Most of the top frequently exploited vulnerabilities in 2023 were initially exploited as zero-days, according to data from government agencies.
Hi, what are you looking for?
Most of the top frequently exploited vulnerabilities in 2023 were initially exploited as zero-days, according to data from government agencies.
Ivanti has released fixes for dozens of vulnerabilities in Endpoint Manager, Avalanche, Connect Secure, Policy Secure, and Secure Access Client.
Zoom Apps security updates resolve six vulnerabilities and Chrome 131 stable is rolling out with 12 security fixes.
Citrix and Fortinet have released patches for multiple vulnerabilities, including high-severity bugs in NetScaler and FortiOS.
Cybersecurity incident impacts Giant Food, Hannaford, and other Ahold Delhaize USA brands, including pharmacies and e-commerce services.
SAP has released eight new security notes on November 2024 patch day, including one addressing a high-severity vulnerability in Web Dispatcher.
Hot Topic has suffered a data breach impacting approximately 57 million unique email addresses and the personal information of roughly 25 million.
A new feature in the latest iOS release reportedly reboots locked devices that have not been unlocked for longer periods of time.
The FBI is seeing an increase in threat actors using fake emergency data requests to harvest information from US companies.
Forth says the personal information of 1.5 million people was compromised in a May 2024 data breach.
Veeam has released a hotfix for a high-severity authentication bypass vulnerability in Backup Enterprise Manager.
D-Link warns of a critical-severity command injection vulnerability impacting multiple discontinued NAS models.
Malwarebytes has acquired Sweden-based privacy-focused VPN provider AzireVPN to expand its product offerings.
ZDI discloses vulnerabilities in the infotainment system of multiple Mazda car models that could lead to code execution.
Texas-based oilfield supplier Newpark Resources says a ransomware attack disrupted information systems and business applications.
HPE this week warned of two critical vulnerabilities in Aruba Networking access points that could lead to unauthenticated command injection.
Impersonating legitimate software such as Foxit PDF Editor and AutoCAD, the SteelFox crimeware bundle steals user information.
A critical vulnerability in Cisco Unified Industrial Wireless software could allow remote, unauthenticated attackers to inject commands with root privileges.
Vehicle tracking services for Serco, DHL, and other fleets were disrupted after Microlise fell victim to a cyberattack.
Starting this month, Google Cloud will be rolling out mandatory MFA for all users who sign in with a password.