Business Wire

REALVNC

9.6.2022 15:02:03 CEST | Business Wire | Press release

Share
RealVNC Becomes First and Only Remote Access Solution to Complete White Box Audit to Validate Security

VNC Connect by RealVNC, the remote access service used by hundreds of millions of people worldwide, was audited by Cure53 , the Berlin, Germany-based IT security consultancy who have also audited other industry leading software such as Mozilla VPN, 1Password and Bitwarden. The comprehensive audit, which took 86 person days and included VNC Server and VNC Viewer on Linux, Windows and Mac, VNC Viewer for iOS and Android, the VNC Connect management portal and backend services, found 38 security-relevant discoveries, none of which were critical and only three were deemed high severity, and these were fixed immediately. The report states, in conclusion, that RealVNC places a strong focus on the security posture of all its components.

“As the technologists responsible for bringing remote access to the mass market, we are today setting new standards and expectations for security in the face of the challenges of the modern IT environment. IT buyers of remote access technologies should expect no less than independent and comprehensive third-party validation of vendor claims. This is especially true for remote access software where the stakes are high, and a mistake could be reputationally damaging or even existential. With Cure53’s report, buyers can be confident that choosing RealVNC as their remote access vendor will never be a regret,” said Adam Greenwood-Byrne, CEO of RealVNC.

A white box security audit is significantly more in-depth than the more common black box penetration test (which RealVNC also commissions by an external organization annually), as the auditors have access to all of the source code, binaries and API/protocol documentation. Of the 38 vulnerabilities found across the range of software and services tested, 32 have been properly addressed — with the fixes confirmed by Cure53 — while the other six were flagged as either false-alerts or works-as-intended and evaluated to be of lower risk.

“At RealVNC, we operate from the standpoint that no company should ever take a vendor’s word for it when they claim their software is secure, which is why we chose to complete a white box audit with a highly regarded security consultancy to prove it,” said Andrew Woodhouse, CIO of RealVNC.

The Cure53 team is highly motivated to find issues when completing white box penetration tests. The fact that no critical threats were found reinforces RealVNC’s focus on ensuring its customers remain safe from threats when using VNC Connect.

“Cure53 is happy to state that test preparation, test execution and also the fix verification, which is one of the most important parts of such an audit, went smoothly and professionally. It is clear that RealVNC has demonstrated a genuine interest in ensuring VNC Connect's security and is prepared and committed to maintaining the high standards we have observed,” said Dr.-Ing. Mario Heiderich, Founder of Cure53.

Headquartered in Cambridge, RealVNC's products for desktop, mobile and embedded platforms make it easy for users to access and operate devices remotely while enabling remote users to work with technicians to resolve problems easily.

“We’re not shying away from any of the issues the report found. We actively fixed issues as they came up and, as security is an ever changing landscape, we’ll continue to ensure the security of VNC Connect in future iterations of the service,” said Ben May, Head of Cyber Security at RealVNC.

To review Cure53's summary of the audit, click here , and to learn more about why RealVNC chose to conduct a Cure53 audit, click here .

ABOUT REALVNC

RealVNC’s secure remote access and management software is used by hundreds of millions of people worldwide. Their software helps organizations cut costs and improve the quality of supporting remote devices and applications, as well as enabling remote working. RealVNC is the original, UK-based, inventor of VNC remote access software and they support an unrivaled mix of desktop, mobile and embedded platforms.

ABOUT CURE53

Cure53 offers classic black-box penetration tests (zero-knowledge) as well as white-box tests and code audits. Web application and mobile app developers speak many languages and so do we. From classic languages such as PHP, JavaScript, ActionScript, Java, Ruby, Python and Perl to more exotic candidates like web back-ends written in C++ and Delphi – we've seen them.

Since Cure53 was founded in 2007, we have performed hundreds of penetration tests against all kinds of web applications, online services, hardware interfaces, mobile applications, libraries and crypto tools. We value manual and thorough tests, human interaction and communication and a short yet-to-the-point penetration test report without overhead or pie charts no one wants to see.

Link:

ClickThru

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Incode Acquires Identiq to Expand Its Privacy-First Architecture for Identity and Fraud Prevention25.6.2026 15:00:00 CEST | Press release

Extends its privacy-by-design architecture with Identiq’s patented cryptographic technology that enables organizations to share fraud signals without sharing sensitive data. Incode Technologies, a global leader in AI-powered identity verification and fraud prevention, today announced that it has completed the acquisition of Identiq, a company specializing in privacy-enhancing cryptographic solutions for peer-to-peer anti-fraud collaboration. Incode announced this acquisition as part of a $100 million commitment to advancing its original privacy-preserving identity infrastructure. The funds will be used to enhance on-device processing capabilities, continue R&D in privacy-enhancing technologies, and expand engineering resources and its global footprint. “We have always believed that privacy and fraud prevention are not a tradeoff, but part of the same problem, solved together or not at all,” said Ricardo Amper, Founder and CEO of Incode. “Identiq is the piece that enhances our Privacy b

Gurobi Introduces New Optimization Game Set in a Fast-Paced Coffee Shop25.6.2026 15:00:00 CEST | Press release

Gurobean, companion to the “Burrito Optimization Game” with 85,000+ plays, introduces advanced concepts like nonlinearity and uncertainty. Gurobi Optimization, LLC, the leader in decision intelligence technology, today announced the launch of Gurobean: The Coffee Optimization Game, a new educational game that brings nonlinearity, simulation, and decision-making under uncertainty to life. Following the success of the Burrito Optimization Game—which has been played over 85,000 times by learners across the world since its launch in 2022—Gurobean places players behind the counter of a virtual coffee shop, where they must make critical decisions around pricing, staffing, queue management, inventory levels, and more. The free, interactive game furthers Gurobi’s ongoing commitment to open education, teaching players: The value of mathematical optimization How quickly real-world decision problems become too complex to solve by trial and error How nonlinearity and uncertainty make outcomes hard

AllUnity and Zebec Deploy EURAU-Powered Employee Benefits and Enterprise Payment Solutions on Stellar25.6.2026 14:59:00 CEST | Press release

AllUnity and Zebec today announced the launch of an EURAU-based employee benefits and enterprise payments program on the Stellar network. The pilot program aims to expand payroll and workforce payments in AllUnity's regulated euro stablecoin across its ecosystem, including its major enterprise clients and partners. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260625883682/en/ Built on Stellar and powered by EURAU, AllUnity's regulated euro stablecoin, the program combines regulated digital currency with enterprise grade payroll and payments infrastructure purpose built for global value transfer. Employees participating in the pilot can receive benefits directly to digital wallets while accessing a growing range of spending, savings, and payment options through the Zebec platform. "Regulated stablecoins are increasingly moving from financial infrastructure to real world business applications," said Simon Babakhani, CEO of Z

2026 Esri User Conference to Focus on Creating a More Intelligent World with GIS25.6.2026 14:00:00 CEST | Press release

More Than 18,000 Attendees Expected for World's Largest GIS Conference in San Diego The 2026 Esri User Conference will be held from July 13 to 17 in San Diego, California. This year's theme is "GIS—Creating a more intelligent world." Jack Dangermond, president and founder of Esri, and Kristine Tompkins, president and cofounder of Tompkins Conservation, will be the keynote speakers in the Plenary Session. Esri, the global leader in geographic information system (GIS) technology, today announced speakers and the conference theme for the 2026 Esri User Conference. The conference will be held from July 13 to 17 at the San Diego Convention Center in San Diego, California. This year's theme of "GIS—Creating a more intelligent world" will emphasize how GIS turns the science of "where" into shared understanding and coordinated action—at the scale of communities, enterprises, and the planet. Kristine Tompkins, president and cofounder of Tompkins Conservation, will join Esri president Jack Dange

Copeland Releases FY2025 Global Impact Report Highlighting Energy Efficiency, Safety and Innovation Progress25.6.2026 14:00:00 CEST | Press release

Scope 1 and Scope 2 greenhouse gas emissions declined nearly 20%1Near-term reduction targets validated by the Science Based Targets InitiativeGlobal Total Recordable Incident Rate improved to 0.21, outperforming the industry average by over 90% Copeland, a global leader in compression technologies and controls solutions, has released its second annual Global Impact Report. The report highlights the company’s Fiscal Year 2025 (FY25) progress across environmental sustainability, workplace safety and community impact, guided by its Purpose, Performance and People pillars. Copeland has advanced its sustainability commitments through three strategic areas of focus: Performance-Driven Decarbonization: Copeland reduced Scope 1 and Scope 2 greenhouse gas emissions by 20% year-over-year, advancing toward its Science Based Targets initiative (SBTi)-validated goal of a 55% absolute reduction by FY33, using FY23 as a baseline.2 Renewable energy procurement and onsite solar generation accounted for

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye