The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Multiple security vulnerabilities have recently been discovered in the XOrg Server prior to 21.1.11, and Xwayland display implementations prior to 23.2.4. Thes…
The decentralized social network Mastodon has disclosed a critical security flaw that enables malicious actors to impersonate and take over any account."Due to…
The threat actor behind a peer-to-peer (P2P) botnet known as FritzFrog has made a return with a new variant that leverages the Log4Shell vulnerability to propa…
How’s your vulnerability management program doing? Is it effective? A success? Let’s be honest, without the right metrics or analytics, how can you tell how we…
Ivanti has warned all Connect Secure and Policy Secure users to immediately update their systems…Two Ivanti Zero-Day Vulnerabilities Demand Immediate User Atte…
Google-owned Mandiant said it identified new malware employed by a China-nexus espionage threat actor known as UNC5221 and other threat groups during post-expl…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting iOS, iPadOS, macOS, tvOS, and watchOS to its…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting iOS, iPadOS, macOS, tvOS, and watchOS to its…
The networking giant Cisco addressed a severe security flaw affecting its Unified Communications Products. Exploiting…Cisco Fixed Critical RCE Flaw In Unified …
Days after releasing a major update, GitLab rolled out another emergency update addressing a serious…GitLab Patched A Workspace Creation Vulnerability With An …
A pair of recently disclosed zero-day flaws in Ivanti Connect Secure (ICS) virtual private network (VPN) devices have been exploited to deliver a Rust-based pa…
A pair of recently disclosed zero-day flaws in Ivanti Connect Secure (ICS) virtual private network (VPN) devices have been exploited to deliver a Rust-based pa…
IaC, or infrastructure as code, is essential to most cloud-based applications. Implementing IaC has advantages that significantly increase the service's charac…
Each New Year introduces a new set of challenges and opportunities for strengthening our cybersecurity posture. It's the nature of the field – the speed at whi…
Apple began the new year 2024 with a zero-day patch that it simultaneously released for…Apple Begins 2024 Patching A Zero-Day Under Attack on Latest Hacking Ne…
A now-patched security flaw in Microsoft Outlook could be exploited by threat actors to access NT LAN Manager (NTLM) v2 hashed passwords when opening a special…
A severe authentication bypass security flaw riddled the GoAnywhere MFT that could allow creating rogue…Critical Authentication Bypass Flaw Patched In GoAnywhe…
The maintainers of the open-source continuous integration/continuous delivery and deployment (CI/CD) automation software Jenkins have resolved nine security fl…
We analyzed 2,5 million vulnerabilities we discovered in our customer’s assets. This is what we found.Digging into the dataThe dataset we analyze here is repre…
A new Go-based malware loader called CherryLoader has been discovered by threat hunters in the wild to deliver additional payloads onto compromised hosts for f…
Security researchers have identified a malicious tool called "SYSTEMBC" that hackers have been actively exploiting. This tool acts as a SOCKS5 proxy , providin…
The ransomware group known as Kasseika has become the latest to leverage the Bring Your Own Vulnerable Driver (BYOVD) attack to disarm security-related process…
The ransomware group known as Kasseika has become the latest to leverage the Bring Your Own Vulnerable Driver (BYOVD) attack to disarm security-related process…
Several public and popular libraries abandoned but still used in Java and Android applications have been found susceptible to a new software supply chain attac…