An improper input validation flaw in Kyocera Device Manager allows attackers to capture credentials, compromise accounts.
Hi, what are you looking for?
An improper input validation flaw in Kyocera Device Manager allows attackers to capture credentials, compromise accounts.
SAP has released patches for critical vulnerabilities in Business Application Studio, Web IDE, and Edge Integration Cell.
Android’s first security update of 2024 resolves high-severity elevation of privilege and information disclosure vulnerabilities.
CISA has added a critical-severity Apache Superset flaw (CVE-2023-27524) to its Known Exploited Vulnerabilities catalog.
Researchers at Securonix warn that Turkish threat actors are targeting organizations in the Americas and Europe with ransomware campaigns.
Mortgage lending firm LoanDepot has disclosed a cyberattack resulting in data encryption and system disruptions.
The LockBit ransomware gang claims to have stolen over 7 terabytes of data from hospital system Capital Health.
QNAP has released patches for a dozen vulnerabilities in its products, including several high-severity flaws.
Turkish state-sponsored group Sea Turtle has been targeting multiple organizations in the Netherlands for espionage.
Self-hosted GitHub Actions runners could allow attackers to inject malicious code into repositories, leading to supply chain attacks.
Global law firm Orrick, Herrington & Sutcliffe disclosed a data breach that affects a roughly 600,000 individuals.
SpectralBlur is a new macOS backdoor that shows similarities with North Korean hacking group’s KandyKorn malware.
CVE-2023-39336, a critical vulnerability in Ivanti EPM, may lead to device takeover and code execution on the server.
A Nigerian national arrested in Ghana faces charges in the US for a BEC scheme involving two charitable organizations.
Vigilant Ops receives $2 million seed investment from DataTribe to help organizations manage SBOMs.
Google has released a Chrome 120 update to resolve six vulnerabilities, including four reported by external researchers.
HealthEC says personal information received from business partners was compromised in a July 2023 data breach.
Estes Express Lines is informing over 21,000 individuals that their personal information was stolen in a ransomware attack.
The personal information of more than 900,000 individuals was stolen in a data breach at Fallon Ambulance Service.
A vulnerability in Google’s authentication process allows malware to restore cookies and hijack user sessions.