The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
**GLPI version 9.4.4** This is a **security release**, upgrading is highly recommended Non exhaustive list of changes: * [security] Prevent account takeover v…
Watch out Windows users!There's a new strain of malware making rounds on the Internet that has already infected thousands of computers worldwide and most likel…
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called …
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Mic…
A Storm-2945 campaign layers device code phishing onto hijacked hotel Wi-Fi to bypass MFA on Microsoft 365 accounts. Here's how it works and how to shut it off…
ESET researchers identified 11 old and forgotten Linux UEFI shim bootloaders at versions 0.9 and below that can be used to bypass UEFI Secure Boot on any UEFI-…
A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps t…
Over the span of just 14 days, threat actors unleashed more than 81 million login attempts against Microsoft’s Azure command-line interface (CLI). The campaign…
Microsoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed every que…
Within the past year, artificial intelligence copilots and agents have quietly permeated the SaaS applications businesses use every day. Tools like Zoom, Slack…
The threat actor known as EncryptHub is continuing to exploit a now-patched security flaw impacting Microsoft Windows to deliver malicious payloads.Trustwave S…
Generative AI is not arriving with a bang, it’s slowly creeping into the software that companies already use on a daily basis. Whether it is video conferencing…
* bsc#1208752 * bsc#1231844 * bsc#1233343 * bsc#1236510 * bsc#1236515
* bsc#1208752 * bsc#1231844 * bsc#1233343 * bsc#1236510 * bsc#1236515
* bsc#1236596 * bsc#1236597 * bsc#1243361 Cross-References:
The Chinese state-sponsored threat actor known as Mustang Panda has been observed employing a novel technique to evade detection and maintain control over infe…
Details have emerged about a now-patched security vulnerability that could allow a bypass of the Secure Boot mechanism in Unified Extensible Firmware Interface…
As Linux security admins, staying ahead of the curve is paramount, especially regarding the browsers you use and manage. On January 9, 2025, The Linux Foundati…
Cybersecurity researchers have discovered two security flaws in Microsoft's Azure Health Bot Service that, if exploited, could permit a malicious actor to achi…
Threat actors have been observed deploying a malware called NiceRAT to co-opt infected devices into a botnet.The attacks, which target South Korean users, are …
Permissions in SaaS platforms like Salesforce, Workday, and Microsoft 365 are remarkably precise. They spell out exactly which users have access to which data …
A new Python-based hacking tool called FBot has been uncovered targeting web servers, cloud services, content management systems (CMS), and SaaS platforms such…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog ba…
Security teams are familiar with threats emanating from third-party applications that employees add to improve their productivity. These apps are inherently de…