The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
The maintainers of theCurl libraryhave released an advisory warning of two security vulnerabilities that are expected to be addressed as part of an forthcoming…
Apple users need to rush to update their devices once again. A month after patching…Latest iOS Update Fixes Another Zero-Day Flaw Under Attack on Latest Hackin…
Multiple security vulnerabilities have been disclosed in the Intelligent Platform Management Interface (IPMI) firmware for Supermicro baseboard management cont…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesdayaddedtwo security flaws to its Known Exploited Vulnerabilities (KEV) catalog due t…
Apple on Wednesday rolled out security patches to address a new zero-day flaw in iOS and iPadOS that it said has come under active exploitation in the wild.Tra…
The recently patched TeamCity RCE flaw is now under active attack by numerous ransomware gangs.…TeamCity RCE Flaw Actively Exploited To Deploy Ransomware on La…
Microsoft has detailed a new campaign in which attackers unsuccessfully attempted to move laterally to a cloud environmentthrough an SQL Server instance."The a…
Security Configuration Assessment (SCA)is critical to an organization's cybersecurity strategy. SCA aims to discover vulnerabilities and misconfigurations that…
Arm has released security patches to contain a security flaw in the Mali GPU Kernel Driver that has come under active exploitation in the wild.Tracked asCVE-20…
Although Cloudflare provides resilient DDoS protection, a researcher devised a strategy to bypass the security…Cloudflare DDoS Protection Flaws Allowed Securit…
Researchers have discovered a new phishing campaign that exploits Microsoft’s Bing Chat to promote malicious…Hackers Meddle With Bing Chat Ads To Promote Malic…
Heads up, Chrome users! Google has just released a major security update for its Chrome…Another Chrome Zero-Day Under Attack Received A Fix on Latest Hacking N…
Researchers caught a serious security flaw in JetBrains TeamCity software that could allow unauthenticated code…Critical Security Flaw Found In JetBrains TeamC…
A high-severity security flaw has been disclosed in the open-source OpenRefine data cleanup and transformation tool that could result in arbitrary code executi…
Multiple security vulnerabilities have been disclosed in theExim mail transfer agentthat, if successfully exploited, could result in information disclosure and…
Progress Software has released hotfixes for a critical security vulnerability, alongside seven other flaws, in the WS_FTP Server Ad hoc Transfer Module and in …
Cisco is warning of attempted exploitation of a security flaw in its IOS Software and IOS XE Software that could permit an authenticated remote attacker to ach…
Cybersecurity agencies from Japan and the U.S. have warned of attacks mounted by a state-backed hacking group from China to stealthily tamper with branch route…
The landscape of browser security has undergone significant changes over the past decade. While Browser Isolation was once considered the gold standard for pro…
Google on Wednesday rolled out fixes to address a new actively exploited zero-day in the Chrome browser.Tracked asCVE-2023-5217, the high-severity vulnerabilit…
Heads up, Apple users! Researchers have caught active exploitation of three zero-day flaws in Apple…Apple Zero-Day Flaws Exploited For Predator Spyware Attacks…
A novel side-channel attack calledGPU.ziprenders virtually all modern graphics processing units (GPU) vulnerable to information leakage."This channel exploits …
Google has assigned a new CVE identifier for a critical security flaw in the libwebp image library for rendering images in theWebP formatthat has come under ac…
SOC 2, ISO, HIPAA, Cyber Essentials – all the security frameworks and certifications today are an acronym soup that can make even a compliance expert’s head sp…