The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A group of academics has disclosed a new "software fault attack" on AMD's Secure Encrypted Virtualization (SEV) technology that could be potentially exploited …
Researchers spotted a couple of security vulnerabilities in PureVPN Desktop clients for Linux that impact…Multiple Vulnerabilities Found In PureVPN – One Remai…
The threat actor known as Lace Tempest has been linked to the exploitation of a zero-day flaw in SysAid IT support software in limited attacks, according to ne…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesdayaddeda high-severity flaw in the Service Location Protocol (SLP) to its Known Expl…
Multiple ransomware groups have begun to actively exploit recently disclosed flaws in Atlassian Confluence and Apache ActiveMQ.Cybersecurity firm Rapid7saidit …
After announcing the upgradation of the CVSS 3.0 scoring system in June, this week, FIRST…CVSS 4.0 Arrived As The New Vulnerability Scoring Standard on Latest …
The threat actors linked toKinsinghave been observed attempting to exploit the recently disclosed Linux privilege escalation flaw called Looney Tunables as par…
The Forum of Incident Response and Security Teams (FIRST) has officially announcedCVSS v4.0, the next generation of the Common Vulnerability Scoring System sta…
Cybersecurity researchers are warning of suspected exploitation of a recently disclosed critical security flaw in the Apache ActiveMQ open-source message broke…
F5 is warning of active abuse of a critical security flaw in BIG-IP less than a week after its public disclosure, resulting in the execution of arbitrary syste…
Atlassian has warned of a critical security flaw in Confluence Data Center and Server that could result in "significant data loss if exploited by an unauthenti…
A critical security flaw existed in the F5 BIG-IP Configuration utility that allows an adversary…Critical F5 BIG-IP Flaw Allows Remote Code Execution Attacks o…
Heads up, phpFox users! A critical remote code execution vulnerability existed in the phpFox service…Critical PHPFox RCE Vulnerability Risked Social Networks o…
Days after back-to-back disclosures about actively exploited zero-day vulnerabilities, Cisco has finally patched them with…Patches Released For The Actively Ex…
Three unpatched high-severity security flaws have been disclosed in theNGINX Ingress controllerfor Kubernetes that could be weaponized by a threat actor to ste…
F5 has alerted customers of a critical security vulnerability impacting BIG-IP that could result in unauthenticated remote code execution.The issue, rooted in …
Cloudflare on Thursday said it mitigated thousands of hyper-volumetric HTTP distributed denial-of-service (DDoS) attacks that exploited a recently disclosed fl…
VMware has released security updates to address a critical flaw in the vCenter Server that could result in remote code execution on affected systems.The issue,…
Virtualization services provider VMware has alerted customers to the existence of a proof-of-concept (PoC) exploit for a recently patched security flaw in Aria…
With a few days gap, Cisco disclosed active exploitation detections for separate zero-days affecting its…Cisco Discloses Multiple Zero-Days Under Attack In IOS…
Cisco has warned of a new zero-day flaw in IOS XE that has been actively exploited by an unknown threat actor to deploy amalicious Lua-based implanton suscepti…
The time between a vulnerability being discovered and hackers exploiting it is narrower than ever –just 12 days. So it makes sense that organizations are start…
Following the rumors about a zero-day flaw in the Signal app, the developers have debunked…Signal Debunks Rumors About Zero-Day Vulnerability In The App on Lat…
In the ever-evolving landscape of cybersecurity, attackers are always searching for vulnerabilities and exploits within organizational environments. They don't…