The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A large-scale extortion campaign has compromised various organizations by taking advantage of publicly accessible environment variable files (.env) that contai…
A large-scale extortion campaign has compromised various organizations by taking advantage of publicly accessible environment variable files (.env) that contai…
SaaS applications have become indispensable for organizations aiming to enhance productivity and streamline operations. However, the convenience and efficiency…
A newly discovered attack vector in GitHub Actions artifacts dubbed ArtiPACKED could be exploited to take over repositories and gain access to organizations' c…
Researchers recently found a new vulnerability under active attack that impacts all major web browsers.…Watch Out For The ‘0.0.0.0 Day’ Zero-Day Flaw Affecting…
The August 2024 Patch Tuesday Update bundle from Microsoft is huge, with 10 zero-day fixes.…Microsoft August Patch Tuesday Fixed 10 Zero-Day Vulnerabilities on…
Cybersecurity researchers have discovered two security flaws in Microsoft's Azure Health Bot Service that, if exploited, could permit a malicious actor to achi…
Cybersecurity researchers have identified a number of security shortcomings in photovoltaic system management platforms operated by Chinese companies Solarman …
The maintainers of the FreeBSD Project have released security updates to address a high-severity flaw in OpenSSH that attackers could potentially exploit to ex…
BlackHat USA , an annual cybersecurity conference with global attendance since 1997, is an essential forum for sharing cutting-edge security research, trends, …
At a time when security breaches have become increasingly sophisticated, an oversight that had persisted across major browsers for years has now been addressed…
Microsoft has disclosed an unpatched zero-day in Office that, if successfully exploited, could result in unauthorized disclosure of sensitive information to ma…
Microsoft has disclosed an unpatched zero-day in Office that, if successfully exploited, could result in unauthorized disclosure of sensitive information to ma…
Cybersecurity researchers have discovered a new "0.0.0.0 Day" impacting all major web browsers that malicious websites could take advantage of to breach local …
Microsoft said it is developing security updates to address two loopholes that it said could be abused to stage downgrade attacks against the Windows update ar…
A critical security flaw impacting Progress Software WhatsUp Gold is seeing active exploitation attempts, making it essential that users move quickly to apply …
As Generative AI expands its disruptive range of applications, researchers demonstrate the novel security risks…New Study Shows GenAI Apps Are Vulnerable To Pr…
Google has addressed a high-severity security flaw impacting the Android kernel that it said has been actively exploited in the wild.The vulnerability, tracked…
Researchers have spotted a new malware campaign where the hackers exploit Google Ads to sponsor…Fake Google Authenticator Sites Exploit Google Ads To Deliver M…
Researchers found Cloudflare’s latest feature, TryCloudflare, actively exploited in malware campaigns. While the feature facilitates…TryCloudflare Exploited In…
Recently, open-source security was rocked by the discovery of an alarming Remote Code Execution (RCE) vulnerability within the Ghostscript document conversion …
Recently, open-source security was rocked by the discovery of an alarming Remote Code Execution (RCE) vulnerability within the Ghostscript document conversion …
Canonical has fixed several recently identified critical Linux kernel vulnerabilities in July 2024. These vulnerabilities primarily affect Microsoft Azure clou…
A recently patched security flaw impacting VMware ESXi hypervisors has been actively exploited by "several" ransomware groups to gain elevated permissions and …