Google has released the Android Security Bulletin for December 2025, detailing a slate of vulnerabilities affecting the...
zero-day
A sophisticated new cyber espionage campaign has been uncovered by Zscaler Threat Hunting, revealing how a Russia-aligned...
A critical security warning has been issued for users of Twonky Server, the popular media server software...
Fortinet has issued an urgent advisory warning customers that a newly disclosed vulnerability in FortiWeb, tracked as...
Google has issued an urgent, out-of-band security update for the Chrome Stable channel, addressing two separate Type...
The Amazon Threat Intelligence team has uncovered a highly sophisticated threat campaign exploiting multiple zero-day vulnerabilities in...
Microsoft has released its November 2025 Patch Tuesday, addressing a total of 68 vulnerabilities, including a high-priority...
Critical Synology BeeStation Zero-Day (CVE-2025-12686) Found at Pwn2Own Allows Remote Code Execution
Critical Synology BeeStation Zero-Day (CVE-2025-12686) Found at Pwn2Own Allows Remote Code Execution
Synology has released an urgent security update for its BeeStation OS, patching a zero-day vulnerability (CVE-2025-12686) that...
Researchers at Mandiant Threat Defense, part of Google Cloud Security Operations, have revealed that a critical unauthenticated...
QNAP has issued an urgent security advisory and released patches for seven zero-day vulnerabilities that were successfully...
A sophisticated campaign executed by the Chinese state-sponsored threat group BRONZE BUTLER (also known as Tick) has...
Google’s Chromium, developed by Google, forms the foundation of many modern browsers — yet researchers have uncovered...
Developer Jay Gibson recently contacted TechCrunch to recount his experience of being targeted by a state-sponsored spyware...
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Adobe Experience Manager (AEM) vulnerability to...
Microsoft’s October 2025 Patch Tuesday has arrived with one of the largest security updates of the year—193...
After discovering that hackers were exploiting a zero-day vulnerability in the Chakra JavaScript engine used by Internet...
Huntress has sounded the alarm over active exploitation of a newly discovered Local File Inclusion (LFI) vulnerability...
A cross-site scripting (XSS) vulnerability in Synacor Zimbra Collaboration Suite (ZCS) — tracked as CVE-2025-27915 — has...
CrowdStrike has sounded the alarm on an ongoing mass exploitation campaign targeting Oracle E-Business Suite (EBS) applications...
A newly disclosed local privilege escalation vulnerability, CVE-2025-41244, has been exploited as a zero-day in the wild,...