Microsoft is offering rewards of up to $15,000 in a new bug bounty program dedicated to its new AI-powered Bing.
Hi, what are you looking for?
Microsoft is offering rewards of up to $15,000 in a new bug bounty program dedicated to its new AI-powered Bing.
Progress Software confirms the SEC has launched its own investigation into costly ransomware zero-days in the MOVEit file transfer software.
A backdoor deployed on a compromised WordPress website poses as a legitimate plugin to hide its presence.
A recently observed phishing campaign targeting Microsoft accounts is using LinkedIn smart links to bypass defenses.
Simpson Manufacturing is experiencing disruptions after taking IT systems offline following a cyberattack.
Citrix has released patches for a critical information disclosure vulnerability in NetScaler ADC and NetScaler Gateway.
CISA, FBI, NSA, and US Treasury published new guidance on improving the security of open source software in OT and ICS.
Google has released Chrome 118 to the stable channel with patches for 20 vulnerabilities, including one rated ‘critical severity’.
CISA has added five bugs to its Known Exploited Vulnerabilities catalog, including the recent WordPad, Skype, and HTTP/2 zero-days.
A Mirai botnet variant tracked as IZ1H9 has updated its arsenal with 13 exploits targeting various routers, IP cameras, and other IoT devices.
SAP has released seven new notes as part of its October 2023 Security Patch Day, all rated ‘medium severity’.
A previously unknown APT group is targeting organizations in biomedical, IT, and manufacturing sectors in Taiwan.
A newly identified Magecart web skimming campaign is tampering with ‘404’ error pages to hide malicious code.
Threat actors are targeting Citrix NetScaler instances unpatched against CVE-2023-3519 to steal user credentials.
A high-severity vulnerability in the data transfer project cURL will be addressed with libcurl and curl updates this week.
The District of Columbia Board of Elections says voter records were compromised in a data breach at hosting provider DataNet.
Google is hosting capture the flag (CTF) events focused on Chrome’s V8 engine and on Kernel-based Virtual Machine (KVM).
A global cybercriminal operation called BadBox has infected the firmware of more than 70,000 Android smartphones, CTV boxes, and tablets with the Triada malware.
US, Ukraine, and Israel remain the most heavily attacked by cyberespionage and cybercrime threat actors, Microsoft says.
CISA and the NSA are urging network defenders and software developers to address the top ten cybersecurity misconfigurations.