Security researcher Zhongquan Li has uncovered a critical flaw in macOS InstallAssistant, tracked as CVE-2025-24103 with a...
cybersecurity
Dashlane, the password manager previously offering a free tier, has announced that it will discontinue its free...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-severity alert for a missing authentication...
A newly disclosed vulnerability in 7-Zip, tracked as CVE-2025-55188, has been identified by security researcher Landon. The...
Xerox has released a security update for FreeFlow Core, addressing two high-impact vulnerabilities that could allow attackers...
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a security advisory warning about a critical authentication...
Kaspersky Labs has uncovered a sophisticated, multi-pronged malware operation leveraging fake legal threats, compromised WordPress sites, and...
IBM X-Force has unveiled an in-depth analysis of CastleBot, a newly emerging Malware-as-a-Service (MaaS) framework that is...
Security researcher Jann Horn from Google Project Zero disclosed the technical details and proof-of-concept exploit code for...
Koi Security’s research team has unveiled GreedyBear, a threat group orchestrating industrial-scale cryptocurrency theft through a seamless...
Security researchers at ESET have uncovered a zero-day path traversal vulnerability in the Windows version of WinRAR...
Researchers from Fortinet’s FortiGuard Labs detected a new DarkCloud campaign deploying a stealthy, fileless payload through a...
As families across India prepare to celebrate Raksha Bandhan, cybercriminals are also gearing up — not with...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a risk evaluation warning about multiple high-severity...
Socket’s Threat Research Team has revealed a long-running supply chain attack in the RubyGems ecosystem, where a...
Unit 42 researchers have uncovered a significant shift in the distribution tactics of the DarkCloud Stealer malware,...
9.1 Critical JWE Ruby Flaw (CVE-2025-54887) Bypasses AES-GCM Authentication, Exposing Encrypted Data
9.1 Critical JWE Ruby Flaw (CVE-2025-54887) Bypasses AES-GCM Authentication, Exposing Encrypted Data
A severe security vulnerability has been uncovered in the Ruby implementation of JSON Web Encryption (JWE), tracked...
Google is continuing to strengthen the security of Android 16, introducing a new Advanced Protection Mode that...
Socket’s Threat Research Team has uncovered an alarming wave of malicious Go packages—some still live on GitHub—designed...
Silent Push Threat Analysts have detailed one of today’s most pervasive cyber threats—SocGholish—exposing its deep ties to...