The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A newly patched security flaw impacting Windows NT LAN Manager (NTLM) was exploited as a zero-day by a suspected Russia-linked actor as part of cyber attacks t…
The Computer Emergency Response Team of Ukraine (CERT-UA) has detailed a new malicious email campaign targeting government agencies, enterprises, and military …
Multiple vulnerabilities have been fixed in bluez library, tools and daemons for using Bluetooth devices. CVE-2021-3658
Cybersecurity researchers have disclosed a security flaw impacting Microsoft Azure Kubernetes Services that, if successfully exploited, could allow an attacker…
Microsoft said it is developing security updates to address two loopholes that it said could be abused to stage downgrade attacks against the Windows update ar…
Canonical has fixed several recently identified critical Linux kernel vulnerabilities in July 2024. These vulnerabilities primarily affect Microsoft Azure clou…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on ev…
The infamous cybercrime group known as Scattered Spider has incorporated ransomware strains such as RansomHub and Qilin into its arsenal, Microsoft has reveale…
Google has released fixes for a high-severity Chromium security flaw ( CVE-2024-5274 ) impacting its widely used Chrome browser and other Chromium-based browse…
Update to 4.15 for CVE-2024-3652
Threat actors linked to the Black Basta ransomware may have exploited a recently disclosed privilege escalation flaw in the Microsoft Windows Error Reporting S…
* bsc#1225365 Cross-References: * CVE-2024-35235
* bsc#1223179 * bsc#1225365 Cross-References: * CVE-2024-35235
* bsc#1222842 Cross-References: * CVE-2024-3651
Update to 3.7 (rhbz#2274439), security fix for CVE-2024-3651
* bsc#1222842 Cross-References: * CVE-2024-3651
A new malware campaign leveraged two zero-day flaws in Cisco networking gear to deliver custom malware and facilitate covert data collection on target environm…
The Russia-linked nation-state threat actor tracked as APT28 weaponized a security flaw in the Microsoft Windows Print Spooler component to deliver a previousl…
The malicious code inserted into the open-source library XZ Utils, a widely used package present in major Linux distributions, is also capable of facilitating …
Composer, an application-level dependency manager for the PHP programming language was vulnerable. CVE-2023-43655:
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. (CVE-2020-36518) In FasterXML j…
The updated packages fix a security vulnerability: pam_namespace: protect_dir(): use O_DIRECTORY to prevent local DoS situations. (CVE-2024-22365) References:
The maintainers of shim have released version 15.8 to address six security flaws, including a critical bug that could pave the way for remote code execution un…
The maintainers of shim have released version 15.8 to address six security flaws, including a critical bug that could pave the way for remote code execution un…