The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Several flaws were discovered in jackson-databind, a fast and powerful JSON library for Java. CVE-2020-36518
Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted ht…
Microsoft researchers discovered a serious vulnerability in TikTok that threatened user accounts’ security. Specifically, they…Serious Account Hijacking Vulner…
Several vulnerabilities have been discovered in the Linux kernel that may lead to privilege escalation, denial of service or information leaks: CVE-2021-33655
Linux disk/nic frontends data leaks [XSA-403, CVE-2022-26365, CVE-2022-33740, CVE-2022-33741, CVE-2022-33742] (#2104747) ---- update to xen-4.15.3 x86: MMIO St…
Linux disk/nic frontends data leaks [XSA-403, CVE-2022-26365, CVE-2022-33740, CVE-2022-33741, CVE-2022-3374]
Months after Microsoft patched a remote code execution vulnerability in SharePoint, a new way to…New Exploit Emerges For A Previously Patched SharePoint Vulner…
Last Friday, Microsoft announced that they have discovered a new botnet that exposes both Windows and Linux computers and web servers to new threats. The botne…
Last Friday, Microsoft announced that they have discovered a new botnet that exposes both Windows and Linux computers and web servers to new threats. The botne…
The tech giant Microsoft has recently shared details about multiple vulnerabilities affecting Linux systems. Identified…Multiple “Nimbuspwn” Vulnerabilities Al…
Google's Threat Analysis Group (TAG) took the wraps off a newinitial access brokerthat it said is closely affiliated to a Russian cyber crime gang notorious fo…
A serious security flaw in Microsoft’s Skype extension for Chrome browser risked users’ privacy. Thankfully,…Chrome Skype Extension Flaw Threatened User Privac…
An update is now available for Red Hat JBoss Web Server 3.1 for Red Hat Enterprise Linux 7 and Microsoft Windows. Red Hat Product Security has rated this relea…
Microsoft on Tuesday kicked off its first set of updates for 2022 byplugging 96 security holesacross its software ecosystem, while urging customers to prioriti…
Red Hat JBoss Web Server 5.6.0 zip release is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, and Microsoft Windows. Red Hat Product …
Update to upstream stable release 2.9.4, includes a fix for CVE-2021-3802 (#2003650, #2003649)
389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed (CVE-2021-3652) For more details about the security issue(s), including the i…
Multiple security fixes for nodejs. See references for details References: - https://bugs.mageia.org/show_bug.cgi?id=29365 - https://nodejs.org/en/blog/vulnera…
Red Hat JBoss Web Server 5.5.1 zip release is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, and Microsoft Windows. Red Hat Product …
Fixed crypt handling of locked accounts. (CVE-2021-3652) References: - https://bugs.mageia.org/show_bug.cgi?id=29393 - https://lists.suse.com/pipermail/sle-sec…
Azure users running Linux VMs may not be aware they have a severely vulnerable piece of management software installed on their machine by Microsoft, which can …
Microsoft has recently fixed a severe vulnerability that could allow PetiPotam NTLM relay attacks. However,…LockFile Ransomware Exploits PetiPotam To Attack Wi…
Updated bluez packages fix security vulnerability: Adapter incorrectly restores Discoverable state after powered down (CVE-2021-3658).
It hasn't been long since Microsoft patched the devastating PrintNightmare vulnerabilities, now another flaw arrives.…Another Windows Print Spooler Bug Arrives…