After nearly two years of silence, Zloader (a.k.a. Terdot, DELoader, or Silent Night) has returned with new...
cybersecurity
Check Point Research (CPR) has published new findings on Nimbus Manticore, an Iranian state-aligned APT group overlapping...
The Mozilla Foundation has recently announced the launch of a rollback/restore feature for Firefox Add-ons, enabling developers...
SolarWinds has released a hotfix for its Web Help Desk (WHD) software after the discovery of a...
Researchers at Unit 42 uncovered a large-scale search engine optimization (SEO) poisoning campaign, tracked as CL-UNK-1037 and...
The Socket Threat Research Team has uncovered a new malware campaign hiding inside an npm package called...
The CERT Coordination Center (CERT/CC) has issued a vulnerability note warning of a cross-site scripting (XSS) flaw...
Libraesva has released an urgent security advisory addressing a command injection vulnerability (CVE-2025-59689) in its Email Security...
A new report from Hunt Intelligence reveals how attackers are abusing ConnectWise ScreenConnect (formerly ConnectWise Control) to...
A new study from a ZeroSalarium security researcher sheds light on a new technique to bypass endpoint...
The LastPass Threat Intelligence, Mitigation, and Escalation (TIME) team has issued a warning about an ongoing infostealer...
Security researcher Ezzer17 published a clear, methodical write-up that walks through the root cause, the partial fixes,...
CVE-2025-55241: Microsoft Entra ID Flaw with CVSS 10.0 Could Have Compromised Every Tenant Worldwide
CVE-2025-55241: Microsoft Entra ID Flaw with CVSS 10.0 Could Have Compromised Every Tenant Worldwide
In one of the most significant discoveries of 2025, security researcher Dirk-jan Mollema revealed a vulnerability in...
The Varonis Threat Labs team has published an eye-opening report about a persistent vulnerability in how modern...
Zscaler ThreatLabz has uncovered yet another supply chain attack against the Python Package Index (PyPI). In August...
Yarix’s Incident Response Team (YIR) has published an in-depth analysis of a targeted intrusion that leveraged an...
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about multiple critical vulnerabilities in ProGauge...
Researchers at Jamf Threat Labs have uncovered two mobile applications leaking sensitive user data, including credentials and...
Nokia has published a security advisory warning customers of two high-severity vulnerabilities affecting its CloudBand Infrastructure Software...
HubSpot has issued a security advisory regarding a critical flaw in its Jinjava template engine, which powers...
The Cybersecurity and Infrastructure Security Agency (CISA) has published a new Malware Analysis Report (MAR) detailing how...
A newly disclosed vulnerability in Fortra’s GoAnywhere Managed File Transfer (MFT) platform has been assigned CVE-2025-10035, carrying...