REALVNC
9.6.2022 15:02:03 CEST | Business Wire | Press release
VNC Connect by RealVNC, the remote access service used by hundreds of millions of people worldwide, was audited by Cure53 , the Berlin, Germany-based IT security consultancy who have also audited other industry leading software such as Mozilla VPN, 1Password and Bitwarden. The comprehensive audit, which took 86 person days and included VNC Server and VNC Viewer on Linux, Windows and Mac, VNC Viewer for iOS and Android, the VNC Connect management portal and backend services, found 38 security-relevant discoveries, none of which were critical and only three were deemed high severity, and these were fixed immediately. The report states, in conclusion, that RealVNC places a strong focus on the security posture of all its components.
“As the technologists responsible for bringing remote access to the mass market, we are today setting new standards and expectations for security in the face of the challenges of the modern IT environment. IT buyers of remote access technologies should expect no less than independent and comprehensive third-party validation of vendor claims. This is especially true for remote access software where the stakes are high, and a mistake could be reputationally damaging or even existential. With Cure53’s report, buyers can be confident that choosing RealVNC as their remote access vendor will never be a regret,” said Adam Greenwood-Byrne, CEO of RealVNC.
A white box security audit is significantly more in-depth than the more common black box penetration test (which RealVNC also commissions by an external organization annually), as the auditors have access to all of the source code, binaries and API/protocol documentation. Of the 38 vulnerabilities found across the range of software and services tested, 32 have been properly addressed — with the fixes confirmed by Cure53 — while the other six were flagged as either false-alerts or works-as-intended and evaluated to be of lower risk.
“At RealVNC, we operate from the standpoint that no company should ever take a vendor’s word for it when they claim their software is secure, which is why we chose to complete a white box audit with a highly regarded security consultancy to prove it,” said Andrew Woodhouse, CIO of RealVNC.
The Cure53 team is highly motivated to find issues when completing white box penetration tests. The fact that no critical threats were found reinforces RealVNC’s focus on ensuring its customers remain safe from threats when using VNC Connect.
“Cure53 is happy to state that test preparation, test execution and also the fix verification, which is one of the most important parts of such an audit, went smoothly and professionally. It is clear that RealVNC has demonstrated a genuine interest in ensuring VNC Connect's security and is prepared and committed to maintaining the high standards we have observed,” said Dr.-Ing. Mario Heiderich, Founder of Cure53.
Headquartered in Cambridge, RealVNC's products for desktop, mobile and embedded platforms make it easy for users to access and operate devices remotely while enabling remote users to work with technicians to resolve problems easily.
“We’re not shying away from any of the issues the report found. We actively fixed issues as they came up and, as security is an ever changing landscape, we’ll continue to ensure the security of VNC Connect in future iterations of the service,” said Ben May, Head of Cyber Security at RealVNC.
To review Cure53's summary of the audit, click here , and to learn more about why RealVNC chose to conduct a Cure53 audit, click here .
ABOUT REALVNC
RealVNC’s secure remote access and management software is used by hundreds of millions of people worldwide. Their software helps organizations cut costs and improve the quality of supporting remote devices and applications, as well as enabling remote working. RealVNC is the original, UK-based, inventor of VNC remote access software and they support an unrivaled mix of desktop, mobile and embedded platforms.
ABOUT CURE53
Cure53 offers classic black-box penetration tests (zero-knowledge) as well as white-box tests and code audits. Web application and mobile app developers speak many languages and so do we. From classic languages such as PHP, JavaScript, ActionScript, Java, Ruby, Python and Perl to more exotic candidates like web back-ends written in C++ and Delphi – we've seen them.
Since Cure53 was founded in 2007, we have performed hundreds of penetration tests against all kinds of web applications, online services, hardware interfaces, mobile applications, libraries and crypto tools. We value manual and thorough tests, human interaction and communication and a short yet-to-the-point penetration test report without overhead or pie charts no one wants to see.
View source version on businesswire.com: https://www.businesswire.com/news/home/20220609005211/en/
Link:
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
VerSprite Launches Fork and Knife: AI-Driven Threat Modeling and Adversarial Testing Built for the Speed of Modern Software26.6.2026 23:28:00 CEST | Press release
Powered by the risk-centric PASTA methodology and two decades of accredited offensive security, the integrated platform lets enterprises threat model in a security sprint—then prove the risk through AI-led, human-on-the-loop testing. VerSprite, a global leader in risk-based threat modeling and the firm behind the PASTA (Process for Attack Simulation and Threat Analysis) methodology, today announced the general availability of Fork (www.forktm.com), a continuous application threat modeling platform, alongside Knife, an AI-led, human-on-the-loop adversarial testing platform for web applications and web API endpoints. Together, the two products operationalize a new model for product security—one where applications are securely designed, continuously modeled, and actively tested as part of the build process itself. The launch addresses a problem every security leader knows but few tools have solved: threat modeling is essential, never more so than in an AI-driven era, yet it has remained s
Venture Global Announces Closing of $1.5 Billion Senior Secured Vessel Financing Facility26.6.2026 22:30:00 CEST | Press release
Venture Global, Inc. (NYSE: VG) announced today that its wholly-owned subsidiary, Venture Global Shipping Holdings, LLC (“VGSH”), has entered into a Credit and Guaranty Agreement providing for a senior secured term loan facility (the “Facility”) in an aggregate principal amount of up to $1,500,000,000. The Facility will mature on June 26, 2032. Deutsche Bank and ING acted as coordinating lead arrangers for the Facility. ING also serves as facility agent and security trustee. VGSH intends to use the net proceeds from the Facility for general corporate purposes, including to reimburse Venture Global LNG, Inc. for payments previously made by it or its affiliates in connection with the acquisition of nine LNG carriers, funding certain reserve accounts, and paying transaction fees and expenses. About Venture Global Venture Global is an American producer and exporter of low-cost U.S. liquefied natural gas (“LNG”) with over 100 MTPA of capacity in production, construction, or development. Ven
Andersen Consulting tilføjer House of Code for at styrke teknologi- og dataløsninger26.6.2026 20:01:00 CEST | Pressemeddelelse
Andersen Consulting forstærker sine kompetencer inden for teknologisk transformation gennem en samarbejdsaftale med House of Code, en global virksomhed med hovedkvarter i USA, der specialiserer sig i datadrevne platforme, automatisering og agentbaserede ai-løsninger. House of Code blev stiftet i 2001 og udvikler softwareløsninger samt yder rådgivning til energihandels- og finanssektoren med kunder, der spænder over hedgefonde, kapitalfonde og forsyningsvirksomheder. Virksomheden besidder dyb ekspertise inden for energihandel og risikostyring og hjælper organisationer med systemimplementering, forretningstransformation, dataautomatisering og ai-underbygget modernisering af arbejdsgange. Deres proprietære platform, Enterprise Platform for Integrated Compliance (EPIC), skaber en mere effektiv datastyring, automatiserer rapporteringsprocesser, forbedrer den driftsmæssige gennemsigtighed på tværs af virksomhedssystemer og skaber et fundament for opbygning af intelligente, agentbaserede arbe
Capco Recognized by OpenAI for Innovation and Responsible AI Leadership26.6.2026 20:00:00 CEST | Press release
Receives AI Governance & Risk Excellence Award at OpenAI Partner SummitCapco’s UK AI Lab wins OpenAI Codex Hackathon Global management and technology consultancy Capco, a Wipro company,has been recognized by OpenAI for both AI innovation and responsible AI leadership. Capco received the AI Governance & Risk Excellence Award at the recent OpenAI Partner Summit 2026 in San Francisco, highlighting Capco’s ability to deliver enterprise-grade AI outcomes in highly regulated environments. The award recognizes Capco’s expert advantage when helping financial services and energy organizations to scale AI with confidence, balancing innovation with strong governance to reduce risk, strengthen compliance and improve customer outcomes. This award follows Capco winning the OpenAI Codex Hackathon, where its UK AI Lab competed against more than 30 teams and over 100 participants from across the OpenAI partner ecosystem. Capco's winning entry Sentra – a consulting-led, AI-powered retail banking solutio
Incyte Announces Positive CHMP Opinion for Opzelura® (ruxolitinib) Cream for the Treatment of Adults with Moderate Atopic Dermatitis26.6.2026 13:30:00 CEST | Press release
If approved, Opzelura® (ruxolitinib) cream will be the first steroid-free, topical JAK treatment option in the European Union (EU) for adults with moderate atopic dermatitis (AD) for whom standard topical therapies have failedAD, the most common type of eczema which affects 230 million people globally,1 is a chronic, recurring, inflammatory and highly pruritic (itchy) skin condition that can have a significant impact on daily life2Phase 3 TRuE‑AD4 data supporting the positive CHMP opinion demonstrated that ruxolitinib cream met both co‑primary endpoints at Week 8, maintained disease control with as-needed treatment through Week 24 and was well tolerated3,4,5 Incyte (Nasdaq: INCY) today announced that the Committee for Medicinal Products for Human Use (CHMP) of the European Medicines Agency (EMA) has issued a positive opinion recommending the approval of Opzelura® (ruxolitinib) cream for the treatment of moderate atopic dermatitis (AD) in adult patients for whom topical corticosteroids
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
