The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Researchers highlighted a serious privacy and security flaw that keeps deleted and private repositories retained…GitHub Design Flaw Retains Deleted, Private Re…
Google Chrome users recently faced hours-long trouble when the browser’s password manager feature developed a…Google Chrome Password Manager Flaw Triggered Out…
A serious security vulnerability in Docker Engine recently received a patch, compelling users to rush…Docker Engine Vulnerability Could Allow AuthZ Bypass on L…
Response from ServiceNow: Based on our investigation to date, we have not observed evidence that…ServiceNow Remote Code Execution Vulnerabilities Under Attack …
Progress Telerik Report Server users must rush to update their systems as the firm patched…Progress Telerik Report Server Vulnerability Allows RCE Attacks on L…
Cybersecurity company Acronis is warning that a now-patched critical security flaw impacting its Cyber Infrastructure (ACI) product has been exploited in the w…
Cybersecurity researchers have disclosed a privilege escalation vulnerability impacting Google Cloud Platform's Cloud Functions service that an attacker could …
The Internet Systems Consortium (ISC) has released patches to address multiple security vulnerabilities in the Berkeley Internet Name Domain (BIND) 9 Domain Na…
A zero-day security flaw in Telegram's mobile app for Android called EvilVideo made it possible for attackers to malicious files disguised as harmless-looking …
In an era where cybersecurity threats loom larger than ever, the discovery of a Remote Code Execution (RCE) vulnerability in OpenSSH by Qualys' Threat Research…
Exim is one of Unix-like systems' most widely used mail transfer agents. It's essential for email delivery and handling and is a significant part of the Intern…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on ev…
Numerous security vulnerabilities riddled the XenForo Internet Forum solution, one of which could even allow…Multiple Vulnerabilities Found In XenForo Internet…
The JavaScript downloader malware known as SocGholish (aka FakeUpdates) is being used to deliver a remote access trojan called AsyncRAT as well as a legitimate…
Cybersecurity firm CrowdStrike, which is facing the heat for causing worldwide IT disruptions by pushing out a flawed update to Windows devices, is now warning…
Let's face it: AppSec and developers often feel like they're on opposing teams. You're battling endless vulnerabilities while they just want to ship code. Soun…
The Cybersecurity and Infrastructure Security Agency (CISA) recently added a new Linux kernel privilege escalation bug ( CVE-2024-1086 ) to its Known Exploited…
Cybersecurity researchers have uncovered security shortcomings in SAP AI Core cloud-based platform for creating and deploying predictive artificial intelligenc…
As the cybersecurity landscape continues to evolve, developers and system administrators have faced several challenges in ensuring the safety of systems writte…
The infamous cybercrime group known as Scattered Spider has incorporated ransomware strains such as RansomHub and Qilin into its arsenal, Microsoft has reveale…
Threat actors are actively exploiting a recently disclosed critical security flaw impacting Apache HugeGraph-Server that could lead to remote code execution at…
WordPress admins running the Modern Events Calendar plugin on their websites must rush to update…Vulnerability In Modern Events Calendar WordPress Plugin Activ…
Researchers revealed that the recently patched Windows MSHTML vulnerability remained under attack for over a…Hackers Exploited Windows MSHTML Vulnerability For…
WordPress admins must update their websites with the latest ProfileGrid plugin release. A severe privilege…ProfileGrid WordPress Plugin Vulnerability Could All…