent surge in new contracts. In order to qualify … More Cyber-insurance and vulnerability scanning

Winter Vivern exploits zero-day vulnerability in RoundcubeWebmail servers

ESET Research recommends updating Roundcube Webmail to the latest available version as soon as possible. ESET Research has been closely tracking the cyberespionage operations of Winter Vivern for more than a year and, during our routine monitoring, we found that the group began exploiting a zero-day XSS vulnerability in the Roundcube Webmail server on October 11th, 2023. … More Winter Vivern exploits zero-day vulnerability in RoundcubeWebmail servers

Staying on top of security updates

Why keeping software up to date is a crucial security practice that should be followed by everyone from individual users to SMBs and large enterprises. This week, the US Cybersecurity and Infrastructure Security Agency (CISA) added five new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing solid evidence of active exploitation by attackers. The vulnerabilities, for … More Staying on top of security updates

Atlas VPN zero-day vulnerability leaks users’ real IP address

An Atlas VPN zero-day vulnerability affecting the Linux client leaks a user’s real IP address simply by visiting a website, writes Bleeping Computer*. Atlas VPN is a VPN product that offers a cost-effective solution based on WireGuard and supports all major operating systems. In a proof of concept exploit shared on Reddit, a researcher describes … More Atlas VPN zero-day vulnerability leaks users’ real IP address

360 Million Records Exposed in free VPN data breach

According to Cybersecurity Connect*,  A non-password secured database containing over 360 million records was uncovered by cyber security researcher at vpnMentor, Jeremiah Fowler, who said the records related to a VPN data breach. 360,308,817 records were exposed, totaling 133 gigabytes of data. The types of data exposed included email addresses, original IP addresses, records of … More 360 Million Records Exposed in free VPN data breach