REALVNC
9.6.2022 15:02:03 CEST | Business Wire | Press release
VNC Connect by RealVNC, the remote access service used by hundreds of millions of people worldwide, was audited by Cure53 , the Berlin, Germany-based IT security consultancy who have also audited other industry leading software such as Mozilla VPN, 1Password and Bitwarden. The comprehensive audit, which took 86 person days and included VNC Server and VNC Viewer on Linux, Windows and Mac, VNC Viewer for iOS and Android, the VNC Connect management portal and backend services, found 38 security-relevant discoveries, none of which were critical and only three were deemed high severity, and these were fixed immediately. The report states, in conclusion, that RealVNC places a strong focus on the security posture of all its components.
“As the technologists responsible for bringing remote access to the mass market, we are today setting new standards and expectations for security in the face of the challenges of the modern IT environment. IT buyers of remote access technologies should expect no less than independent and comprehensive third-party validation of vendor claims. This is especially true for remote access software where the stakes are high, and a mistake could be reputationally damaging or even existential. With Cure53’s report, buyers can be confident that choosing RealVNC as their remote access vendor will never be a regret,” said Adam Greenwood-Byrne, CEO of RealVNC.
A white box security audit is significantly more in-depth than the more common black box penetration test (which RealVNC also commissions by an external organization annually), as the auditors have access to all of the source code, binaries and API/protocol documentation. Of the 38 vulnerabilities found across the range of software and services tested, 32 have been properly addressed — with the fixes confirmed by Cure53 — while the other six were flagged as either false-alerts or works-as-intended and evaluated to be of lower risk.
“At RealVNC, we operate from the standpoint that no company should ever take a vendor’s word for it when they claim their software is secure, which is why we chose to complete a white box audit with a highly regarded security consultancy to prove it,” said Andrew Woodhouse, CIO of RealVNC.
The Cure53 team is highly motivated to find issues when completing white box penetration tests. The fact that no critical threats were found reinforces RealVNC’s focus on ensuring its customers remain safe from threats when using VNC Connect.
“Cure53 is happy to state that test preparation, test execution and also the fix verification, which is one of the most important parts of such an audit, went smoothly and professionally. It is clear that RealVNC has demonstrated a genuine interest in ensuring VNC Connect's security and is prepared and committed to maintaining the high standards we have observed,” said Dr.-Ing. Mario Heiderich, Founder of Cure53.
Headquartered in Cambridge, RealVNC's products for desktop, mobile and embedded platforms make it easy for users to access and operate devices remotely while enabling remote users to work with technicians to resolve problems easily.
“We’re not shying away from any of the issues the report found. We actively fixed issues as they came up and, as security is an ever changing landscape, we’ll continue to ensure the security of VNC Connect in future iterations of the service,” said Ben May, Head of Cyber Security at RealVNC.
To review Cure53's summary of the audit, click here , and to learn more about why RealVNC chose to conduct a Cure53 audit, click here .
ABOUT REALVNC
RealVNC’s secure remote access and management software is used by hundreds of millions of people worldwide. Their software helps organizations cut costs and improve the quality of supporting remote devices and applications, as well as enabling remote working. RealVNC is the original, UK-based, inventor of VNC remote access software and they support an unrivaled mix of desktop, mobile and embedded platforms.
ABOUT CURE53
Cure53 offers classic black-box penetration tests (zero-knowledge) as well as white-box tests and code audits. Web application and mobile app developers speak many languages and so do we. From classic languages such as PHP, JavaScript, ActionScript, Java, Ruby, Python and Perl to more exotic candidates like web back-ends written in C++ and Delphi – we've seen them.
Since Cure53 was founded in 2007, we have performed hundreds of penetration tests against all kinds of web applications, online services, hardware interfaces, mobile applications, libraries and crypto tools. We value manual and thorough tests, human interaction and communication and a short yet-to-the-point penetration test report without overhead or pie charts no one wants to see.
View source version on businesswire.com: https://www.businesswire.com/news/home/20220609005211/en/
Link:
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Dominican Republic Drives Modernization of Electronic Passports Under the Leadership of the Thales - MIDAS Consortium25.3.2026 23:22:00 CET | Press release
The General Directorate of Passports, together with the Presidency of the Dominican Republic, are leading the transformation of the country’s passport issuance system with a new, secure, efficient document aligned with international standards.In 2025, the Thales-MIDAS consortium was awarded the contract to develop, issue, and personalize a modern, secure, and highly reliable travel document for Dominican citizens, incorporating additional cybersecurity measures. The Presidency of the Dominican Republic, through the General Directorate of Passports, issued the country’s first electronic passport as part of its strategy to modernize and strengthen national security. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260324368065/en/ Passport of the Dominican Republic The new document was developed in partnership with Thales, world leader in advanced technologies for the Defense, Aerospace, Cybersecurity, and Digital sectors, and M
3D Systems Achieves Full-Scope EU MDR Certification, Accelerating European Launch of NextDent® Jetted Denture Solution Targeted for Summer 202625.3.2026 17:20:00 CET | Press release
Certification Marks Major Milestone in Strategic Dental Growth Initiative Addressing Straightening, Protection, Repair and Replacement of Teeth 3D Systems (NYSE: DDD) today announced it has received full-scope certification under the European Union Medical Device Regulation (EU MDR) 2017/745. The certification was attained on Monday, March 16, 2026. This milestone confirms that the Company’s quality system, technical documentation, and clinical evidence meet the most rigorous regulatory requirements in the medical device sector. With the MDR certificate in hand, 3D Systems will now introduce MDR-compliant product versions through a carefully coordinated, phased rollout across its dental product families and European markets. This approach ensures a smooth transition while maintaining uninterrupted product availability for customers and healthcare providers. The EU MDR certification immediately enables the introduction of innovative new materials and is a pivotal step for one of 3D Syst
Visa to Bring Privacy-Preserving Payments to Canton Network25.3.2026 17:00:00 CET | Press release
Visa is the first payments company selected to become a Super Validator on the Canton Network, where it will help banks and financial institutions bring new payment flows onchain Visa (NYSE:V), a global leader in digital payments, today announced it will join the Canton Network as the first major global payments company to serve as a Super Validator, to help extend privacy‑preserving blockchain infrastructure to banks and financial institutions around the world. Visa will be one of 40 Super Validators on Canton. That move goes straight to a core challenge for financial institutions: the same transparency that gives blockchains their appeal can clash with privacy expectations financial institutions operate under. Canton Network, a blockchain built for regulated finance, has privacy built in from the beginning, so organizations can use shared infrastructure without exposing sensitive information. As a Super Validator, Visa will help clients who choose to run and secure operations on the
ECU Worldwide Unveils XLERATE 2.0 Expansion to Bypass Asia–Europe Supply Chain Disruptions25.3.2026 14:30:00 CET | Press release
Strategic LAX gateway enables faster, predictable cargo movement through a reimagined sea–air logistics model ECU Worldwide, Allcargo Globals’ wholly-owned global subsidiary, has announced a strategic expansion of its transformative logistics solution, XLERATE 2.0, to provide a high-speed and resilient alternative to Asia-to-Europe trade lanes facing transit disruptions. Under this alternative routing, cargo is transported across the Pacific to the US West Coast, using Los Angeles (LAX) as a temporary hub. The solution leverages XLERATE 2.0’s premium, time-definite ocean services, ensuring greater transit agility and continuity. XLERATE 2.0 offers two distinct shipping solutions from China and Vietnam, providing shippers with flexibility as traditional trade arteries remain impacted by shifts in global logistics. These changes have led to reduced overall capacity and the disruption of standard sea–air services via conventional transit points. Commenting on the rollout, Simon Bajada, Re
Incyte Announces Executive Leadership Appointments25.3.2026 14:00:00 CET | Press release
Incyte (NASDAQ:INCY) today announced appointments among its executive leadership team to support the Company’s strategic focus and long-term growth plans. Pablo J. Cagnoni, M.D., has been appointed President, Incyte and Global Head of Research and Development. In this role, Dr. Cagnoni will retain responsibility for Research and Development, while also supporting enterprise-wide strategic planning and operational execution. Under Dr. Cagnoni’s scientific leadership, Incyte’s R&D progress has been notable, including advancing our mutCALR antibody, povorcitinib, CDK2, KRASG12D and TGFßR2xPD1 programs. Dr. Cagnoni has also continued to strengthen the way Incyte conducts R&D, introducing a new structure, processes and new technologies to improve productivity and keep Incyte competitive. Steven Stein, M.D., has been appointed Executive Vice President, Chief Medical Officer and Head of Late-stage Development. In this role, Dr. Stein will continue to oversee Incyte’s extensive and growing lat
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
