The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Web applications are an integral part of most business operations today. They are commonly used for storing, processing, or transmitting data in various busine…
Researchers found a critical vulnerability in the Google Cloud Build that allowed elevated privileges to…A Google Cloud Build Vulnerability Could Aid Supply-Ch…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory on Thursday warning that the newly disclosed critical security flaw in Citr…
Mallox ransomware activities in 2023 have witnessed a 174% increase when compared to the previous year, new findings from Palo Alto Networks Unit 42 reveal."Ma…
Multiple security flaws have been disclosed in Apache OpenMeetings, a web conferencing solution, that could be potentially exploited by malicious actors to sei…
Months after releasing the patch, hackers are still exploiting the security flaw in WooCommerce Payments…WooCommerce Payments WP Plugin Flaw Goes Under Active …
Adobe has released a fresh round of updates to address an incomplete fix for a recently disclosed ColdFusion flaw that has come under active exploitation in th…
It was discovered that in Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (re…
Multiple severe security issues were discovered in the GPAC multimedia framework, including a heap-based Buffer Overflow in the GitHub repository gpac/gpac bef…
Cybersecurity researchers have uncovered a privilege escalation vulnerability in Google Cloud that could enable malicious actors tamper with application images…
The U.S. government on Tuesday added two foreign commercial spyware vendors, Cytrox and Intellexa, to an economic blocklist for weaponizing cyber exploits to g…
Citrix isalertingusers of a critical security flaw in NetScaler Application Delivery Controller (ADC) and Gateway that it said is being actively exploited in t…
Threat actors are taking advantage of Android'sWebAPK technologyto trick unsuspecting users into installing malicious web apps on Android phones that are desig…
Microsoft Word documents exploiting known remote code execution flaws are being used as phishing lures to drop malware calledLokiBoton compromised systems."Lok…
Researchers found the popular chat service QuickBlox exhibiting numerous security flaws. Exploiting the QuickBlox framework…QuickBlox Framework Vulnerabilities…
Multiple security vulnerabilities have been discovered in various services, including Honeywell Experion distributed control system (DCS) and QuickBlox, that, …
In a sign that cybersecurity researchers continue to be under the radar of malicious actors, a proof-of-concept (PoC) has been discovered on GitHub, concealing…
A type confusion issue that may have been actively exploited has been identified in the WebKitGTK web engine (CVE-2023-32439). With a low attack complexity and…
Exploit code will soon become available for a critical vulnerability in the Linux kernel that a security researcher discovered and reported in mid-June. Dubbed…
The July 2023 Patch Tuesday update bundle patched at least six different actively-exploited vulnerabilities across…Microsoft July Patch Tuesday Fixed Six Zero-…
SonicWall on Wednesday urged customers of Global Management System (GMS) firewall management and Analytics network reporting engine software to apply the lates…
Microsoft on Tuesday released updates to address a totalof 130 new security flawsspanning its software, including six zero-day flaws that it said have been act…
Microsoft on Tuesday released updates to address a totalof 132 new security flawsspanning its software, including six zero-day flaws that it said have been act…
Siemens recently addressed numerous vulnerabilities affecting its automation device A8000. The vulnerabilities even included a…Multiple Vulnerabilities Patched…