The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A researcher found a severe cross-site scripting (XSS) vulnerability in the Zoom Whiteboard app. Zoom…Serious XSS Vulnerability Found In Zoom Whiteboard on Lat…
Researchers discovered numerous vulnerabilities in the credential manager “Passwordstate” that could leave stored passwords exposed.…Passwordstate Vulnerabilit…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) hasaddedtwo years-old security flaws impacting TIBCO Software's JasperReports product to its K…
This week, Microsoft rolled out its monthly scheduled updates for Windows systems. The December Patch…Microsoft Patch Tuesday For December 2022 Fixes Two Zero-…
Thousands of Citrix Application Delivery Controller (ADC) and Gateway endpoints remain vulnerable to two critical security flaws disclosed by the company over …
Intel engineers had submitted support for Linear Address Masking (LAM) with the recently-closed Linux 6.2 merge window but it was rejected by Linus Torvalds . …
Merry Christmas, Linux systems administrators: Here's a kernel vulnerability with a CVSS score of 10 in your SMB server for the holiday season giving an unauth…
Most businesses running SMB servers are believed to be shielded but one expert likened potential exploits to Heartbleed.
Multiple high-severity vulnerabilities have been disclosed in Passwordstate password management solution that could be exploited by an unauthenticated remote a…
Cybersecurity researchers have detailed two security flaws in the JavaScript-based blogging platform known asGhost, one of which could be abused to elevate pri…
Threat actors affiliated with a ransomware strain known as Play are leveraging a never-before-seen exploit chain that bypasses blocking rules for ProxyNotShell…
The patch management process can be painful, tedious, and time and labor intensive. Often, all this effort is for no other purpose than to maintain the operati…
Microsoft has disclosed details of a now-patched security flaw in Apple macOS that could be exploited by an attacker to get around security protections imposed…
AWS has patched a vulnerability in its Elastic Container Registry (ECR) that was uncovered by Lightspin researcher Gafnit Amiga during an examination of AWS's …
Samba has released software updates to remediate multiple vulnerabilities that, if successfully exploited, could allow an attacker to take control of affected …
Government entities in Ukraine have been breached as part of a new campaign that leveraged trojanized versions of Windows 10 installer files to conduct post-ex…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) hasaddedtwo vulnerabilities impacting Veeam Backup & Replication software to its Known Exploit…
Microsoft has revised the severity of a security vulnerability it originallypatched in September 2022, upgrading it to "Critical" after it emerged that it coul…
Web applications, often in the form of Software as a Service (SaaS), are now the cornerstone for businesses all over the world. SaaS solutions have revolutioni…
Tech giant Microsoft released its last set of monthly security updates for 2022 withfixes for 49 vulnerabilitiesacross its software products.Of the 49 bugs, si…
The U.S. National Security Agency (NSA) on Tuesdaysaida threat actor tracked as APT5 has been actively exploiting a zero-day flaw in Citrix Application Deliver…
Apple on Tuesday rolled out security updates to iOS, iPadOS, macOS, tvOS, and Safari web browser to address a new zero-day vulnerability that could result in t…
Google on Tuesday announced the open source availability ofOSV-Scanner, a scanner that aims to offer easy access to vulnerability information about various pro…
Google on Tuesday announced the open source availability ofOSV-Scanner, a scanner that aims to offer easy access to vulnerability information about various pro…