A critical vulnerability in the Spring Framework, tracked as CVE-2024-38819 (CVSS score 7.5), has been publicly disclosed,...
Vulnerability
In a critical revelation highlighting the vulnerabilities of IoT ecosystems, Team82 has published a report detailing 10...
A critical security vulnerability, tracked as CVE-2024-45337 (CVSS 9.1), has been discovered in the Golang cryptography library....
X41 D-Sec GmbH, a leading cybersecurity firm, has completed a white-box penetration test of the Mullvad VPN...
In a recent investigation, Aqua Nautilus uncovered alarming security vulnerabilities within the Prometheus ecosystem. Their research highlights...
A series of critical security vulnerabilities have been discovered in GLPI (Gestionnaire Libre de Parc Informatique), a...
A recently discovered vulnerability in the popular curl command line tool and library, tracked as CVE-2024-11053 and...
Oasis Security’s research team has unveiled a critical vulnerability in Microsoft Azure’s Multi-Factor Authentication (MFA) system, exposing...
Deep Instinct Security Researcher Eliran Nissan has uncovered a new and potent lateral movement technique, “DCOM Upload...
Over 15,000 Sites at Risk: Woffice WordPress Theme Vulnerabilities Could Lead to Full Site Takeovers
Over 15,000 Sites at Risk: Woffice WordPress Theme Vulnerabilities Could Lead to Full Site Takeovers
Patchstack has disclosed two critical vulnerabilities in the widely used Woffice WordPress theme, a premium intranet/extranet solution...
Akamai security researcher Tomer Peled has unveiled a novel attack technique exploiting Microsoft’s legacy UI Automation framework,...
Dell has released a critical security update to address multiple vulnerabilities impacting several of its enterprise products,...
A critical vulnerability in PDQ Deploy, a software deployment service used by system administrators, has been highlighted...
A significant increase in brute-force attacks targeting outdated and misconfigured Citrix NetScaler devices has been observed in...
A newly discovered vulnerability in Apache Superset, a popular open-source business intelligence platform, could allow attackers to...
A serious vulnerability in the Hunk Companion plugin for WordPress, tracked as CVE-2024-11972 (CVSS 9.8), has been...
Rapid7 Labs and its Managed Detection and Response (MDR) team uncovered a sophisticated modular Java-based Remote Access...
Developers using the popular Apache Struts framework are urged to update their systems immediately following the discovery...
Organizations using Cleo file transfer software are urged to take immediate action as a critical vulnerability, CVE-2024-50623,...
A collaborative research effort has exposed a significant vulnerability, designated CVE-2024-21944 and named “BadRAM,” that undermines the...