Collected every two hours from specialised publications — each link leads to the original article.
A DarkGate malware campaign observed in mid-January 2024 leveraged a recently patched security flaw in Microsoft Windows as a zero-day using bogus software ins…
As the shift of IT infrastructure to cloud-based solutions celebrates its 10-year anniversary, it becomes clear that traditional on-premises approaches to data…
Integrating the Graph for Understanding Artifact Composition (GUAC) in the open-source security framework has tremendous potential to improve software supply c…
The threat actor known as Patchwork likely used romance scam lures to trap victims in Pakistan and India, and infect their Android devices with a remote access…
Google-owned Mandiant said it identified new malware employed by a China-nexus espionage threat actor known as UNC5221 and other threat groups during post-expl…
A financially motivated threat actor known as UNC4990 is leveraging weaponized USB devices as an initial infection vector to target organizations in Italy.Goog…
IaC, or infrastructure as code, is essential to most cloud-based applications. Implementing IaC has advantages that significantly increase the service's charac…
Vulnerable Docker services are being targeted by a novel campaign in which the threat actors are deploying XMRig cryptocurrency miner as well as the 9Hits View…
The Russia-linked threat actor known as COLDRIVER has been observed evolving its tradecraft to go beyond credential harvesting to deliver its first-ever custom…
Google on Tuesday released updates to fix four security issues in its Chrome browser, including an actively exploited zero-day flaw.The issue, tracked as CVE-2…
Google has rolled out security updates for the Chrome web browser to address a high-severity zero-day flaw that it said has been exploited in the wild.The vuln…
Over the past few years, SaaS has developed into the backbone of corporate IT. Service businesses, such as medical practices, law firms, and financial services…
Cybersecurity researchers have discovered 18 malicious loan apps for Android on the Google Play Store that have been collectively downloaded over 12 million ti…
A CACTUS ransomware campaign has been observed exploiting recently disclosed security flaws in a cloud analytics and business intelligence platform called Qlik…
Numerous industries—including technology, financial services, energy, healthcare, and government—are rushing to incorporate cloud-based and containerized web a…
This new product offers SaaS discovery and risk assessment coupled with a free user access review in a unique “freemium” modelSecuring employees' SaaS usage is…
A new cyber attack campaign has been observed using spuriousMSIXWindows app package files for popular software such as Google Chrome, Microsoft Edge, Brave, Gr…
Cloudflare on Thursday said it mitigated thousands of hyper-volumetric HTTP distributed denial-of-service (DDoS) attacks that exploited a recently disclosed fl…
In today's digital landscape, around60%of corporate data now resides in the cloud, with Amazon S3 standing as the backbone of data storage for many major corpo…
Taiwanese networking equipment manufacturer D-Link has confirmed a data breach that led to the exposure of what it said is "low-sensitivity and semi-public inf…
Taiwanese networking equipment manufacturer D-Link has confirmed a data breach that led to the exposure of what it said is "low-sensitivity and semi-public inf…
Heads up, Chrome users! Google has just released a major security update for its Chrome…Another Chrome Zero-Day Under Attack Received A Fix on Latest Hacking N…
Google has assigned a new CVE identifier for a critical security flaw in the libwebp image library for rendering images in theWebP formatthat has come under ac…
Security teams are familiar with threats emanating from third-party applications that employees add to improve their productivity. These apps are inherently de…