Date: December 9, 2024
The OpenWrt team has addressed a critical flaw (CVE-2024-54143) in its sysupgrade server, which posed risks of malicious firmware being installed. Simultaneously, QNAP released patches for vulnerabilities disclosed during the Pwn2Own Ireland 2024 hacking competition. Organizations using these platforms are urged to apply updates immediately.
Source: SecurityWeek
The industry continues to consolidate as Bitsight acquires Cybersixgill for $115 million, and CrowdStrike announces a $300 million acquisition of Adaptive Shield. These moves highlight the increasing importance of advanced threat intelligence and security posture management in enterprise cybersecurity.
Source: SecurityWeek
A new report from Gartner identifies nine critical capabilities for cybersecurity leaders to focus on in 2024. These include harnessing generative AI, improving resilience amid hybrid work and cloud adoption, and adapting to stricter regulatory demands. The report underscores the growing complexity of managing digital ecosystems in a rapidly evolving threat landscape.
Source: Gartner
SonicWall has patched six high-severity vulnerabilities in its SMA100 SSL-VPN products. These flaws could have allowed attackers to gain unauthorized access or disrupt operations. Customers are strongly advised to update their systems without delay.
Source: SecurityWeek
SecurityWeek’s latest insights explore the dangers of deepfake technology being weaponized for business email compromise (BEC) scams. A forthcoming webinar aims to equip organizations with strategies to counteract these advanced social engineering attacks.
Source: SecurityWeek