The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Researchers have discovered an inexpensive attack technique that could be leveraged to brute-force fingerprints on smartphones to bypass user authentication an…
Heads up, WordPress admins! It’s time to update your websites with the latest Beautiful Cookie…XSS Flaw Riddled Beautiful Cookie Consent Banner WP Plugin on La…
A critical security vulnerability has been disclosed in the Open Authorization (OAuth) implementation of the application development framework Expo.io.The shor…
A new security flaw has been disclosed in the Google Cloud Platform's (GCP) Cloud SQL service that could be potentially exploited to obtain access to confident…
The Cybersecurity & Infrastructure Security Agency (CISA) added seven new Linux vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on Friday …
A new strain of malicious software that's engineered to penetrate and disrupt critical systems in industrial environments has been unearthed.Google-owned threa…
Email protection and network security services provider Barracuda is warning users about a zero-day flaw that it said has been exploited to breach the company'…
Zyxel has released software updates to address two critical security flaws affecting select firewall and VPN products that could be abused by remote attackers …
US CISA recently issued an alert, warning Samsung users about an ASLR bypass flaw being…Samsung ASLR Bypass Flaw Is Actively Exploited – Warns CISA on Latest H…
Several important security issues have been found in the Linux kernel, including a slab-out-of-bound read problem (CVE-2023-1380), a heap out-of-bounds read/wr…
Two important ReDoS issues have been found in the Ruby programming language; one in the URI component (CVE-2023-28755) and one in the Time component (CVE-2023-…
The infamous Lazarus Group actor has been targeting vulnerable versions of Microsoft Internet Information Services (IIS) servers as an initial breach route to …
Several important security issues were identified in the runC Open Container Project. It was discovered that runC incorrectly performed access control when mou…
The identity of the second threat actor behind the Golden Chickens malware has been uncovered courtesy of a "fatal" operational security blunder, cybersecurity…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation of a medium-severity flaw affecting Samsung devices.The issue, t…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of active exploitation of a medium-severity flaw affecting Samsung devices.The issu…
Google recently announced significant updates to its Vulnerability Reward Program for Android OS and devices.…Google Upgrades Its Vulnerability Reward Program …
Apple on Thursdayrolled out security updatesto iOS, iPadOS, macOS, tvOS, watchOS, and the Safari web browser to address dozens of flaws, including three new ze…
The second generation version of Belkin's Wemo Mini Smart Plug has been found to contain a buffer overflow vulnerability that could be weaponized by a threat a…
Several security vulnerabilities have been disclosed in cloud management platforms associated with three industrial cellular router vendors that could expose o…
The Cybersecurity & Infrastructure Security Agency (CISA) added seven new Linux vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on Friday …
Researchers caught Trafficstealer actively abusing Docker Container APIs to redirect users to malicious websites. The…Trafficstealer Exploits Container APIs fo…
WordPress is one of the most popular content management systems in the world due to the ability it gives non-technical, inexperienced users to create professio…
Cybersecurity researchers have discovered an ongoing phishing campaign that makes use of a unique attack chain to deliver theXWorm malwareon targeted systems.S…