The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Several denial of service (DoS) and code execution vulnerabilities have been discovered in the Vim enhanced vi editor.
Two critical remote code execution (RCE) vulnerabilities have been found in OpenSSH (CVE-2023-28531 and CVE-2023-38408). Because these bugs are simple to explo…
A four-year-old critical security flaw impacting Fortinet FortiOS SSL has emerged as one of the most routinely and frequently exploited vulnerabilities in 2022…
Hundreds of Citrix NetScaler ADC and Gateway servers have been breached by malicious actors to deploy web shells, according to the Shadowserver Foundation.The …
It was discovered that under specific microarchitectural circumstances, a register in "Zen 2" CPUs might not be written to 0 correctly, potentially causing dat…
Several significant out-of-bounds access vulnerabilities have been found in the X.Org X Server (CVE-2021-4008, CVE-2021-4009, and CVE-2021-4011). These flaws t…
Cybersecurity researchers have discovered a bypass for a recently fixed actively exploited vulnerability in some versions of Ivanti Endpoint Manager Mobile (EP…
Linux security is anything but stagnant. It's no secret that cybercriminals are exploiting the growing popularity of the OS and the high-value servers and devi…
Advanced persistent threat (APT) actors exploited a recently disclosed critical flaw impacting Ivanti Endpoint Manager Mobile (EPMM) as a zero-day since at lea…
Researchers found numerous vulnerabilities affecting Peloton Treadmill systems that allow malware attacks. An adversary may…Peloton Treadmill Vulnerabilities R…
Fall of August 1991: Linus Torvalds, a student at the University of Helsinki, creates an operating system as a hobby. The motive? Creating a free, open-source …
Days after the details about a severe zero-day vulnerability in Ivanti mobile management software surfaced…Ivanti Warns Of Another EPMM Zero-Day Flaw Under Att…
Ivanti has disclosed yet another security flaw impacting Endpoint Manager Mobile (EPMM), formerly known as MobileIron Core, that it said has been weaponized as…
Zimbra recently addressed a severe zero-day vulnerability found actively exploited in the wild. While the…Zimbra Patched An XSS Zero-Day Vulnerability Under Ac…
As part ofCheckmarx's missionto help organizations develop and deploy secure software, the Security Research team started looking at the security posture of ma…
Thank you to Ruth Webb for contributing this article.WordPress stands tall as one of the most popular content management systems (CMS), empowering millions of …
AMD recently addressed a critical vulnerability affecting its Zen2 CPUs. Named “Zenbleed,” the researcher who…New Zenbleed Attack Threatens AMD Zen2 CPUs – Pat…
Users of Metabase, a popular business intelligence and data visualization software package, are being advised to update to the latest version following the dis…
Cybersecurity agencies in Australia and the U.S. havepublisheda joint cybersecurity advisory warning against security flaws in web applications that could be e…
Heads up, MikroTik users! The router firm has recently patched a critical-severity privilege escalation flaw…Critical Privilege Escalation Flaw Risks 900K+ Mik…
Cybersecurity researchers have disclosed two high-severity security flaws in the Ubuntu kernel that could pave the way for local privilege escalation attacks.C…
As cloud applications are built, tested and updated, they wind their way through an ever-complex series of different tools and teams. Across hundreds or even t…
Two new Linux kernel privilege escalation flaws have been discovered in the OverlayFS module in Ubuntu, which affect nearly 40% of Ubuntu users (CVE-2023-2640 …
Organizations using the Ivanti EPMM mobile management software must update their systems immediately as hackers…Ivanti Mobile Management Software Zero-Day Unde…