The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
VMware hasreleasedsecurity updates to fix a trio of flaws in Aria Operations for Networks that could result in information disclosure and remote code execution…
IoT cybersecurity company Sternum has identified a security vulnerability affecting Zyxel Networks' Linux-operated NAS drives, including NAS326, NAS540, and NA…
Google on Monday released security updates to patch a high-severity flaw in its Chrome web browser that it said is being actively exploited in the wild.Tracked…
The popular password manager KeePass had a severe security vulnerability exposing users’ master passwords in…KeePass Vulnerability Could Expose Master Password…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Mondayplacedtwo recently disclosed flaws in Zyxel firewalls to its Known Exploited Vulnerab…
Cybersecurity researchers have unearthed a new ongoingMagecart-style web skimmer campaign that's designed to steal personally identifiable information (PII) an…
The popular and one of the most-used WordPress plugins, Jetpack recently addressed a critical security…Jetpack Plugin Patched A Critical Vulnerability Triggeri…
A critical flaw in Progress Software's in MOVEit Transfer managed file transfer application has come under widespread exploitation in the wild to take over vul…
A previously unknown advanced persistent threat (APT) is targeting iOS devices as part of a sophisticated and long-running mobile campaign dubbedOperation Tria…
IT hygieneis a security best practice that ensures that digital assets in an organization's environment are secure and running properly. Good IT hygiene includ…
Several buffer overflow vulnerabilities have been identified in ntfs-3g. With a low attack complexity and a high confidentiality, integrity and availability im…
It was discovered that Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1 incorrectly handled uploading multiple files using one form field (CVE-…
Cybersecurity researchers have found "backdoor-like behavior" within Gigabyte systems, which they say enables theUEFI firmwareof the devices to drop a Windows …
Microsoft has shared details of a now-patched flaw in Apple macOS that could be abused by threat actors with root access to bypass security enforcements and pe…
Researchers have found a malicious campaign exploiting seemingly legit YouTube accounts. The campaign involves uploading…This Campaign Delivers Three Malware V…
Enterprise security firm Barracuda on Tuesday disclosed that a recently patched zero-day flaw in its Email Security Gateway (ESG) appliances had been abused by…
Multiple security flaws uncovered in Sonos One wireless speakers could be potentially exploited to achieve information disclosure and remote code execution, th…
In this day and age, vulnerabilities in software and systems pose a considerable danger to businesses, which is why it is essential to have an efficient vulner…
GitLab has recently rolled out an emergency update, patching a critical path traversal vulnerability. Users…GitLab Released Emergency Fix For Critical Vulnerab…
Researchers have discovered an inexpensive attack technique that could be leveraged to brute-force fingerprints on smartphones to bypass user authentication an…
Heads up, WordPress admins! It’s time to update your websites with the latest Beautiful Cookie…XSS Flaw Riddled Beautiful Cookie Consent Banner WP Plugin on La…
A critical security vulnerability has been disclosed in the Open Authorization (OAuth) implementation of the application development framework Expo.io.The shor…
A new security flaw has been disclosed in the Google Cloud Platform's (GCP) Cloud SQL service that could be potentially exploited to obtain access to confident…
The Cybersecurity & Infrastructure Security Agency (CISA) added seven new Linux vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on Friday …