CISA has added five bugs to its Known Exploited Vulnerabilities catalog, including the recent WordPad, Skype, and HTTP/2 zero-days.
Hi, what are you looking for?
CISA has added five bugs to its Known Exploited Vulnerabilities catalog, including the recent WordPad, Skype, and HTTP/2 zero-days.
A Mirai botnet variant tracked as IZ1H9 has updated its arsenal with 13 exploits targeting various routers, IP cameras, and other IoT devices.
SAP has released seven new notes as part of its October 2023 Security Patch Day, all rated ‘medium severity’.
A previously unknown APT group is targeting organizations in biomedical, IT, and manufacturing sectors in Taiwan.
A newly identified Magecart web skimming campaign is tampering with ‘404’ error pages to hide malicious code.
Threat actors are targeting Citrix NetScaler instances unpatched against CVE-2023-3519 to steal user credentials.
A high-severity vulnerability in the data transfer project cURL will be addressed with libcurl and curl updates this week.
The District of Columbia Board of Elections says voter records were compromised in a data breach at hosting provider DataNet.
Google is hosting capture the flag (CTF) events focused on Chrome’s V8 engine and on Kernel-based Virtual Machine (KVM).
A global cybercriminal operation called BadBox has infected the firmware of more than 70,000 Android smartphones, CTV boxes, and tablets with the Triada malware.
US, Ukraine, and Israel remain the most heavily attacked by cyberespionage and cybercrime threat actors, Microsoft says.
CISA and the NSA are urging network defenders and software developers to address the top ten cybersecurity misconfigurations.
GitHub beefs up its secret scanning feature, now allowing users to check the validity of exposed credentials for major cloud services.
ICRC is telling hacktivists involved in conflict during war to avoid targeting civilian objectives and hospitals, or making threats of violence.
New US government guidance details the challenges that application developers and vendors face in identity and access management (IAM).
Threat actor uses typosquatting to trick hundreds of users into downloading a malicious NPM package that delivers the r77 rootkit.
Supermicro has released BMC IPMI firmware updates to address multiple vulnerabilities impacting select motherboard models.
A local privilege escalation vulnerability (CVE-2023-4911) in the GNU C Library (glibc) can be exploited to gain full root privileges.
Google and Yahoo are introducing new requirements for bulk senders, to improve phishing and spam protections.
An open redirection vulnerability in the popular job search platform Indeed has been exploited in a series of phishing attacks.