January 17, 2024: Stay updated on cybersecurity with Atlassian, Citrix, VMware & Chrome

January 17, 2024
1 min read

TLDR: Security updates have been issued for Atlassian, Citrix, VMware, and Chrome products. Vulnerabilities were found in Ivanti’s Connect Secure and Pulse Secure VPNs, Atlassian’s Confluence Server and Data Server collaboration application, and VMware’s Aria Automation products. Citrix is urging administrators to patch their installations of NetScaler ADC and NetScaler Gateway to close two vulnerabilities. Trend Micro reported that attackers are actively exploiting a Windows vulnerability to install the Phemedrone information stealer. Google has released an update for the Chrome browser to fix four security issues. The Opera browser’s My Flow feature was found to execute a malicious file outside of the browser’s security confines, highlighting the need for security to be built into every app development workflow. Bosch’s BCC100 Wi-Fi smart thermostat had a vulnerability that could allow an attacker to replace the device’s firmware with a rogue version. An unsecured database owned by an American e-commerce provider containing sensitive information was left open on the internet. The British Library’s catalogue was finally brought back online after suffering a ransomware attack last October.

Latest from Blog

Bridging the cyber talent gap: tips for CISOs

TLDR: – Global cyber threats have increased twofold in recent years, leading to a talent gap of nearly 4 million cyber professionals worldwide. – Existing cyber staff are under strain, with vacancies

North Korean hackers pivot to ransomware attacks

TLDR: North Korean hackers from APT45 have shifted from cyber espionage to ransomware attacks APT45 has targeted critical infrastructure and is linked to ransomware families SHATTEREDGLASS and Maui A North Korea-linked threat

Cyber insurance evolves to cover all your online needs

TLDR: Cyber insurance coverage is evolving to help raise security baselines across businesses. Only one-quarter of companies have a standalone cyber insurance policy. In today’s evolving cybersecurity landscape, cyber insurance coverage is