Atlassian and Cisco have released patches for multiple high-severity vulnerabilities, including remote code execution bugs.
Hi, what are you looking for?
Atlassian and Cisco have released patches for multiple high-severity vulnerabilities, including remote code execution bugs.
The Chinese state-sponsored group Mustang Panda has used new and updated malicious tools in a recent attack.
Windows versions of the BrickStorm backdoor that the Chinese APT used in the MITRE hack last year have been active for years.
In recent attacks, the state-sponsored backdoor BPFDoor is using a controller to open a reverse shell and move laterally.
A critical vulnerability in Apache Roller could be used to maintain persistent access by reusing older sessions even after password changes.
Chrome 135 and Firefox 137 updates have been rolled out with patches for critical- and high-severity vulnerabilities.
Oracle’s April 2025 Critical Patch Update contains 378 security patches that resolve approximately 180 unique CVEs.
Lemonade says the incident is not material and that its operations were not compromised, nor was its customer data targeted.
DaVita has not named the ransomware group behind the incident or share details on the attacker’s ransom demands.
The business services provider confirms personal information such as names and Social Security numbers was stolen in a January cyberattack.
In fresh filings, Landmark Admin and Young Consulting say data breaches back in 2024 impacted more people than initially estimated.
The funding round brings the total amount raised by the NetRise to roughly $25 million.
Customers of the Hertz, Thrifty, and Dollar brands had their personal information stolen as a result of the Cleo hack last year.
A threat actor claims to offer a zero-day exploit for an unauthenticated remote code execution vulnerability in Fortinet firewalls.
Organizations in the healthcare and pharmaceutical sectors have been targeted with ResolverRAT, a new malware family with advanced capabilities.
Researchers uncover new software supply chain threat from LLM-generated package hallucinations.
Threat actors are publishing malicious NPM packages to steal PayPal credentials and hijack cryptocurrency transfers.
A vulnerability in the OttoKit WordPress plugin with over 100,000 active installations has been exploited in the wild.
SonicWall has released fixes for three vulnerabilities in NetExtender for Windows, including a high-severity bug.
Laboratory Services Cooperative says the personal and medical information of 1.6 million was stolen in an October 2024 data breach.