The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Researchers highlighted numerous security vulnerabilities affecting the Intel Trust Domain Extensions (TDX). Exploiting these vulnerabilities…Numerous Vulnerab…
Researchers spotted a severe unpatched remote code execution vulnerability shipped by default in Apache Superset.…Apache Superset Shipped With Unpatched RCE Vu…
Git 2.40.1 has been released to address three new security vulnerabilities being disclosed, which have been classified as ''high-severity'' by the National Vul…
Nuclei is a fast and efficient vulnerability scanner that allows penetration testers to automate the…Nuclei Cheatsheet: The Go-to Resource for Penetration Test…
Git 2.40.1 is out today due to three new security vulnerabilities being disclosed. Due to those security fixes there are also Git updates for prior stable seri…
Microsoft has confirmed that theactive exploitation of PaperCut serversis linked to attacks that are designed to deliver Cl0p and LockBit ransomware families.T…
The maintainers of theApache Supersetopen source data visualization software have released fixes to plug an insecure default configuration that could lead to r…
Details have emerged about a high-severity security vulnerability impacting Service Location Protocol (SLP) that could be weaponized to launch volumetric denia…
Managing vulnerabilities in the constantly evolving technological landscape is a difficult task. Although vulnerabilities emerge regularly, not all vulnerabili…
The print management software firm PaperCut has recently alerted users about two severe vulnerabilities that…CISA Warns Of PaperCut Print Software Vulnerabilit…
Threat actors are employing a previously undocumented "defense evasion tool" dubbed AuKill that's designed to disable endpoint detection and response (EDR) sof…
Researchers found active exploitation of the Eval PHP WordPress plugin to deploy backdoors on target…Hackers Abuse Outdated Eval PHP WordPress Plugin To Deploy…
A severe zero-day vulnerability, identified as the “GhostToken” flaw, could allow an adversary to infect…GhostToken Zero-Day Vulnerability Found In Google Clou…
Cybersecurity researchers have disclosed details of a now-patched zero-day flaw in Google Cloud Platform (GCP) that could have enabled threat actors to conceal…
Several high-impact remotely exploitable vulnerabilities were recently discovered in the popular Chromium free and open-source web browser. These issues could …
Cisco and VMware have released security updates to address critical security flaws in their products that could be exploited by malicious actors to execute arb…
A chain of two critical flaws has been disclosed in Alibaba Cloud's ApsaraDB RDS for PostgreSQL and AnalyticDB for PostgreSQL that could be exploited to breach…
Researchers have found new malware targeting web browsers in active campaigns. Identified as the Zaraza…Zaraza Malware Exploits Web Browsers To Steal Stored Pa…
Fortra, the company behind Cobalt Strike, shed light on a zero-day remote code execution (RCE) vulnerability in its GoAnywhere MFT tool that has come underacti…
Following a high-severity zero-day fix, Google has patched another severe zero-day vulnerability in its Chrome…Google Patched Second Chrome Zero-Day Within A W…
Google on Tuesday rolled out emergency fixes to address another actively exploited high-severity zero-day flaw in its Chrome web browser.The flaw, tracked asCV…
Canonical, the company behind Ubuntu, has announced that Hardware Enablement (HWE) kernels will receive updates via the Livepatch service, just like Long-Term …
A new strain of malware developed by threat actors likely affiliated with the FIN7 cybercrime group has been put to use by the members of the now-defunct Conti…
Several high-impact security vulnerabilities were recently discovered and fixed in the Linux kernel. These flaws could result in memory exhaustion, system cras…