The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Recently, open-source security was rocked by the discovery of an alarming Remote Code Execution (RCE) vulnerability within the Ghostscript document conversion …
Recently, open-source security was rocked by the discovery of an alarming Remote Code Execution (RCE) vulnerability within the Ghostscript document conversion …
Cybersecurity companies are warning about an uptick in the abuse of Clouflare's TryCloudflare free service for malware delivery.The activity, documented by bot…
In yet another sign that threat actors are always looking out for new ways to trick users into downloading malware, it has come to light that the question-and-…
Google has announced that it's adding a new layer of protection to its Chrome browser through what's called app-bound encryption to prevent information-stealin…
The notorious SideWinder threat actor group is back with another cyberespionage campaign. This time, SideWinder…Recent SideWinder Campaign Targets Ports And Ma…
Years after targeting Android malware, the seemingly dormant Mandrake malware reemerges with a sneaky campaign.…Mandrake Android Malware Creeps Up On Google Pl…
As observed, WhatsApp for Windows does not block Python or PHP script execution on Windows…WhatsApp Allows Python, PHP Script Execution on Windows Without Warn…
The social media giant X (formerly Twitter), quietly started using users’ posts for training Grok…X Leverages Users’ Posts For Training Its Grok AI on Latest H…
The threat actors behind an ongoing malware campaign targeting software developers have demonstrated new malware and tactics, expanding their focus to include …
Canonical has fixed several recently identified critical Linux kernel vulnerabilities in July 2024. These vulnerabilities primarily affect Microsoft Azure clou…
On July 24, 2024, OpenSSL took an extraordinary step toward improving community engagement and realigning with its core values when it announced the implementa…
Japanese organizations are the target of a Chinese nation-state threat actor that leverages malware families like LODEINFO and NOOPDOOR to harvest sensitive in…
We’ll TL;DR the FUDdy introduction: we all know that phishing attacks are on the rise in scale and complexity, that AI is enabling more sophisticated attacks t…
A new malicious campaign has been observed making use of malicious Android apps to steal users' SMS messages since at least February 2022 as part of a large-sc…
Companies in Russia and Moldova have been the target of a phishing campaign orchestrated by a little-known cyber espionage group known as XDSpy.The findings co…
As Linux admins, protecting our sensitive data and securing our systems against the growing threat of Linux malware is a crucial concern. After all, none of us…
Cybersecurity researchers have detailed widespread phishing campaigns targeting small and medium-sized businesses (SMBs) in Poland during May 2024 that led to …
Learn about critical threats that can impact your organization and the bad actors behind them from Cybersixgill’s threat experts. Each story shines a light on …
The nation-state threat actor known as SideWinder has been attributed to a new cyber espionage campaign targeting ports and maritime facilities in the Indian O…
Cybersecurity researchers are warning about a new phishing campaign that targets Microsoft OneDrive users with the aim of executing a malicious PowerShell scri…
A recently patched security flaw impacting VMware ESXi hypervisors has been actively exploited by "several" ransomware groups to gain elevated permissions and …
Researchers highlighted a serious privacy and security flaw that keeps deleted and private repositories retained…GitHub Design Flaw Retains Deleted, Private Re…
Google Chrome users recently faced hours-long trouble when the browser’s password manager feature developed a…Google Chrome Password Manager Flaw Triggered Out…