The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Several important security vulnerabilities have been found in the c-ares fork of the ares library, including a 0-byte UDP payload denial of service (DoS) bug (…
Progress Software on Thursdaydiscloseda third vulnerability impacting its MOVEit Transfer application, as the Cl0p cybercrime gang deployed extortion tactics a…
A suspected China-nexus threat actor dubbed UNC4841 has been linked to the exploitation of a recently patched zero-day flaw in Barracuda Email Security Gateway…
This week marked the arrival of monthly scheduled Microsoft Patch Tuesday updates for June 2023.…Microsoft Patch Tuesday June Arrived With 77 Vulnerability Fix…
In what's a new kind of software supply chain attack aimed at open source projects, it has emerged that threat actors could seize control of expired Amazon S3 …
Two "dangerous" security vulnerabilities have been disclosed in Microsoft Azure Bastion and Azure Container Registry that could have been exploited to carry ou…
Hackers are impersonating cybersecurity researchers on Twitter and GitHub to publish fake proof-of-concept exploits for zero-day vulnerabilities that infect Wi…
At least half of dozen GitHub accounts from fake researchers associated with a fraudulent cybersecurity company have been observed pushing malicious repositori…
A security flaw has been uncovered in the WooCommerce Stripe Gateway WordPress plugin that could lead to the unauthorized disclosure of sensitive information.T…
It might come as a surprise, but secrets management has become the elephant in the AppSec room. While security vulnerabilities like Common Vulnerabilities and …
Fortinet on Monday disclosed that anewly patched critical flawimpacting FortiOS and FortiProxy may have been "exploited in a limited number of cases" in attack…
A fully undetectable (FUD) malware obfuscation engine namedBatCloakis being used to deploy various malware strains since September 2022, while persistently eva…
Security vulnerabilities discovered in Honda's e-commerce platform could have been exploited to gain unrestricted access to sensitive dealer information."Broke…
Two important security bugs have been found in Ruby. It was discovered that an HTTP response splitting flaw exists in the Ruby cgi gem before 0.1.0.2, 0.2.x be…
Progress Software, the company behind the MOVEit Transfer application, has released patches to address brand new SQL injection vulnerabilities affecting the fi…
Details have emerged about a now-patched actively exploited security flaw in Microsoft Windows that could be abused by a threat actor to gain elevated privileg…
Details have emerged about a now-patched actively exploited security flaw in Microsoft Windows that could be abused by a threat actor to gain elevated privileg…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have published a joint advisory regarding the active…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have published a joint advisory regarding the active…
APIs, more formally known as application programming interfaces, empower apps and microservices to communicate and share data. However, this level of connectiv…
An Improper Validation of Array Index vulnerability (CVE-2023-0950) was discovered in the spreadsheet component of The Document Foundation LibreOffice 7.4 vers…
Multiple important denial of service (DoS) vulnerabilities (CVE-2023-0464 and CVE-2023-2650) have been discovered in the OpenSSL Secure Sockets Layer toolkit. …
VMware hasreleasedsecurity updates to fix a trio of flaws in Aria Operations for Networks that could result in information disclosure and remote code execution…
IoT cybersecurity company Sternum has identified a security vulnerability affecting Zyxel Networks' Linux-operated NAS drives, including NAS326, NAS540, and NA…