Collected every two hours from specialised publications — each link leads to the original article.
Security teams typically have great visibility over most areas, for example, the corporate network, endpoints, servers, and cloud infrastructure. They use this…
Web infrastructure company Cloudflare on Monday disclosed that it thwarted a record-breaking distributed denial-of-service (DDoS) attack that peaked at over 71…
Google’s upcoming Android 14 will include enhanced security features to block Android malware. As reported,…Android 14 Will Block Malware With Enhanced Securit…
An unknown threat actor created malicious game modes for the Dota 2 multiplayer online battle arena (MOBA) video game that could have been exploited to establi…
APIs, APIs Everywhere! Numerous (and by that, I mean all of them) mobile and cloud-native…Why you still need security alongside your API Gateway on Latest Hack…
Researchers have devised a ChromeOS exploit that unlocks enterprise-managed Chromebooks. While Google is addressing the…New SH1MMER ChromeOS Exploit Jailbreaks…
Microsoft on Tuesday said it took steps to disable fake Microsoft Partner Network (MPN) accounts that were used for creating maliciousOAuthapplications as part…
The threat actors associated with the Gootkit malware have made "notable changes" to their toolset, adding new components and obfuscations to their infection c…
In 2022, the Open Source Software Foundation (OpenSSF) set its sights on fixing security problems with the open software supply chain. including joining forces…
The introduction of cloud computing has significantly changed how online businesses function. Working with data…Compliance Auditing for Data Security Posture M…
Threat actors are evolving to target a wide variety of systems and infrastructure, BlackBerry says in a new report. "In addition, attacks against Linux systems…
Security stakeholders have come to realize that the prominent role the browser has in the modern corporate environment requires a re-evaluation of how it is ma…
The move to SaaS and other cloud tools has put an emphasis on Identity & Access Management (IAM). After all, user identity is one of the only barriers standing…
A suspected China-nexus threat actor exploited a recently patched vulnerability in Fortinet FortiOS SSL-VPN as a zero-day in attacks targeting a European gover…
New research has found that it is possible for threat actors to abuse a legitimate feature in GitHub Codespaces to deliver malware to victim systems.GitHub Cod…
''Log4j has been around for 20 years; it's become embedded into nearly every meaningful Java application; and the Log4Shell event led to compromises in everyth…
Details have emerged about a now-patched vulnerability in Google Chrome and Chromium-based browsers that, if successfully exploited, could have made it possibl…
The threat actors behind theKinsingcryptojacking operation have been spotted exploiting misconfigured and exposed PostgreSQL servers to obtain initial access t…
The Russian cyberespionage group known as Turla has been observed piggybacking on attack infrastructure used by a decade-old malware to deliver its own reconna…
Cloud services provider Rackspace on Thursday confirmed that the ransomware gang known as Play was responsible for last month's breach.The security incident, w…
A critical security flaw has been disclosed in Amazon Elastic Container Registry (ECR) Public Gallery that could have been potentially exploited to stage a mul…
An update for instack-undercloud is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a securi…
Platform certificates used by Android smartphone vendors like Samsung, LG, and MediaTek have been found to be abused to sign malicious apps.The findings were f…
A previously undocumented Go-based malware is targeting Redis servers with the goal of taking control of the infected systems and likely building a botnet netw…