The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Apple began the new year 2024 with a zero-day patch that it simultaneously released for…Apple Begins 2024 Patching A Zero-Day Under Attack on Latest Hacking Ne…
A now-patched security flaw in Microsoft Outlook could be exploited by threat actors to access NT LAN Manager (NTLM) v2 hashed passwords when opening a special…
A severe authentication bypass security flaw riddled the GoAnywhere MFT that could allow creating rogue…Critical Authentication Bypass Flaw Patched In GoAnywhe…
The maintainers of the open-source continuous integration/continuous delivery and deployment (CI/CD) automation software Jenkins have resolved nine security fl…
We analyzed 2,5 million vulnerabilities we discovered in our customer’s assets. This is what we found.Digging into the dataThe dataset we analyze here is repre…
A new Go-based malware loader called CherryLoader has been discovered by threat hunters in the wild to deliver additional payloads onto compromised hosts for f…
Security researchers have identified a malicious tool called "SYSTEMBC" that hackers have been actively exploiting. This tool acts as a SOCKS5 proxy , providin…
The ransomware group known as Kasseika has become the latest to leverage the Bring Your Own Vulnerable Driver (BYOVD) attack to disarm security-related process…
The ransomware group known as Kasseika has become the latest to leverage the Bring Your Own Vulnerable Driver (BYOVD) attack to disarm security-related process…
Several public and popular libraries abandoned but still used in Java and Android applications have been found susceptible to a new software supply chain attac…
Scanning for vulnerabilities in the right places is critically important in securing your Linux environment. While vulnerability scanning initially involved sc…
Researchers spotted a severe security vulnerability in the Bosch thermostat that exposed users to privacy…Serious Vulnerability Spotted In Bosch Thermostat on …
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a now-patched critical flaw impacting Ivanti Endpoint Manager Mobile (EPMM) …
Vulnerable Docker services are being targeted by a novel campaign in which the threat actors are deploying XMRig cryptocurrency miner as well as the 9Hits View…
In today's digital landscape, traditional password-only authentication systems have proven to be vulnerable to a wide range of cyberattacks. To safeguard criti…
GitHub has revealed that it has rotated some keys in response to a security vulnerability that could be potentially exploited to gain access to credentials wit…
Google on Tuesday released updates to fix four security issues in its Chrome browser, including an actively exploited zero-day flaw.The issue, tracked as CVE-2…
Over 178,000 SonicWall firewalls exposed over the internet are exploitable to at least one of the two security flaws that could be potentially exploited to cau…
Heads up, GitLab users! It’s time to upgrade to the latest GitLab versions, as the…GitLab Addressed A Critical Zero-Click Vulnerability With Latest Updates on …
Ivanti has warned users of two zero-day vulnerabilities in its Connect Secure and Policy Secure…Ivanti Patches Connect Secure Zero-day Flaws Under Attack on La…
Thousands of WordPress sites using a vulnerable version of the Popup Builder plugin have been compromised with a malware called Balada Injector.First documente…
Vulnerabilities have been discovered in Bluetooth technology that affect various operating systems. As Linux admins, infosec professionals, Internet security e…
The cyber attacks targeting the energy sector in Denmark last year may not have had the involvement of the Russia-linked Sandworm hacking group, new findings f…
Juniper Networks has released updates to fix a critical remote code execution (RCE) vulnerability in its SRX Series firewalls and EX Series switches.The issue,…