The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A serious security vulnerability affected the WordPress plugin Security Shield, which could allow arbitrary file…Serious Security Vulnerability Patched In Shie…
The operators of Raspberry Robin are now using two new one-day exploits to achieve local privilege escalation, even as the malware continues to be refined and …
IntroductionThe modern software supply chain represents an ever-evolving threat landscape, with each package added to the manifest introducing new attack vecto…
Heads up, Mastodon admins! A critical security vulnerability riddled Mastodon, allowing account takeover by an…Critical Vulnerability Could Allow Mastodon Acco…
As organizations keep more of their customer and business data online, they’re becoming more vulnerable…Tips for Reducing Cybersecurity Risk for Your Business …
The maintainers of shim have released version 15.8 to address six security flaws, including a critical bug that could pave the way for remote code execution un…
The maintainers of shim have released version 15.8 to address six security flaws, including a critical bug that could pave the way for remote code execution un…
SaaS applications are the darlings of the software world. They enable work from anywhere, facilitate collaboration, and offer a cost-effective alternative to o…
The threat actor known as Patchwork likely used romance scam lures to trap victims in Pakistan and India, and infect their Android devices with a remote access…
Multiple security vulnerabilities have recently been discovered in the XOrg Server prior to 21.1.11, and Xwayland display implementations prior to 23.2.4. Thes…
Multiple security vulnerabilities have recently been discovered in the XOrg Server prior to 21.1.11, and Xwayland display implementations prior to 23.2.4. Thes…
The decentralized social network Mastodon has disclosed a critical security flaw that enables malicious actors to impersonate and take over any account."Due to…
The threat actor behind a peer-to-peer (P2P) botnet known as FritzFrog has made a return with a new variant that leverages the Log4Shell vulnerability to propa…
How’s your vulnerability management program doing? Is it effective? A success? Let’s be honest, without the right metrics or analytics, how can you tell how we…
Ivanti has warned all Connect Secure and Policy Secure users to immediately update their systems…Two Ivanti Zero-Day Vulnerabilities Demand Immediate User Atte…
Google-owned Mandiant said it identified new malware employed by a China-nexus espionage threat actor known as UNC5221 and other threat groups during post-expl…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting iOS, iPadOS, macOS, tvOS, and watchOS to its…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting iOS, iPadOS, macOS, tvOS, and watchOS to its…
The networking giant Cisco addressed a severe security flaw affecting its Unified Communications Products. Exploiting…Cisco Fixed Critical RCE Flaw In Unified …
Days after releasing a major update, GitLab rolled out another emergency update addressing a serious…GitLab Patched A Workspace Creation Vulnerability With An …
A pair of recently disclosed zero-day flaws in Ivanti Connect Secure (ICS) virtual private network (VPN) devices have been exploited to deliver a Rust-based pa…
A pair of recently disclosed zero-day flaws in Ivanti Connect Secure (ICS) virtual private network (VPN) devices have been exploited to deliver a Rust-based pa…
IaC, or infrastructure as code, is essential to most cloud-based applications. Implementing IaC has advantages that significantly increase the service's charac…
Each New Year introduces a new set of challenges and opportunities for strengthening our cybersecurity posture. It's the nature of the field – the speed at whi…