The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Thethree zero-day flawsaddressed by Apple on September 21, 2023, were leveraged as part of an iPhone exploit chain in an attempt to deliver a spyware strain ca…
The maintainers of Free Download Manager (FDM) have acknowledged a security incident dating back to 2020 that led to its website being used to distribute malic…
A malicious actor released a fake proof-of-concept (PoC) exploit for a recently disclosed WinRAR vulnerability on GitHub with an aim to infect users who downlo…
A malicious actor released a fake proof-of-concept (PoC) exploit for a recently disclosed WinRAR vulnerability on GitHub with an aim to infect users who downlo…
Multiple security flaws have been disclosed in the Nagios XI network monitoring software that could result in privilege escalation and information disclosure.T…
GitLab has shipped security patches to resolve a critical flaw that allows an attacker to run pipelines as another user.The issue, tracked asCVE-2023-5009(CVSS…
Cybersecurity company Trend Micro hasreleasedpatches and hotfixes to address a critical security flaw in Apex One and Worry-Free Business Security solutions fo…
Recently, a cryptocurrency firm, Fortress Trust, disclosed a theft of $15 million following a cyber…Google Authenticator Flaw Inadvertently Facilitated $15 Mil…
New research has found that close to 12,000 internet-exposed Juniper firewall devices are vulnerable to a recently disclosed remote code execution flaw.VulnChe…
A researcher found an interesting vulnerability in Windows 11 Themes that could allow arbitrary code…ThemeBleed – Code Execution Vulnerability In Windows 11 Th…
A critical buffer overflow vulnerability has been found in c-ares before 1_16_1 thru 1_17_0 via the function ares_parse_soa_reply in ares_parse_soa_reply.c ( C…
Multiple severe, remotely exploitable security vulnerabilities have been found in Chromium, including out-of-bounds memory access in V8, CSS, and Fonts ( CVE-2…
A critical memory safety bug has been discovered in Thunderbird 115.0 and Thunderbird 102.13 ( CVE-2023-4056 ). Due to the severity of this vulnerability's thr…
This week marked the release of the monthly scheduled security fixes from Microsoft. With the…Microsoft Fixed 59 Bugs With September 2023 Patch Tuesday on Late…
A high-severity security flaw has been disclosed in N-Able's Take Control Agent that could be exploited by a local unprivileged attacker to gain SYSTEM privile…
Three interrelated high-severity security flaws discovered in Kubernetes could be exploited to achieve remote code execution with elevated privileges on Window…
More details have emerged about a set of now-patched cross-site scripting (XSS) flaws in theMicrosoft Azure HDInsightopen-source analytics service that could b…
A critical vulnerability was found in the OpenDMARC open-source implementation of the DMARC specification. It was discovered that OpenDMARC through 1.3.2 and 1…
We do not often talk about Linux malware because it is often quickly patched up and not exploited much in the wild compared to Windows/macOS. However, there ha…
Adobe'sPatch Tuesday updatefor September 2023 comes with a patch for a critical actively exploited security flaw in Acrobat and Reader that could permit an att…
A new vulnerability disclosed in GitHub could have exposed thousands of repositories at risk of repojacking attacks, new findings show.The flaw "could allow an…
One of the new Linux networking features we've been looking forward to seeing in the kernel is TCP Authentication Option (TCP-AO / RFC5925) as a means of impro…
Google on Monday rolled out out-of-band security patches to address a critical security flaw in its Chrome web browser that it said has been exploited in the w…
Apple recently patched two vulnerabilities actively exploited in the wild to target iPhones. The researchers…Apple Patched Two iOS Zero-Day Flaws Exploited In …