US-CERT Vulnerability Summary for the Week of April 3, 2023
The CISA Vulnerability Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and...
The CISA Vulnerability Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and...
Threat actors using hacking tools from an Israeli surveillanceware vendor named QuaDream targeted at least five members of civil society...
Here's a hard question to answer: 'How many service accounts do you have in your environment?'. A harder one is:...
Enterprise communications service provider 3CX confirmed that the supply chain attack targeting its desktop application for Windows and macOS was...
It's the second Tuesday of the month, and Microsoft has released another set of security updates to fix a total...
Malware developers have created a thriving market promising to add malicious Android apps to Google Play for $2,000 to $20,000,...
VoIP communications company 3CX confirmed today that a North Korean hacking group was behind last month's supply chain attack. "Based...
The Kodi Foundation has disclosed a data breach after hackers stole the organization's MyBB forum database containing user data and...
Hackers are compromising websites to inject scripts that display fake Google Chrome automatic update errors that distribute malware to unaware...
Microsoft has patched a zero-day vulnerability in the Windows Common Log File System (CLFS), actively exploited by cybercriminals to escalate...
Microsoft and Citizen Lab discovered commercial spyware made by an Israel-based company QuaDream used to compromise the iPhones of high-risk...
Enterprise software vendor SAP has released its April 2023 security updates for several of its products, which includes fixes for...
AI research company OpenAI announced today the launch of a new bug bounty program to allow registered security researchers to...
The CISA Vulnerability Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and...
Malicious loader programs capable of trojanizing Android applications are being traded on the criminal underground for up to $20,000 as...
A "by-design flaw" uncovered in Microsoft Azure could be exploited by attackers to gain access to storage accounts, move laterally...
In today's perilous cyber risk landscape, CISOs and CIOs must defend their organizations against relentless cyber threats, including ransomware, phishing,...
Cybersecurity researchers have detailed the inner workings of the cryptocurrency stealer malware that was distributed via 13 malicious NuGet packages...
The Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to patch two security vulnerabilities actively exploited in the wild...
Yum! Brands, the brand owner of the KFC, Pizza Hut, and Taco Bell fast food chains, is now sending data...
Belgian HR and payroll giant SD Worx has suffered a cyberattack causing them to shut down all IT systems for...
High Vulnerabilities Primary Vendor -- Product Description Published CVSS Score Source & Patch Info grinnellplans -- grinnellplans A vulnerability...
An Estonian national has been charged in the U.S. for purchasing U.S.-made electronics on behalf of the Russian government and...
Threat actors are flooding the npm open source package repository with bogus packages that briefly even resulted in a denial-of-service...