The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
This week marked the Redmond giant Microsoft’s monthly security updates for its products. With Patch…Microsoft Patch Tuesday November Fixes 63 Flaws, Including…
Researchers have found a new malware exploiting Atlassian Confluence vulnerabilities. Identified as Effluence, the new…Atlassian Confluence Vulnerabilities Exp…
Intel has released fixes to close out a high-severity flaw codenamedReptarthat impacts its desktop, mobile, and server CPUs.Tracked asCVE-2023-23583(CVSS score…
Microsoft has released fixes to address63 security bugsin its software for the month of November 2023, including three vulnerabilities that have come under act…
VMware is warning of a critical and unpatched security flaw in Cloud Director that could be exploited by a malicious actor to get around authentication protect…
A group of academics has disclosed a new "software fault attack" on AMD's Secure Encrypted Virtualization (SEV) technology that could be potentially exploited …
Researchers spotted a couple of security vulnerabilities in PureVPN Desktop clients for Linux that impact…Multiple Vulnerabilities Found In PureVPN – One Remai…
The threat actor known as Lace Tempest has been linked to the exploitation of a zero-day flaw in SysAid IT support software in limited attacks, according to ne…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesdayaddeda high-severity flaw in the Service Location Protocol (SLP) to its Known Expl…
Multiple ransomware groups have begun to actively exploit recently disclosed flaws in Atlassian Confluence and Apache ActiveMQ.Cybersecurity firm Rapid7saidit …
After announcing the upgradation of the CVSS 3.0 scoring system in June, this week, FIRST…CVSS 4.0 Arrived As The New Vulnerability Scoring Standard on Latest …
The threat actors linked toKinsinghave been observed attempting to exploit the recently disclosed Linux privilege escalation flaw called Looney Tunables as par…
The Forum of Incident Response and Security Teams (FIRST) has officially announcedCVSS v4.0, the next generation of the Common Vulnerability Scoring System sta…
Cybersecurity researchers are warning of suspected exploitation of a recently disclosed critical security flaw in the Apache ActiveMQ open-source message broke…
F5 is warning of active abuse of a critical security flaw in BIG-IP less than a week after its public disclosure, resulting in the execution of arbitrary syste…
Atlassian has warned of a critical security flaw in Confluence Data Center and Server that could result in "significant data loss if exploited by an unauthenti…
A critical security flaw existed in the F5 BIG-IP Configuration utility that allows an adversary…Critical F5 BIG-IP Flaw Allows Remote Code Execution Attacks o…
Heads up, phpFox users! A critical remote code execution vulnerability existed in the phpFox service…Critical PHPFox RCE Vulnerability Risked Social Networks o…
Days after back-to-back disclosures about actively exploited zero-day vulnerabilities, Cisco has finally patched them with…Patches Released For The Actively Ex…
Three unpatched high-severity security flaws have been disclosed in theNGINX Ingress controllerfor Kubernetes that could be weaponized by a threat actor to ste…
F5 has alerted customers of a critical security vulnerability impacting BIG-IP that could result in unauthenticated remote code execution.The issue, rooted in …
Cloudflare on Thursday said it mitigated thousands of hyper-volumetric HTTP distributed denial-of-service (DDoS) attacks that exploited a recently disclosed fl…
VMware has released security updates to address a critical flaw in the vCenter Server that could result in remote code execution on affected systems.The issue,…
Virtualization services provider VMware has alerted customers to the existence of a proof-of-concept (PoC) exploit for a recently patched security flaw in Aria…