GitLab CE and EE updates resolve 14 vulnerabilities, including a critical- and three high-severity bugs.
Hi, what are you looking for?
GitLab CE and EE updates resolve 14 vulnerabilities, including a critical- and three high-severity bugs.
Most critical open source software contains code written in a memory unsafe language, US, Australian, and Canadian government agencies warn.
CISA on Wednesday warned that three older flaws in GeoServer, Linux kernel, and Roundcube webmail are exploited in the wild.
Aqua Security shows that code in repositories remains accessible even after being deleted or overwritten, continuing to leak secrets.
Google has disrupted over 175,000 YouTube and Blogger instances related to the Chinese influence operation Dragonbridge.
The P2Pinfect worm targeting Redis servers has been updated with ransomware and cryptocurrency mining payloads.
More than 100,000 websites are affected by a supply chain attack injecting malware via a Polyfill domain.
A Mirai-like botnet has started exploiting a critical-severity vulnerability in discontinued Zyxel NAS products.
CoinStats says North Korean hackers drained $2 million in virtual assets from 1,590 cryptocurrency wallets.
Five WordPress plugins were injected with malicious code that creates a new administrative account.
Google has released a Chrome security update to resolve four high-severity use-after-free vulnerabilities.
LivaNova USA says the personal and medical information of 130,000 individuals was compromised in an October 2023 data breach.
The US has announced charges against four Vietnamese nationals for hacking businesses and causing $71 million in losses.
The Los Angeles County Department of Health Services discloses a data breach caused by push notification spamming attack.
A hacker claims to have stolen the information of 30 million users from TEG subsidiary Ticketek.
Santander US is notifying over 12,000 employees that their personal information was compromised in a data breach.
Threat actors are exploiting a recent path traversal vulnerability in SolarWinds Serv-U using public PoC code.
CISA says CFATS program data was likely accessed after an Ivanti Connect Secure appliance was hacked in January.
A years-long espionage campaign has targeted telecoms companies in Asia with tools associated with Chinese groups.
Pomerium raises $13.75 million in Series A funding for dynamic user identity verification and access management platform.