The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A new strain of malicious software that's engineered to penetrate and disrupt critical systems in industrial environments has been unearthed.Google-owned threa…
Email protection and network security services provider Barracuda is warning users about a zero-day flaw that it said has been exploited to breach the company'…
Zyxel has released software updates to address two critical security flaws affecting select firewall and VPN products that could be abused by remote attackers …
US CISA recently issued an alert, warning Samsung users about an ASLR bypass flaw being…Samsung ASLR Bypass Flaw Is Actively Exploited – Warns CISA on Latest H…
Several important security issues have been found in the Linux kernel, including a slab-out-of-bound read problem (CVE-2023-1380), a heap out-of-bounds read/wr…
Two important ReDoS issues have been found in the Ruby programming language; one in the URI component (CVE-2023-28755) and one in the Time component (CVE-2023-…
The infamous Lazarus Group actor has been targeting vulnerable versions of Microsoft Internet Information Services (IIS) servers as an initial breach route to …
Several important security issues were identified in the runC Open Container Project. It was discovered that runC incorrectly performed access control when mou…
The identity of the second threat actor behind the Golden Chickens malware has been uncovered courtesy of a "fatal" operational security blunder, cybersecurity…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation of a medium-severity flaw affecting Samsung devices.The issue, t…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of active exploitation of a medium-severity flaw affecting Samsung devices.The issu…
Google recently announced significant updates to its Vulnerability Reward Program for Android OS and devices.…Google Upgrades Its Vulnerability Reward Program …
Apple on Thursdayrolled out security updatesto iOS, iPadOS, macOS, tvOS, watchOS, and the Safari web browser to address dozens of flaws, including three new ze…
The second generation version of Belkin's Wemo Mini Smart Plug has been found to contain a buffer overflow vulnerability that could be weaponized by a threat a…
Several security vulnerabilities have been disclosed in cloud management platforms associated with three industrial cellular router vendors that could expose o…
The Cybersecurity & Infrastructure Security Agency (CISA) added seven new Linux vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on Friday …
Researchers caught Trafficstealer actively abusing Docker Container APIs to redirect users to malicious websites. The…Trafficstealer Exploits Container APIs fo…
WordPress is one of the most popular content management systems in the world due to the ability it gives non-technical, inexperienced users to create professio…
Cybersecurity researchers have discovered an ongoing phishing campaign that makes use of a unique attack chain to deliver theXWorm malwareon targeted systems.S…
As many as five security flaws have been disclosed in Netgear RAX30 routers that could be chained to bypass authentication and achieve remote code execution."S…
U.S. cybersecurity and intelligence agencies have warned of attacks carried out by a threat actor known as theBl00dy Ransomware Gangthat attempt to exploit vul…
A security vulnerability has been disclosed in the popular WordPress pluginEssential Addons for Elementorthat could be potentially exploited to achieve elevate…
A security vulnerability has been disclosed in the popular WordPress pluginEssential Addons for Elementorthat could be potentially exploited to achieve elevate…
According to Forrester, External Attack Surface Management (EASM) emerged as a market category in 2021 and gained popularity in 2022. In a different report, Ga…