The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
About 34% of security vulnerabilities impacting industrial control systems (ICSs) that were reported in the first half of 2023 have no patch or remediation, re…
Microsoft has rolled out the scheduled Patch Tuesday updates for August 2023, ensuring automatic updates…Microsoft Patch Tuesday For August ’23 Addresses 84 Fl…
Multiple security issues were discovered in Thunderbird, including a bug in popup notifications delay calculation that could have enabled an attacker to trick …
Eleven severe vulnerabilities have been found in Chromium, including multiple Type Confusion bugs in V8, use-after-frees in Cast, Blink Task Scheduling and Web…
Microsoft has patched a total of74 flawsin its software as part of the company's Patch Tuesday updates for August 2023, down from the voluminous 132 vulnerabil…
Exposed Kubernetes (K8s) clusters are being exploited by malicious actors to deploy cryptocurrency miners and other backdoors.Cloud security firm Aqua, in arep…
According to recent reports, there have been instances of threat actors using malware called ''SkidMap'' to exploit vulnerable Redis systems.
Cybersecurity researchers have discovered a set of 11 living-off-the-land binaries-and-scripts (LOLBAS) that could be maliciously abused by threat actors to co…
Cybersecurity researchers have discovered a set of 11 living-off-the-land binaries-and-scripts (LOLBAS) that could be maliciously abused by threat actors to co…
A new malware campaign has been observed making use of malicious OpenBullet configuration files to target inexperienced cyber criminals with the goal of delive…
A security engineer at Linux distro maker SUSE has published an advisory for a flaw in the Mozilla VPN client for Linux that has yet to be addressed in a publi…
By dеtеcting flaws and vulnеrabilitiеs in onlinе applications, Dynamic Application Sеcurity Tеsting - DAST -…3 Typеs of DAST Tools for Enhancing Application Sе…
VulnerableRedis serviceshave been targeted by a "new, improved, dangerous" variant of a malware called SkidMap that's engineered to target a wide range of Linu…
VulnerableRedis serviceshave been targeted by a "new, improved, dangerous" variant of a malware called SkidMap that's engineered to target a wide range of Linu…
Researchers have discovered a new phishing campaign targeting Facebook accounts while exploiting a Salesforce zero-day.…Salesforce Zero-Day Flaw Exploited In F…
Cybersecurity researchers have discovered a new high-severity security flaw in PaperCut print management software for Windows that could result in remote code …
Several denial of service (DoS) and code execution vulnerabilities have been discovered in the Vim enhanced vi editor.
Two critical remote code execution (RCE) vulnerabilities have been found in OpenSSH (CVE-2023-28531 and CVE-2023-38408). Because these bugs are simple to explo…
A four-year-old critical security flaw impacting Fortinet FortiOS SSL has emerged as one of the most routinely and frequently exploited vulnerabilities in 2022…
Hundreds of Citrix NetScaler ADC and Gateway servers have been breached by malicious actors to deploy web shells, according to the Shadowserver Foundation.The …
It was discovered that under specific microarchitectural circumstances, a register in "Zen 2" CPUs might not be written to 0 correctly, potentially causing dat…
Several significant out-of-bounds access vulnerabilities have been found in the X.Org X Server (CVE-2021-4008, CVE-2021-4009, and CVE-2021-4011). These flaws t…
Cybersecurity researchers have discovered a bypass for a recently fixed actively exploited vulnerability in some versions of Ivanti Endpoint Manager Mobile (EP…
Linux security is anything but stagnant. It's no secret that cybercriminals are exploiting the growing popularity of the OS and the high-value servers and devi…