The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Anytime you upgrade software, you risk something breaking. This is the nature of the IT beast. The purpose of patches is usually to fix a bug or, worse, a secu…
Researchers have disclosed details of three new security vulnerabilities affecting operational technology (OT) products from CODESYS and Festo that could lead …
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Mondayaddeda critical flaw impacting Oracle Fusion Middleware to its Known Exploited Vulner…
Amazon Web Services (AWS) has resolved a cross-tenant vulnerability in its platform that could be weaponized by an attacker to gain unauthorized access to reso…
Researchers have discovered a serious security issue in the social networking platform Mastodon. Specifically, the…A Mastodon Vulnerability Could Allow Meddlin…
Researchers discovered two different vulnerabilities riddling Zendesk Explore security. Exploiting the flaws could allow an…Numerous Vulnerabilities Spotted In…
Redhat has just just published a risk advisory about a vulnerability in the Linux Kernel that allows for local privilege escalation. This vulnerability is trac…
Canonical has released a new Linux kernel security updates for all supported Ubuntu LTS releases to address up to 16 vulnerabilities discovered by various secu…
Cybersecurity continues to be a hot topic. More and more organizations are getting hit by ransomware attacks, critical open software vulnerabilities are making…
Samba this week released patches for an integer overflow vulnerability that could potentially lead to arbitrary code execution.
The local privilege escalation vulnerability in the Linux Kernel was reported by Redhat, and its CVE code is 2022-3977 . The problem is that the most recent Li…
Ethical hacking is analyzing a system without permission to try and discover vulnerabilities that hackers can use. On the other hand, penetration testing attem…
The C and C++ languages are unsafe. Instead, the U.S. National Security Agency would like devs to use memory-safe languages''because most security vulnerabilit…
You might have heard that the VENOM vulnerability might be worse than Heartbleed, but is that true? What is VENOM? What can you do about it.
Future Intel CPUs and some existing processors via a microcode update will support a new feature called the Asynchronous EXit (AEX) notification mechanism to h…
Made public earlier this year was Spectre-BHB / BHI as a speculative execution vulnerability similar to Spectre V2 and affecting Intel and Arm CPUs.
Indirect Branch Tracking (IBT) is still being eyed for enabling as part of the default Linux x86_64 kernel configurations to provide better out-of-the-box secu…
The critical security vulnerability turned out to be two serious vulnerabilities. Still, they need patching ASAP.
The tech provider ConnectWise disclosed a severe remote code execution flaw that exposed thousands of…ConnectWise Addressed Remote Code Execution Flaw Risking …
Canonical published today the first Linux kernel security update for its recently released Ubuntu 22.10 (Kinetic Kudu) operating system series to address recen…
The OpenSSL Project team has announced that, on November 1, 2022, they will release OpenSSL version 3.0.7, which will fix a critical vulnerability in the popul…
SecurityWeek reports that federal agencies have been ordered by the Cybersecurity and Infrastructure Security Agency to remediate within three weeks a Linux ke…
A now-patched vulnerability in VMware Workspace ONE Access has been observed being exploited to deliver both cryptocurrency miners and ransomware on affected m…
Recently, a remote code execution flaw in the Apache Common Text library stirred up the…Apache Commons Text Library Flaw Is Worrisome, But Not Like Log4Shell o…