The flaws could allow attackers to access and modify data, and cause system unavailability and request-response desynchronization.
Hi, what are you looking for?
The flaws could allow attackers to access and modify data, and cause system unavailability and request-response desynchronization.
Multiple state-sponsored APTs are compromising poorly secured devices across critical infrastructure sector networks.
UK-based cybersecurity firm Valarian has raised a total of $70 million for its ACRA technology.
A threat actor poisoned several Jscrambler NPM package versions to drop a cross-platform credential stealer.
A new CMMC review and reform task force will conduct a comprehensive review of the program.
Once a notorious blackhat hacker, McGraw shares his journey from high school hacking and prison to redemption as a cybersecurity advocate.
Significant cybersecurity M&A deals announced by 1Password, Accenture, Cisco, F5, Rubrik, and SailPoint.
Unauthenticated attackers could obtain the broker's confidential OAuth client secret, allowing them to take control of the broker.
The flaw results in malicious code embedded in crafted emails being executed when the emails are opened.
The move targeted people and entities accused of links to an online spying network that the EU claims targeted governments and carried out sabotage operations against critical infrastructure.
Threat actors have been targeting Balbooa Forms and iCagenda Joomla extension flaws for remote code execution.
The company notified customers to manually shut down their servers while it is investigating a credible threat.
The WorldLeaks extortion group claimed to have stolen 720 GB of data from the healthcare testing and laboratory services provider.
Multiple campaigns are using ghost accounts to map GitHub organizations, including their repositories and members.
Other noteworthy stories that might have slipped under the radar: Abnormal AI sued by Anthropic, AssuranceAmerica data breach affects 7 million people, NSA brings back TAO.
Angelo Martino, a former ransomware negotiator, was sentenced to 70 months for helping the BlackCat/Alphv group.
Both foes and allies have targeted the Balochistan Police force in Pakistan for at least two years, according to SentinelOne.
The attackers call victims to direct them to phishing websites mirroring Microsoft Entra ID login pages.
The backdoor’s destructive capabilities include a standalone wiper, ransomware encryption, and a multi-pass wiping command.
Researchers demonstrate adversarial hallucination squatting against popular AI assistants to achieve remote code execution.