Collected every two hours from specialised publications — each link leads to the original article.
Cloudflare on Thursday said it mitigated thousands of hyper-volumetric HTTP distributed denial-of-service (DDoS) attacks that exploited a recently disclosed fl…
Heads up, Chrome users! Google has just released a major security update for its Chrome…Another Chrome Zero-Day Under Attack Received A Fix on Latest Hacking N…
Google has assigned a new CVE identifier for a critical security flaw in the libwebp image library for rendering images in theWebP formatthat has come under ac…
Threat actors associated with North Korea arecontinuingtotargetthe cybersecurity community using a zero-day bug in an unspecified software over the past severa…
Updates to Kubernetes for F38 and F39. Security fixes for CVE-2023-3955 and CVE-2023-3676. Related update for rawhide already in stable. Update for F37 is curr…
Google researchers recently reported a vulnerability in Intel CPUs leading to a new “Downfall” side-channel…Intel Patched Newly Reported Downfall Attack Affect…
[BLACK HAT] Googlers have lately found not one but two more security vulnerabilities in Intel and AMD processors that can be exploited to steal sensitive data …
Exposed Kubernetes (K8s) clusters are being exploited by malicious actors to deploy cryptocurrency miners and other backdoors.Cloud security firm Aqua, in arep…
While the use of Infrastructure as Code (IaC) has gained significant popularity as organizations embrace cloud computing and DevOps practices, the speed and fl…
A suspected China-nexus threat actor dubbed UNC4841 has been linked to the exploitation of a recently patched zero-day flaw in Barracuda Email Security Gateway…
At least half of dozen GitHub accounts from fake researchers associated with a fraudulent cybersecurity company have been observed pushing malicious repositori…
A new strain of malicious software that's engineered to penetrate and disrupt critical systems in industrial environments has been unearthed.Google-owned threa…
Several security vulnerabilities have been disclosed in cloud management platforms associated with three industrial cellular router vendors that could expose o…
Three new security flaws have been disclosed in Microsoft Azure API Management service that could be abused by malicious actors to gain access to sensitive inf…
Microsoft has patched a misconfiguration issue impacting the Azure Active Directory (AAD) identity and access management service that exposed several "high-imp…
A number of zero-day vulnerabilities that were addressed last year were exploited by commercial spyware vendors to target Android and iOS devices, Google's Thr…
As many as 55 zero-day vulnerabilities were exploited in the wild in 2022, with most of the flaws discovered in software from Microsoft, Google, and Apple.Whil…
Remote code execution on feed enrichment. If "Extract full content from HTML5 and Google AMP" has been enabled for one or more feed subscriptions it is possibl…
A pair of severe security vulnerabilities have been disclosed in the Jenkins open source automation server that could lead to code execution on targeted system…
At the beginning of January, Gcore faced an incident involving several L3/L4 DDoS attacks with a peak volume of 650 Gbps. Attackers exploited over 2000 servers…
An unknown threat actor created malicious game modes for the Dota 2 multiplayer online battle arena (MOBA) video game that could have been exploited to establi…
Researchers have devised a ChromeOS exploit that unlocks enterprise-managed Chromebooks. While Google is addressing the…New SH1MMER ChromeOS Exploit Jailbreaks…
Security stakeholders have come to realize that the prominent role the browser has in the modern corporate environment requires a re-evaluation of how it is ma…
A suspected China-nexus threat actor exploited a recently patched vulnerability in Fortinet FortiOS SSL-VPN as a zero-day in attacks targeting a European gover…