The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Microsoft has detailed a new campaign in which attackers unsuccessfully attempted to move laterally to a cloud environmentthrough an SQL Server instance."The a…
Security Configuration Assessment (SCA)is critical to an organization's cybersecurity strategy. SCA aims to discover vulnerabilities and misconfigurations that…
Arm has released security patches to contain a security flaw in the Mali GPU Kernel Driver that has come under active exploitation in the wild.Tracked asCVE-20…
Although Cloudflare provides resilient DDoS protection, a researcher devised a strategy to bypass the security…Cloudflare DDoS Protection Flaws Allowed Securit…
Researchers have discovered a new phishing campaign that exploits Microsoft’s Bing Chat to promote malicious…Hackers Meddle With Bing Chat Ads To Promote Malic…
Heads up, Chrome users! Google has just released a major security update for its Chrome…Another Chrome Zero-Day Under Attack Received A Fix on Latest Hacking N…
Researchers caught a serious security flaw in JetBrains TeamCity software that could allow unauthenticated code…Critical Security Flaw Found In JetBrains TeamC…
A high-severity security flaw has been disclosed in the open-source OpenRefine data cleanup and transformation tool that could result in arbitrary code executi…
Multiple security vulnerabilities have been disclosed in theExim mail transfer agentthat, if successfully exploited, could result in information disclosure and…
Progress Software has released hotfixes for a critical security vulnerability, alongside seven other flaws, in the WS_FTP Server Ad hoc Transfer Module and in …
Cisco is warning of attempted exploitation of a security flaw in its IOS Software and IOS XE Software that could permit an authenticated remote attacker to ach…
Cybersecurity agencies from Japan and the U.S. have warned of attacks mounted by a state-backed hacking group from China to stealthily tamper with branch route…
The landscape of browser security has undergone significant changes over the past decade. While Browser Isolation was once considered the gold standard for pro…
Google on Wednesday rolled out fixes to address a new actively exploited zero-day in the Chrome browser.Tracked asCVE-2023-5217, the high-severity vulnerabilit…
Heads up, Apple users! Researchers have caught active exploitation of three zero-day flaws in Apple…Apple Zero-Day Flaws Exploited For Predator Spyware Attacks…
A novel side-channel attack calledGPU.ziprenders virtually all modern graphics processing units (GPU) vulnerable to information leakage."This channel exploits …
Google has assigned a new CVE identifier for a critical security flaw in the libwebp image library for rendering images in theWebP formatthat has come under ac…
SOC 2, ISO, HIPAA, Cyber Essentials – all the security frameworks and certifications today are an acronym soup that can make even a compliance expert’s head sp…
Thethree zero-day flawsaddressed by Apple on September 21, 2023, were leveraged as part of an iPhone exploit chain in an attempt to deliver a spyware strain ca…
The maintainers of Free Download Manager (FDM) have acknowledged a security incident dating back to 2020 that led to its website being used to distribute malic…
A malicious actor released a fake proof-of-concept (PoC) exploit for a recently disclosed WinRAR vulnerability on GitHub with an aim to infect users who downlo…
A malicious actor released a fake proof-of-concept (PoC) exploit for a recently disclosed WinRAR vulnerability on GitHub with an aim to infect users who downlo…
Multiple security flaws have been disclosed in the Nagios XI network monitoring software that could result in privilege escalation and information disclosure.T…
GitLab has shipped security patches to resolve a critical flaw that allows an attacker to run pipelines as another user.The issue, tracked asCVE-2023-5009(CVSS…