Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Important Fix for c-ares DoS Bug Released

Several important security vulnerabilities have been found in the c-ares fork of the ares library, including a 0-byte UDP payload denial of service (DoS) bug (…

The Hacker News
The Hacker News Breaches & leaks

Third Flaw Uncovered in MOVEit Transfer App Amidst Cl0p Ransomware Mass Attack

Progress Software on Thursdaydiscloseda third vulnerability impacting its MOVEit Transfer application, as the Cl0p cybercrime gang deployed extortion tactics a…

The Hacker News
The Hacker News Vulnerabilities

Chinese UNC4841 Group Exploits Zero-Day Flaw in Barracuda Email Security Gateway

A suspected China-nexus threat actor dubbed UNC4841 has been linked to the exploitation of a recently patched zero-day flaw in Barracuda Email Security Gateway…

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities

Microsoft Patch Tuesday June Arrived With 77 Vulnerability Fixes

This week marked the arrival of monthly scheduled Microsoft Patch Tuesday updates for June 2023.…Microsoft Patch Tuesday June Arrived With 77 Vulnerability Fix…

The Hacker News
The Hacker News Breaches & leaks

New Supply Chain Attack Exploits Abandoned S3 Buckets to Distribute Malicious Binaries

In what's a new kind of software supply chain attack aimed at open source projects, it has emerged that threat actors could seize control of expired Amazon S3 …

AWS

The Hacker News
The Hacker News Breaches & leaks

Severe Vulnerabilities Reported in Microsoft Azure Bastion and Container Registry

Two "dangerous" security vulnerabilities have been disclosed in Microsoft Azure Bastion and Azure Container Registry that could have been exploited to carry ou…

Azure Docker

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Fake Zero-Day PoC Exploits on GitHub Push Windows, Linux Malware

Hackers are impersonating cybersecurity researchers on Twitter and GitHub to publish fake proof-of-concept exploits for zero-day vulnerabilities that infect Wi…

Linux Windows GitHub

The Hacker News
The Hacker News Vulnerabilities

Fake Researcher Profiles Spread Malware through GitHub Repositories as PoC Exploits

At least half of dozen GitHub accounts from fake researchers associated with a fraudulent cybersecurity company have been observed pushing malicious repositori…

Exchange GitHub Chrome

The Hacker News
The Hacker News Vulnerabilities

Critical Security Vulnerability Discovered in WooCommerce Stripe Gateway Plugin

A security flaw has been uncovered in the WooCommerce Stripe Gateway WordPress plugin that could lead to the unauthorized disclosure of sensitive information.T…

WordPress

The Hacker News
The Hacker News Vulnerabilities

Over Half of Security Leaders Lack Confidence in Protecting App Secrets, Study Reveals

It might come as a surprise, but secrets management has become the elephant in the AppSec room. While security vulnerabilities like Common Vulnerabilities and …

The Hacker News
The Hacker News Vulnerabilities

Critical FortiOS and FortiProxy Vulnerability Likely Exploited - Patch Now!

Fortinet on Monday disclosed that anewly patched critical flawimpacting FortiOS and FortiProxy may have been "exploited in a limited number of cases" in attack…

Fortinet

The Hacker News
The Hacker News Vulnerabilities

Cybercriminals Using Powerful BatCloak Engine to Make Malware Fully Undetectable

A fully undetectable (FUD) malware obfuscation engine namedBatCloakis being used to deploy various malware strains since September 2022, while persistently eva…

The Hacker News
The Hacker News Vulnerabilities

Password Reset Hack Exposed in Honda's E-Commerce Platform, Dealers Data at Risk

Security vulnerabilities discovered in Honda's e-commerce platform could have been exploited to gain unrestricted access to sensitive dealer information."Broke…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Multiple Ruby Info Disclosure Vulns Fixed

Two important security bugs have been found in Ruby. It was discovered that an HTTP response splitting flaw exists in the Ruby cgi gem before 0.1.0.2, 0.2.x be…

The Hacker News
The Hacker News Vulnerabilities

New Critical MOVEit Transfer SQL Injection Vulnerabilities Discovered - Patch Now!

Progress Software, the company behind the MOVEit Transfer application, has released patches to address brand new SQL injection vulnerabilities affecting the fi…

The Hacker News
The Hacker News Vulnerabilities

Experts Unveil PoC Exploit for Recent Windows Vulnerability Under Active Exploitation

Details have emerged about a now-patched actively exploited security flaw in Microsoft Windows that could be abused by a threat actor to gain elevated privileg…

Windows

The Hacker News
The Hacker News Vulnerabilities

Experts Unveil Exploit for Recent Windows Vulnerability Under Active Exploitation

Details have emerged about a now-patched actively exploited security flaw in Microsoft Windows that could be abused by a threat actor to gain elevated privileg…

Windows

The Hacker News
The Hacker News Breaches & leaks

Clop Ransomware Gang Likely Exploiting MOVEit Transfer Vulnerability Since 2021

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have published a joint advisory regarding the active…

The Hacker News
The Hacker News Breaches & leaks

Clop Ransomware Gang Likely Aware of MOVEit Transfer Vulnerability Since 2021

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have published a joint advisory regarding the active…

The Hacker News
The Hacker News Vulnerabilities

How to Improve Your API Security Posture

APIs, more formally known as application programming interfaces, empower apps and microservices to communicate and share data. However, this level of connectiv…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Critical LibreOffice Code Execution Vuln Fixed

An Improper Validation of Array Index vulnerability (CVE-2023-0950) was discovered in the spreadsheet component of The Document Foundation LibreOffice 7.4 vers…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Multiple Easily Exploitable OpenSSL DoS Bugs Fixed

Multiple important denial of service (DoS) vulnerabilities (CVE-2023-0464 and CVE-2023-2650) have been discovered in the OpenSSL Secure Sockets Layer toolkit. …

OpenSSL

The Hacker News
The Hacker News Vulnerabilities

Urgent Security Updates: Cisco and VMware Address Critical Vulnerabilities

VMware hasreleasedsecurity updates to fix a trio of flaws in Aria Operations for Networks that could result in information disclosure and remote code execution…

VMware Cisco

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Top NAS Devices Are Being Targeted by This Dangerous Malware

IoT cybersecurity company Sternum has identified a security vulnerability affecting Zyxel Networks' Linux-operated NAS drives, including NAS326, NAS540, and NA…

Linux