The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
The Midnight Blizzard and Cloudflare-Atlassian cybersecurity incidents raised alarms about the vulnerabilities inherent in major SaaS platforms. These incident…
Threat actors are leveraging a recently disclosed security flaw impacting Ivanti Connect Secure, Policy Secure, and ZTA gateways to deploy a backdoor codenamed…
Cybersecurity researchers have uncovered an "implementation vulnerability" that has made it possible to reconstruct encryption keys and decrypt data locked by …
Imagine your most sensitive and critical information being made accessible to threat actors without your permission or knowledge. This is exactly what a new in…
Four significant vulnerabilities have been discovered in the GNU C Library (glibc) , a fundamental component of most Linux distributions. These vulnerabilities…
A serious security vulnerability affected the WordPress plugin Security Shield, which could allow arbitrary file…Serious Security Vulnerability Patched In Shie…
The operators of Raspberry Robin are now using two new one-day exploits to achieve local privilege escalation, even as the malware continues to be refined and …
IntroductionThe modern software supply chain represents an ever-evolving threat landscape, with each package added to the manifest introducing new attack vecto…
Heads up, Mastodon admins! A critical security vulnerability riddled Mastodon, allowing account takeover by an…Critical Vulnerability Could Allow Mastodon Acco…
As organizations keep more of their customer and business data online, they’re becoming more vulnerable…Tips for Reducing Cybersecurity Risk for Your Business …
The maintainers of shim have released version 15.8 to address six security flaws, including a critical bug that could pave the way for remote code execution un…
The maintainers of shim have released version 15.8 to address six security flaws, including a critical bug that could pave the way for remote code execution un…
SaaS applications are the darlings of the software world. They enable work from anywhere, facilitate collaboration, and offer a cost-effective alternative to o…
The threat actor known as Patchwork likely used romance scam lures to trap victims in Pakistan and India, and infect their Android devices with a remote access…
Multiple security vulnerabilities have recently been discovered in the XOrg Server prior to 21.1.11, and Xwayland display implementations prior to 23.2.4. Thes…
Multiple security vulnerabilities have recently been discovered in the XOrg Server prior to 21.1.11, and Xwayland display implementations prior to 23.2.4. Thes…
The decentralized social network Mastodon has disclosed a critical security flaw that enables malicious actors to impersonate and take over any account."Due to…
The threat actor behind a peer-to-peer (P2P) botnet known as FritzFrog has made a return with a new variant that leverages the Log4Shell vulnerability to propa…
How’s your vulnerability management program doing? Is it effective? A success? Let’s be honest, without the right metrics or analytics, how can you tell how we…
Ivanti has warned all Connect Secure and Policy Secure users to immediately update their systems…Two Ivanti Zero-Day Vulnerabilities Demand Immediate User Atte…
Google-owned Mandiant said it identified new malware employed by a China-nexus espionage threat actor known as UNC5221 and other threat groups during post-expl…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting iOS, iPadOS, macOS, tvOS, and watchOS to its…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting iOS, iPadOS, macOS, tvOS, and watchOS to its…
The networking giant Cisco addressed a severe security flaw affecting its Unified Communications Products. Exploiting…Cisco Fixed Critical RCE Flaw In Unified …