The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Heads up, Zyxel users! The vendors have recently released patches for a serious security vulnerability…Severe OS Command Injection Vulnerability Caught In Zyxe…
Heads up, WordPress admins! Researchers have caught a zero-day vulnerability in the Ultimate Member WordPress…Ultimate Member Plugin Zero-Day Risks 200K+ WordP…
The North Korea-aligned threat actor known as Andariel leveraged a previously undocumented malware called EarlyRat in phishing attacks, adding another piece to…
A critical security flaw has been disclosed in miniOrange'sSocial Login and Register pluginfor WordPress that could enable a malicious actor to log in as any u…
A new process injection technique dubbed Mockingjay could be exploited by threat actors to bypass security solutions to execute malicious code on compromised s…
As the business environment becomes increasingly connected, organizations’ attack surfaces continue to expand, making it challenging to map and secure both kno…
Multiple remotely exploitable denial of service (DoS) and code execution vulnerabilities have been found in the VLC multimedia player and streamer. These bugs …
Fortinet has rolled out updates to address a critical security vulnerability impacting its FortiNAC network access control solution that could lead to the exec…
Security and IT teams are routinely forced to adopt software before fully understanding the security risks. And AI tools are no exception.Employees and busines…
The cybersecurity and technology provider, Fortinet, has recently addressed multiple security flaws affecting FortiNAC systems.…Fortinet Addressed Critical RCE…
Researchers found a severe security vulnerability in Microsoft Teams that allows malware distribution. Specifically, an…Serious IDOR Vulnerability Found In Mic…
The U.S. Cybersecurity and Infrastructure Security Agency hasaddeda batch of six flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of…
Millions of software repositories on GitHub are likely vulnerable to an attack called RepoJacking, a new study has revealed.This includes repositories from org…
Several important denial of service (DoS) and information disclosure vulnerabilities have been discovered in the OpenJDK Java runtime. These bugs require no pr…
Fourteen important vulnerabilities have been discovered in Chromium, including multiple use-after-free and type confusion bugs. With a low attack complexity an…
A new malware calledCondihas been observed exploiting a security vulnerability in TP-Link Archer AX21 (AX1800) Wi-Fi routers to rope the devices into a distrib…
VMware has flagged that a recently patched critical command injection vulnerability in Aria Operations for Networks (formerly vRealize Network Insight) has com…
Zyxel has rolled out security updates to address a critical security flaw in its network-attached storage (NAS) devices that could result in the execution of a…
Taiwanese company ASUS on Mondayreleased firmware updatesto address, among other issues, nine security bugs impacting a wide range of router models.Of the nine…
A new threat has emerged that exploits a vulnerability in Microsoft Teams. This attack, known…Understanding the Microsoft Teams Vulnerability: The GIFShell Att…
SMS delivery reports not only let the sender know about the message receipt, but can…This Side-Channel Attack Exploits SMS Delivery Reports To Retrieve Locatio…
A critical security flaw in the WooCommerce plugin Stripe Payment Gateway risked users’ safety. Exploiting…Stripe Payment Gateway Plugin Patched Serious IDOR F…
Fortinet recently patched a critical pre-authentication RCE flaw in its Fortigate firmware. The vulnerability only…Fortinet Quietly Patched Pre-Auth RCE Flaw I…
While the use of Infrastructure as Code (IaC) has gained significant popularity as organizations embrace cloud computing and DevOps practices, the speed and fl…