The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
* bsc#1236539 Cross-References: * CVE-2024-11704 * CVE-2025-1009
* bsc#1236596 Cross-References: * CVE-2024-11187
The North Korea-linked nation-state hacking group known as Kimsuky has been observed conducting spear-phishing attacks to deliver an information stealer malwar…
* bsc#1236518 Cross-References: * CVE-2023-45288
* bsc#1236518 Cross-References: * CVE-2023-45288
* bsc#1236518 Cross-References: * CVE-2023-45288
* bsc#1219437 * bsc#1234089 Cross-References: * CVE-2024-2365
2024 was marked by numerous critical incidents that highlighted the importance of robust Linux security measures among admins. One notable event was when Utils…
The Russian nation-state actor tracked as Secret Blizzard has been observed leveraging malware associated with other threat actors to deploy a known backdoor c…
* bsc#1233651 * bsc#1233702 * bsc#1233703 Cross-References:
* bsc#1233651 * bsc#1233702 * bsc#1233703 Cross-References:
* bsc#1233650 * bsc#1233695 Cross-References: * CVE-2024-11691
* bsc#1233651 * bsc#1233702 * bsc#1233703 Cross-References:
The Russia-aligned threat actor known as RomCom has been linked to the zero-day exploitation of two security flaws, one in Mozilla Firefox and the other in Mic…
The North Korea-linked threat actor known as Sapphire Sleet is estimated to have stolen more than $10 million worth of cryptocurrency as part of social enginee…
This is the .NET 9.0 GA release. It contains security fixes for CVE-2024-43498 and CVE-2024-43499 Announcement: https://devblogs.microsoft.com/dotnet/announcin…
The threat actor known as Mysterious Elephant has been observed using an advanced version of malware called Asyncshell.The attack campaign is said to have used…
This is the .NET 9.0 GA release. It contains security fixes for CVE-2024-43498 and CVE-2024-43499 Announcement: https://devblogs.microsoft.com/dotnet/announcin…
A newly patched security flaw impacting Windows NT LAN Manager (NTLM) was exploited as a zero-day by a suspected Russia-linked actor as part of cyber attacks t…
Cybersecurity threats have reached a new level of prevalence and sophistication, and innovative methods and tools are urgently needed to protect sensitive info…
The Computer Emergency Response Team of Ukraine (CERT-UA) has detailed a new malicious email campaign targeting government agencies, enterprises, and military …
Identity security is front, and center given all the recent breaches that include Microsoft, Okta, Cloudflare and Snowflake to name a few. Organizations are st…
Nation-state threat actors backed by Beijing broke into a "handful" of U.S. internet service providers (ISPs) as part of a cyber espionage campaign orchestrate…
An Iranian advanced persistent threat (APT) threat actor likely affiliated with the Ministry of Intelligence and Security (MOIS) is now acting as an initial ac…