The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A recently patched security flaw in the popular WinRAR archiving software has been exploited as a zero-day since April 2023, new findings from Group-IB reveal.…
Multiple significant microcode security issues have been discovered. An information exposure bug known as Downfall ( CVE-2022-40982 ) has been found in some In…
A malicious toolset dubbedSpacecolonis being deployed as part of an ongoing campaign to spread variants of the Scarab ransomware across victim organizations gl…
Twenty-one severe vulnerabilities have been found in Chromium, including multiple use after frees and heap buffer overflows, among other security issues. These…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) hasaddeda critical security flaw in Adobe ColdFusion to its Known Exploited Vulnerabilities (K…
A high-severity security flaw has been disclosed in the WinRAR utility that could be potentially exploited by a threat actor to achieve remote code execution o…
Heads up, WinRAR users! It’s time to update your systems with the latest WinRAR version…WinRAR Security Flaw Could Allow Command Execution on Latest Hacking Ne…
Researchers found numerous security vulnerabilities in the ScrutisWeb ATM fleet monitoring software that threatened ATM…ScrutisWeb ATM Software Vulnerabilities…
Researchers detected numerous security vulnerabilities in Ivanti Avalanche EMM, allowing remote code execution attacks from…Multiple Vulnerabilities Found In I…
A cybersecurity researcher from SUSE, a Linux distribution manufacturer, has made public a serious security flaw in the Mozilla VPN client for Linux.
While IT security managers in companies and public administrations rely on the concept of Zero Trust, APTS (Advanced Persistent Threats) are putting its practi…
"Variants of CL0p were initially only found on Windows systems, but the gang also developed a Linux variant toward the end of 2022, reflecting the diversity of…
Microsoft on Thursday disclosed that it found a new version of theBlackCatransomware (aka ALPHV and Noberus) that embeds tools like Impacket and RemCom to faci…
"Open-source software's security and reliability aspects have played a significant role in its rise. The availability of source code to a large community of de…
Multiple critical security flaws have been reported inIvanti Avalanche, an enterprise mobile device management solution that’s used by 30,000 organizations.The…
Nearly 2,000 Citrix NetScaler instances have been compromised with a backdoor by weaponizing a recently disclosed critical security vulnerability as part of a …
Four security vulnerabilities in the ScrutisWeb ATM fleet monitoring software made by Iagona could be exploited to remotely break into ATMs, upload arbitrary f…
Microsoft researchers discovered numerous vulnerabilities affecting Codesys PLC that risked power plants’ security with various…Multiple Codesys PLC Vulnerabil…
Google researchers recently reported a vulnerability in Intel CPUs leading to a new “Downfall” side-channel…Intel Patched Newly Reported Downfall Attack Affect…
E-commerce sites using Adobe's Magento 2 software are the target of an ongoing campaign that has been active since at least January 2023.The attacks, dubbedXur…
[BLACK HAT] Googlers have lately found not one but two more security vulnerabilities in Intel and AMD processors that can be exploited to steal sensitive data …
The White House launched a multimillion-dollar cyber contest to use artificial intelligence (AI) to detect and fix security vulnerabilities in the U.S. governm…
Following yesterday's disclosure of the AMD "Inception" security vulnerability and the Linux kernel patches merged for reporting the mitigation status as well …
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) hasaddeda recently patched security flaw in Microsoft's .NET and Visual Studio products to its…