Top CMS Sitecore patches critical zero-day flaw being hit by hackers By Sead Fadilpašić published 5 September 25 Sitecore flaw was being used to deploy reconnaissance malware as well as numerous legitimate tools.
UK cybercrime agency blocks nearly 1 billion access attempts to malicious websites By Sead Fadilpašić published 4 December 25 The Share and Defend service was introduced last year and is defending UK netizens from scammers.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware By Sead Fadilpašić published 20 March 25 Virtual disk files allow cybercriminals to bypass security protections.
ESET security scanner vulnerability used to deploy TCESB malware By Sead Fadilpašić published 10 April 25 Kaspersky found a threat actor abusing the popular EPP solution in BYOVD attacks.
Maximum severity vulnerability puts over 1200 SAP NetWeaver servers at risk of hijacking By Sead Fadilpašić published 29 April 25 A workaround and a patch are already available but many firms have already been breached.
Hackers are sneaking malware into SVG images to bypass antivirus - here's what we know By Sead Fadilpašić published 8 September 25 SVG files used to trick people into downloading malicious DLLs.
Microsoft warns critical GoAnywhere security bug is being exploited by ransomware gang, so be on your guard By Sead Fadilpašić published 7 October 25 GoAnywhere bug was discovered and patched weeks ago, but crooks are still using it to drop encryptors.
Sophos is cutting staff following Secureworks deal By Craig Hale published 14 February 25 Sophos is cutting 6% of its jobs following its $859 million acquisition of Secureworks.
Sophos hotfixes remote code execution vulnerabilities in Firewall By Sead Fadilpašić published 23 December 24 Sophos patched three flaws it found in its firewall, including two critical issues.
US government warns agencies to make sure their backups are safe from NAKIVO security issue By Sead Fadilpašić published 21 March 25 A NAKIVO bug patched in November 2024 has been added to CISA's KEV catalog, so update now.
Key trusted Microsoft platform exploited to enable malware, experts warn By Sead Fadilpašić published 24 March 25 Microsoft Trusted Signing is being abused to grant malware short-lived certificates and help it bypass endpoint protection.
Fake CAPTCHAs are being used to spread malware - and we only have ourselves to blame By Ellen Jennings-Trace published 18 March 25 HP research highlights rise in the abuse of verification tests.
BeyondTrust says hackers hit its remote support products By Sead Fadilpašić published 20 December 24 This was not a ransomware attack, BeyondTrust confirms, but users should still be wary.
Hackers are using Google.com to deliver malware by bypassing antivirus software. Here's how to stay safe By Efosa Udinmwen published 14 June 25 A stealthy malware campaign uses Google OAuth URLs to inject dynamic JavaScript attacks that bypass antivirus software.
Microsoft says Russian hackers are planting fake antivirus software in embassy attacks By Ellen Jennings-Trace published 1 August 25 The hackers are using custom malware to target foreign governments.
SonicWall tells admins to patch worrying SSLVPN flaw immediately By Sead Fadilpašić published 9 January 25 A patch is already available, so SonicWall users should update immediately.
SonicWall VPNs are being targeted by a new zero-day in ransomware attacks By Sead Fadilpašić last updated 6 August 25 There's been an uptick in malicious VPN logins lately, but no one knows how they happened yet.
A Windows filetype update may have complicated cyber threat detection efforts By Efosa Udinmwen published 4 January 25 Microsoft's native support for additional archive formats increases bypass risks, Cofense claims.
Citrix patches a trio of high-severity security bugs, so be on your guard By Sead Fadilpašić published 27 August 25 Citrix urges users to apply the patch without delay to stay protected.
Experts warn a maximum severity GoAnywhere MFT flaw is now being exploited as a zero day By Sead Fadilpašić published 29 September 25 Hackers started abusing GoAnywhere MFT bug a week before the patch was released.
Cisco warns a decade-old vulnerability is back and targeting users By Sead Fadilpašić published 4 December 24 Cisco bug was also added to CISA's KEV.
This devious two-step phishing campaign uses Microsoft tools to bypass email security By Efosa Udinmwen published 25 December 24 Advanced phishing exploits blend social engineering with trusted platforms to breach defences.
Thousands of businesses at risk worldwide as new data exfiltration technique uncovered - here's what you need to know By Efosa Udinmwen published 28 April 25 Data Splicing Attacks expose the inability of current DLP tools to detect insider-driven data leaks through browsers.
Google VP says traditional approach to fighting ransomware falls short - points accusatory finger to 'persistent threat on Microsoft Windows and Microsoft Office' By Efosa Udinmwen published 6 October 25 Google unveils AI-powered Drive features to detect ransomware, highlighting Microsoft vulnerabilities, antivirus shortcomings, and layered protection.
DigiCert buys Valimail to boost email security and mitigate growing global phishing threats using DMARC By Efosa Udinmwen published 23 September 25 DigiCert acquires Valimail to integrate zero-trust email authentication, targeting phishing and spoofing threats.
North Korean hackers target South Korea with Internet Explorer vulnerabilities to deploy RokRAT malware By Efosa Udinmwen published 8 December 24 North Korean hacker intensifies cyber-espionage efforts by targeting media organizations and experts in South Korean affairs.
Top file synchronization tool Rsync security flaws mean up to 660,000 servers possibly affected By Sead Fadilpašić published 16 January 25 Security researchers found six flaws in popular Rsync tool including a critical-severity RCE bug.
Veeam urges users to patch security issues which could allow backup hacks By Sead Fadilpašić published 21 March 25 Researchers criticize the way Veeam handled deserialization flaws.
Synology patches critical vulnerabilities, urges users to update devices against zero-click attacks By Efosa Udinmwen published 22 December 24 Synology swiftly patched critical zero-click vulnerabilities in its NAS devices.
Glassworm returns once again with a third round of VS code attacks By Sead Fadilpašić published 2 December 25 The Visual Studio Marketplace and the Open VSX Registry users are targeted once again with infostealing malware.