The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A now-patched security flaw in Microsoft Outlook could be exploited by threat actors to access NT LAN Manager (NTLM) v2 hashed passwords when opening a special…
GitHub has revealed that it has rotated some keys in response to a security vulnerability that could be potentially exploited to gain access to credentials wit…
Microsoft’s security team researchers discovered numerous security vulnerabilities in the Perforce Helix Core Server platform.…Multiple Vulnerabilities Found I…
Attackers are weaponizing an old Microsoft Office vulnerability as part of phishing campaigns to distribute a strain of malware called Agent Tesla.The infectio…
Attackers are weaponizing an old Microsoft Office vulnerability as part of phishing campaigns to distribute a strain of malware called Agent Tesla.The infectio…
The threat actor known as Lace Tempest has been linked to the exploitation of a zero-day flaw in SysAid IT support software in limited attacks, according to ne…
Researchers have discovered a new phishing campaign that exploits Microsoft’s Bing Chat to promote malicious…Hackers Meddle With Bing Chat Ads To Promote Malic…
More details have emerged about a set of now-patched cross-site scripting (XSS) flaws in theMicrosoft Azure HDInsightopen-source analytics service that could b…
New findings show that malicious actors could leverage a sneaky malware detection evasion technique and bypass endpoint security solutions by manipulating the …
Microsoft on Thursday disclosed that it found a new version of theBlackCatransomware (aka ALPHV and Noberus) that embeds tools like Impacket and RemCom to faci…
Microsoft researchers discovered numerous vulnerabilities affecting Codesys PLC that risked power plants’ security with various…Multiple Codesys PLC Vulnerabil…
At least half of dozen GitHub accounts from fake researchers associated with a fraudulent cybersecurity company have been observed pushing malicious repositori…
Details have emerged about a now-patched actively exploited security flaw in Microsoft Windows that could be abused by a threat actor to gain elevated privileg…
Details have emerged about a now-patched actively exploited security flaw in Microsoft Windows that could be abused by a threat actor to gain elevated privileg…
Cybersecurity researchers have shared details about a now-patched security flaw in Windows MSHTML platform that could be abused to bypass integrity protections…
Threat actors are employing a previously undocumented "defense evasion tool" dubbed AuKill that's designed to disable endpoint detection and response (EDR) sof…
ceph 16.2.12 GA Security fix for CVE-2022-3650
Several out of bounds memory access and buffer overflows were fixed in xrdp, an open source project which provides a graphical login to remote machines using M…
As many as 55 zero-day vulnerabilities were exploited in the wild in 2022, with most of the flaws discovered in software from Microsoft, Google, and Apple.Whil…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) hasaddeda high-severity flaw affecting the ZK Framework to its Known Exploited Vulnerabilities…
The threat actors behind theKinsingcryptojacking operation have been spotted exploiting misconfigured and exposed PostgreSQL servers to obtain initial access t…
Threat actors affiliated with a ransomware strain known as Play are leveraging a never-before-seen exploit chain that bypasses blocking rules for ProxyNotShell…
Red Hat JBoss Web Server 5.7.1 zip release is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, and Microsoft Windows. Red Hat Product …
A malicious campaign targeting the Middle East is likely linked toBackdoorDiplomacy, an advanced persistent threat (APT) group with ties to China.The espionage…