Attackers are attempting to exploit a critical RCE flaw in Apache Struts 2 after researchers publish PoC code.
Hi, what are you looking for?
Attackers are attempting to exploit a critical RCE flaw in Apache Struts 2 after researchers publish PoC code.
GambleForce uses SQL injections to hack gambling, government, retail, and travel websites to steal sensitive information.
Microsoft disrupts Storm-1152, a cybercrime-as-a-service business facilitating phishing, identity theft, and DDoS attacks.
US, UK, and Poland warn of Russia-linked cyberespionage group’s broad exploitation of recent TeamCity vulnerability.
Cybersecurity startup Zero Networks has raised $20 million in a Series B funding round led by US Venture Partners.
CISA is asking for public opinion on SCuBA secure configuration baselines for nine Google Workspace services.
A Chrome 120 security update resolves nine vulnerabilities, including five high-severity flaws reported externally.
Sophos has patched EOL Firewall versions against a critical flaw exploited in the wild, after identifying a new exploit.
SAP patches multiple vulnerabilities in the Business Technology Platform, including a critical elevation of privilege bug.
Critical remote code execution flaws in Backup Migration and Elementor plugins expose WordPress sites to attacks.
A recent emergence on the threat landscape, the Sandman APT appears linked to a Chinese hacking group.
Toyota Germany is informing customers that their personal data has been stolen in a ransomware attack last month.
Researchers call attention to 14 security defects that can be exploited to drop and freeze 5G connections on smartphones and routers.
Compromised data includes names, dates of birth, Social Security numbers, health and insurance information, and driver’s license numbers.
North Korean hackers have used Dlang-based malware in attacks against manufacturing, agriculture, and physical security organizations.
Apache has addressed a critical-severity Struts 2 file upload vulnerability that could lead to remote code execution.
French startup ProvenRun raises €15 million investment to build secure software for connected vehicles and IoT devices.
WordPress 6.4.2 patches a flaw that could be chained with another vulnerability to execute arbitrary code.
Russian threat actor APT28 has been exploiting a no-interaction Outlook vulnerability in attacks against 14 countries.
A Bluetooth authentication bypass allows attackers to connect to vulnerable Android, Linux, and Apple devices and inject keystrokes.