The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Published back in November were a set of patches for allowing (e)BPF to extend the Linux kernel's scheduler . That interesting work is continuing with Friday h…
Researchers discovered numerous vulnerabilities in the Yellowfin BI platform that could allow remote code execution…Multiple Vulnerabilities In Yellowfin BI Co…
Researchers discovered multiple vulnerabilities in the LearnPress WordPress plugin, allowing SQL injection and file inclusion…LearnPress Plugin Vulnerabilities…
Researchers are warning about a spike in exploitation attempts weaponizing a now-patched critical remote code execution flaw in Realtek Jungle SDK since the st…
The Internet Systems Consortium (ISC) has released patches to address multiple security vulnerabilities in the Berkeley Internet Name Domain (BIND) 9 Domain Na…
Security stakeholders have come to realize that the prominent role the browser has in the modern corporate environment requires a re-evaluation of how it is ma…
VMware on Tuesday released software to remediate four security vulnerabilities affectingvRealize Log Insight(aka Aria Operations for Logs) that could expose us…
Suspected Chinese hackers exploited a recently disclosed FortiOS SSL-VPN vulnerability as a zero-day in December, targeting a European government and an Africa…
Vulnerability analysis results inOrange Cyberdefenses' Security Navigatorshow that some vulnerabilities first discovered in 1999 are still found in networks to…
Apple has backported fixes for a recently disclosed critical security flaw affecting older devices, citing evidence of active exploitation.The issue, tracked a…
Researchers discovered numerous security vulnerabilities in Samsung’s Galaxy App Store application that threatened Samsung users.…Multiple Vulnerabilities Foun…
A suspected China-nexus threat actor exploited a recently patched vulnerability in Fortinet FortiOS SSL-VPN as a zero-day in attacks targeting a European gover…
A new critical remote code execution (RCE) flaw discovered impacting multiple services related to Microsoft Azure could be exploited by a malicious actor to co…
A new critical remote code execution (RCE) flaw discovered impacting multiple services related to Microsoft Azure could be exploited by a malicious actor to co…
The US government's cybersecurity agency CISA is giving federal agencies an early February deadline to patch a critical -- and already exploited -- security vu…
Experts warn of a critical Linux Kernel vulnerability (CVSS score of 10) impacting SMB servers that can lead to remote code execution.
Security vulnerabilities have been disclosed in Netcomm and TP-Link routers, some of which could be weaponized to achieve remote code execution.The flaws, trac…
A security researcher found a serious prototype pollution vulnerability in Python programming language. Exploiting the…Researcher Finds Class Pollution – A Pro…
Four different Microsoft Azure services have been found vulnerable to server-side request forgery (SSRF) attacks that could be exploited to gain unauthorized a…
A new privilege escalation vulnerability has been identified in the Linux kernel by researcher Davide Ornaghi. This vulnerability might enable a local attacker…
''Log4j has been around for 20 years; it's become embedded into nearly every meaningful Java application; and the Log4Shell event led to compromises in everyth…
A majority of internet-exposed Cacti servers have not been patched against a recently patched critical security vulnerability that has come under active exploi…
Cisco has warned of two security vulnerabilities affecting end-of-life (EoL) Small Business RV016, RV042, RV042G, and RV082 routers that it said will not be fi…
Malicious actors are actively attempting to exploit a recently patched critical vulnerability in Control Web Panel (CWP) that enables elevated privileges and u…