The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A new malware campaign leveraged two zero-day flaws in Cisco networking gear to deliver custom malware and facilitate covert data collection on target environm…
The Russia-linked nation-state threat actor tracked as APT28 weaponized a security flaw in the Microsoft Windows Print Spooler component to deliver a previousl…
Threat actors are now taking advantage of GitHub's search functionality to trick unsuspecting users looking for popular repositories into downloading spurious …
The malicious code inserted into the open-source library XZ Utils, a widely used package present in major Linux distributions, is also capable of facilitating …
Composer, an application-level dependency manager for the PHP programming language was vulnerable. CVE-2023-43655:
The WINELOADER backdoor used in recent cyber attacks targeting diplomatic entities with wine-tasting phishing lures has been attributed as the handiwork of a h…
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. (CVE-2020-36518) In FasterXML j…
The updated packages fix a security vulnerability: pam_namespace: protect_dir(): use O_DIRECTORY to prevent local DoS situations. (CVE-2024-22365) References:
The maintainers of shim have released version 15.8 to address six security flaws, including a critical bug that could pave the way for remote code execution un…
The maintainers of shim have released version 15.8 to address six security flaws, including a critical bug that could pave the way for remote code execution un…
A now-patched security flaw in Microsoft Outlook could be exploited by threat actors to access NT LAN Manager (NTLM) v2 hashed passwords when opening a special…
Cybersecurity researchers have detected in the wild yet another variant of the Phobos ransomware family known as Faust.Fortinet FortiGuard Labs, which detailed…
GitHub has revealed that it has rotated some keys in response to a security vulnerability that could be potentially exploited to gain access to credentials wit…
Collaboration is a powerful selling point for SaaS applications. Microsoft, Github, Miro, and others promote the collaborative nature of their software applica…
Microsoft’s security team researchers discovered numerous security vulnerabilities in the Perforce Helix Core Server platform.…Multiple Vulnerabilities Found I…
Attackers are weaponizing an old Microsoft Office vulnerability as part of phishing campaigns to distribute a strain of malware called Agent Tesla.The infectio…
Attackers are weaponizing an old Microsoft Office vulnerability as part of phishing campaigns to distribute a strain of malware called Agent Tesla.The infectio…
A new wave of phishing messages distributing the QakBot malware has been observed, more than three months after a law enforcement effort saw its infrastructure…
A new phishing attack has been observed leveraging a Russian-language Microsoft Word document to deliver malware capable of harvesting sensitive information fr…
The threat actor known as Lace Tempest has been linked to the exploitation of a zero-day flaw in SysAid IT support software in limited attacks, according to ne…
A new cyber attack campaign has been observed using spuriousMSIXWindows app package files for popular software such as Google Chrome, Microsoft Edge, Brave, Gr…
A piece of malware known asDarkGatehas been observed being spread via instant messaging platforms such as Skype and Microsoft Teams.In these attacks, the messa…
A Gaza-based threat actor has been linked to a series of cyber attacks aimed at Israeli private-sector energy, defense, and telecommunications organizations.Mi…
Researchers have discovered a new phishing campaign that exploits Microsoft’s Bing Chat to promote malicious…Hackers Meddle With Bing Chat Ads To Promote Malic…