The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A new strain of malware developed by threat actors likely affiliated with the FIN7 cybercrime group has been put to use by the members of the now-defunct Conti…
Several high-impact security vulnerabilities were recently discovered and fixed in the Linux kernel. These flaws could result in memory exhaustion, system cras…
Google has recently rolled out the latest Chrome release with a zero-day fix. This Chrome…Google Patched High-Severity Zero-Day Flaw With Latest Chrome Release…
The Spectre vulnerability that has haunted hardware and software makers since 2018 continues to defy efforts to bury it.
Google on Friday released out-of-band updates to resolve an actively exploited zero-day flaw in its Chrome web browser, making it the first such bug to be addr…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) hasaddedtwo vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, based on evi…
Google on Thursday outlined a set of initiatives aimed at improving the vulnerability management ecosystem and establishing greater transparency measures aroun…
An emerging Python-based credential harvester and a hacking tool named Legion is being marketed via Telegram as a way for threat actors to break into various o…
This week marked the scheduled release of monthly security updates from Microsoft. With April 2023…Microsoft Patch Tuesday April Fixed 97 Flaws Including 1 Zer…
OpenAI, the company behind the massively popular ChatGPT AI chatbot, has launched abug bounty programin an attempt to ensure its systems are "safe and secure."…
It's the second Tuesday of the month, and Microsoft has released another set of security updates to fixa total of 97 flawsimpacting its software, one of which …
Over one million WordPress websites are estimated to have been infected by an ongoing campaign to deploy malware calledBalada Injectorsince 2017.The massive ca…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday addedfive security flawsto its Known Exploited Vulnerabilities (KEV) catalog, citing…
A serious vulnerability existed in the popular WordPress plugin Elementor Pro that could allow website…Severe Elementor Pro WP Plugin Vulnerability Actively Ex…
Apple's decision to support MAC Address Randomization across its platforms may provide some degree of protection against a newly-identified Wi-Fi flaw research…
Microsoft has patched a misconfiguration issue impacting the Azure Active Directory (AAD) identity and access management service that exposed several "high-imp…
Critical security flaws in Cacti, Realtek, and IBM Aspera Faspex are being exploited by various threat actors in hacks targeting unpatched systems.This entails…
Unknown threat actors are actively exploiting a recently patched security vulnerability in the Elementor Pro website builder plugin for WordPress.The flaw, des…
The advanced persistent threat (APT) actor known as Winter Vivern is now targeting officials in Europe and the U.S. as part of an ongoing cyber espionage campa…
Researchers have discovered a major security vulnerability in the WiFi protocol that risks data exposure…Study Reveals WiFi Protocol Vulnerability Exposing Net…
Taiwanese hardware vendor QNAP warns customers to secure their Linux-powered network-attached storage (NAS) devices against a high-severity Sudo privilege esca…
For over a decade now the X.Org Server has been seeing routine security disclosures in its massive codebase with some security researchers saying it's even wor…
Enterprise communications software maker 3CX on Thursday confirmed that multiple versions of its desktop app for Windows and macOS are affected by asupply chai…
Details have emerged about a now-patched vulnerability in Azure Service Fabric Explorer (SFX) that could lead to unauthenticated remote code execution.Tracked …