The latest OpenSSH update patches two vulnerabilities, including one that enabled MitM attacks with no user interaction.
Hi, what are you looking for?
The latest OpenSSH update patches two vulnerabilities, including one that enabled MitM attacks with no user interaction.
Google and Mozilla resolve high-severity memory safety vulnerabilities with the latest Chrome and Firefox security updates.
A recently identified macOS infostealer named FrigidStealer has been distributed through a compromised website, as a fake browser update.
Financial software firm Finastra is notifying individuals whose personal information was stolen in a recent data breach.
A newly discovered Golang backdoor is abusing Telegram for communication with its command-and-control (C&C) server.
Microsoft has observed a new variant of the XCSSET malware being used in limited attacks against macOS users.
Israeli cybersecurity startup Dream has raised $100 million in Series B funding and is now valued at $1.1 billion.
A newly identified malware family abuses the Outlook mail service for communication, via the Microsoft Graph API.
Russian hackers have been targeting government, defense, telecoms, and other organizations in a device code phishing campaign.
Xerox released security updates to resolve pass-back attack vulnerabilities in Versalink multifunction printers.
Meta received close to 10,000 vulnerability reports and paid out over $2.3 million in bug bounty rewards in 2024.
The exploitation of a recent SonicWall vulnerability has started shortly after proof-of-concept (PoC) code was published.
China-linked APT Salt Typhoon has been exploiting known vulnerabilities in Cisco devices in attacks on telecom providers in the US and abroad.
Identity management provider SGNL has raised $30 million in a Series A funding round led by Brightmind Partners.
A toolset associated with China-linked espionage intrusions was employed in a ransomware attack, likely by a single individual.
Jscrambler has received a $5.2 million investment from Iberis Capital to accelerate innovation and research.
Threat actors are increasingly exploiting two old vulnerabilities in ThinkPHP and OwnCloud in their attacks.
Google has released a Chrome 133 update to address four high-severity vulnerabilities reported by external researchers.
A subgroup of the Russia-linked Seashell Blizzard is tasked with broad initial access operations to sustain long-term persistence.
Ivanti and Fortinet on Tuesday released patches for multiple critical- and high-severity vulnerabilities in their products.