Collected every two hours from specialised publications — each link leads to the original article.
Google has warned that a security flaw impacting Pixel Firmware has been exploited in the wild as a zero-day.The high-severity vulnerability, tagged as CVE-202…
Google has rolled out fixes to address a set of nine security issues in its Chrome browser, including a new zero-day that has been exploited in the wild.Assign…
A recent increase in attacks has been observed from the 8220 Gang, a cybercriminal group from China. The group has become notorious for infiltrating cloud-base…
The Android banking trojan known as Anatsa has expanded its focus to include Slovakia, Slovenia, and Czechia as part of a new campaign observed in November 202…
The Midnight Blizzard and Cloudflare-Atlassian cybersecurity incidents raised alarms about the vulnerabilities inherent in major SaaS platforms. These incident…
A 29-year-old Ukrainian national has been arrested in connection with running a “sophisticated cryptojacking scheme,” netting them over $2 million (€1.8 millio…
Google is highlighting the role played by Clang sanitizers in hardening the security of the cellular baseband in the Android operating system and preventing sp…
BOSTON, MASS. and TEL AVIV, ISRAEL, November 28, 2023 - A severe design flaw in…Design Flaw in Domain-Wide Delegation Could Leave Google Workspace Vulnerable f…
The maintainers of the open-source file-sharing software ownCloud have warned of three critical security flaws that could be exploited to disclose sensitive in…
Two critical security flaws discovered in the open-sourceCasaOSpersonal cloud software could be successfully exploited by attackers to achieve arbitrary code e…
Microsoft has detailed a new campaign in which attackers unsuccessfully attempted to move laterally to a cloud environmentthrough an SQL Server instance."The a…
Recently, a cryptocurrency firm, Fortress Trust, disclosed a theft of $15 million following a cyber…Google Authenticator Flaw Inadvertently Facilitated $15 Mil…
Google on Monday rolled out out-of-band security patches to address a critical security flaw in its Chrome web browser that it said has been exploited in the w…
Google has released its monthly security updates for the Android operating system, addressing 46 new software vulnerabilities. Among these, three vulnerabiliti…
cloud-init could write sensitive information to logs.
Google on Thursday outlined a set of initiatives aimed at improving the vulnerability management ecosystem and establishing greater transparency measures aroun…
Four different Microsoft Azure services have been found vulnerable to server-side request forgery (SSRF) attacks that could be exploited to gain unauthorized a…
An Internet Explorer zero-day vulnerability was actively exploited by a North Korean threat actor to target South Korean users by capitalizing on the recentIta…
As per the latest CERT-In security alert, multiple vulnerabilities have been reported in the Linux-based operating system designed by Google
The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which…
Multiple vulnerabilities have been found in Nextcloud, the worst of which could result in denial of service.
The 8220 cryptomining group has expanded in size to encompass as many as 30,000 infected hosts, up from 2,000 hosts globally in mid-2021."8220 Gang is one of t…
cloud-init could be made to expose sensitive information.
It was discovered that the package com.google.code.gson:gson before 2.8.9 is vulnerable to Deserialization of Untrusted Data via the writeReplace() method in i…