Threat actors have begun exploiting a critical vulnerability in the Apache Struts framework, CVE-2024-53677, just days after...
Vulnerability
A serious security flaw has been discovered in Laravel Pulse, a popular real-time application performance monitoring and...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about two critical vulnerabilities...
A critical XML External Entity (XXE) Injection vulnerability, identified as CVE-2024-55875, has been discovered in the http4k...
A critical vulnerability in the Spring Framework, tracked as CVE-2024-38819 (CVSS score 7.5), has been publicly disclosed,...
In a critical revelation highlighting the vulnerabilities of IoT ecosystems, Team82 has published a report detailing 10...
A critical security vulnerability, tracked as CVE-2024-45337 (CVSS 9.1), has been discovered in the Golang cryptography library....
X41 D-Sec GmbH, a leading cybersecurity firm, has completed a white-box penetration test of the Mullvad VPN...
In a recent investigation, Aqua Nautilus uncovered alarming security vulnerabilities within the Prometheus ecosystem. Their research highlights...
A series of critical security vulnerabilities have been discovered in GLPI (Gestionnaire Libre de Parc Informatique), a...
A recently discovered vulnerability in the popular curl command line tool and library, tracked as CVE-2024-11053 and...
Oasis Security’s research team has unveiled a critical vulnerability in Microsoft Azure’s Multi-Factor Authentication (MFA) system, exposing...
Deep Instinct Security Researcher Eliran Nissan has uncovered a new and potent lateral movement technique, “DCOM Upload...
Over 15,000 Sites at Risk: Woffice WordPress Theme Vulnerabilities Could Lead to Full Site Takeovers
Over 15,000 Sites at Risk: Woffice WordPress Theme Vulnerabilities Could Lead to Full Site Takeovers
Patchstack has disclosed two critical vulnerabilities in the widely used Woffice WordPress theme, a premium intranet/extranet solution...
Akamai security researcher Tomer Peled has unveiled a novel attack technique exploiting Microsoft’s legacy UI Automation framework,...
Dell has released a critical security update to address multiple vulnerabilities impacting several of its enterprise products,...
A critical vulnerability in PDQ Deploy, a software deployment service used by system administrators, has been highlighted...
A significant increase in brute-force attacks targeting outdated and misconfigured Citrix NetScaler devices has been observed in...
A newly discovered vulnerability in Apache Superset, a popular open-source business intelligence platform, could allow attackers to...
A serious vulnerability in the Hunk Companion plugin for WordPress, tracked as CVE-2024-11972 (CVSS 9.8), has been...
Rapid7 Labs and its Managed Detection and Response (MDR) team uncovered a sophisticated modular Java-based Remote Access...
Developers using the popular Apache Struts framework are urged to update their systems immediately following the discovery...