Collected every two hours from specialised publications — each link leads to the original article.
An updated version of the commodity malware called Legion comes with expanded features to compromise SSH servers and Amazon Web Services (AWS) credentials asso…
Malicious Google Search ads for generative AI services like OpenAI ChatGPT and Midjourney are being used to direct users to sketchy websites as part of a BATLO…
Several security vulnerabilities have been disclosed in cloud management platforms associated with three industrial cellular router vendors that could expose o…
With eBPF monitoring container activity from the kernel layer, many of the challenges associated with observability in the cloud are solved.
Three new security flaws have been disclosed in Microsoft Azure API Management service that could be abused by malicious actors to gain access to sensitive inf…
Stopping new and evasive threats is one of the greatest challenges in cybersecurity. This is among the biggest reasons whyattacks increased dramatically in the…
The browser serves as the primary interface between the on-premises environment, the cloud, and the web in the modern enterprise. Therefore, the browser is als…
The supply chain attack targeting 3CX was the result of a prior supply chain compromise associated with a different company, demonstrating a new level of sophi…
Enterprise communications service provider 3CX confirmed that thesupply chain attacktargeting its desktop application for Windows and macOS was the handiwork o…
The Iranian nation-state group known asMuddyWaterhas been observed carrying out destructive attacks on hybrid environments under the guise of a ransomware oper…
Chromium-based web browsers are the target of a new malware called Rilide that masquerades itself as a seemingly legitimate extension to harvest sensitive data…
Microsoft has patched a misconfiguration issue impacting the Azure Active Directory (AAD) identity and access management service that exposed several "high-imp…
A number of zero-day vulnerabilities that were addressed last year were exploited by commercial spyware vendors to target Android and iOS devices, Google's Thr…
As many as 55 zero-day vulnerabilities were exploited in the wild in 2022, with most of the flaws discovered in software from Microsoft, Google, and Apple.Whil…
Remote code execution on feed enrichment. If "Extract full content from HTML5 and Google AMP" has been enabled for one or more feed subscriptions it is possibl…
A North Korean espionage group tracked asUNC2970has been observed employing previously undocumented malware families as part of a spear-phishing campaign targe…
A pair of severe security vulnerabilities have been disclosed in the Jenkins open source automation server that could lead to code execution on targeted system…
Written by Linux security expert and LinuxSecurity.com Founder Dave Wreski.Attacks targeting Linux have surged in recent years due to the mass migration of wor…
This past January, a SaaS Security Posture Management (SSPM) company named Wing Security (Wing) made waves with thelaunch of its free SaaS-Shadow IT discovery …
IBM said this week it will soon roll out an AI-infused, hybrid-cloud oriented version of its z/OS mainframe operating system.
Microsoft engineers continue to work heavily on enhancing the Linux support for Hyper-V considering that in the Azure public cloud at last report was more than…
Back in 2020 Google and the Open-Source Security Foundation (OpenSSF) came up with a "Criticality Score" to rank the importance/criticality of open-source proj…
At the beginning of January, Gcore faced an incident involving several L3/L4 DDoS attacks with a peak volume of 650 Gbps. Attackers exploited over 2000 servers…
Samsung has announced a new feature called Message Guard that comes with safeguards to protect users from malware and spyware via what's referred to as zero-cl…