A new intelligence report from Proofpoint reveals that TA416, a sophisticated threat actor aligned with Chinese state...
infosec
Budibase, the popular open-source low-code platform used by engineers to rapidly build internal tools, has released urgent...
A critical security vulnerability has been unmasked in Kestra, the popular open-source, event-driven orchestration platform. The flaw,...
A critical security vulnerability has been unmasked in Convoy, the modern KVM server management panel used by...
The Electron framework—the powerhouse behind heavyweights like Visual Studio Code and countless other cross-platform desktop applications —has...
In the world of cybercrime, malware is typically designed for one of two things: stealthy espionage or...
A researcher has publicly disclosed a functional zero-day exploit targeting the internal signature update mechanism of Windows...
Cisco Talos has revealed a major automated credential harvesting campaign, tracked as UAT-10608, that has already compromised...
ThreatLabz has released a deep-dive analysis into the latest iterations of Xloader, a notorious information-stealing malware that...
Researchers from the University of Toronto have demonstrated that Rowhammer attacks on GPUs can move far beyond...
A new mobile threat is proving that even the most trusted app stores aren’t immune to high-level...
Cybersecurity researchers have shed light on a sophisticated, financially motivated threat actor that has been quietly building...
A new and highly sophisticated malware campaign is exploiting the trust users place in familiar communication platforms....
A sophisticated and carefully orchestrated malware campaign has been uncovered, marking a significant evolution in how attackers...
A new report from Microsoft Threat Intelligence has exposured on Storm-1175, a financially motivated threat actor that...
In a major alert for the WordPress community, a critical security flaw has been disclosed in the...
The popular open-source identity and access management solution Keycloak has released a critical security update, version 26.5.7,...
In a significant discovery for enterprises and public sector organizations, a critical security vulnerability has been unmasked...
Security researchers have disclosed two major vulnerabilities within fast-jwt, a high-performance library used to implement JSON Web...
A severe security failure has been unearthed in Control Web Panel (CWP)—formerly known as CentOS Web Panel—that...
Check Point Research (CPR) has been tracking an extensive password-spraying operation targeting Microsoft 365 environments, conducted by...
As organizations race to integrate autonomous systems into their workflows, a new and subtle threat is emerging...