Huge backdoor discovered that could compromise SSH logins on Linux By James Capell published 31 March 24 Updates required for Debian sid, Fedora 40, Fedora Rawhide, openSUSE Tumbleweed, and openSUSE MicroOS
CitrixBleed 2 flaws are officially here - so get patching or leave your systems at risk By Sead Fadilpašić published 30 June 25 The company recently fixed three major flaws, but worries of a new threat remain.
Fluent Bit vulnerability threatens almost all popular cloud platforms By Sead Fadilpašić published 21 May 24 Popular logging tool comes with a major flaw that could result in sensitive information leakage.
CitrixBleed 2 exploits are now in the wild, so patch now By Sead Fadilpašić published 8 July 25 Multiple researchers are warning about CitrixBleed 2, a critical-severity flaw in Citrix NetScaler ADC and NetScaler Gateway.
Google's AI-powered bug hunting tool finds a host of concerning open source security flaws By Sead Fadilpašić published 21 November 24 Among the bugs was a flaw in OpenSSL that could leave users vulnerable.
A critical Erlang/OTP security flaw is "surprisingly easy" to exploit, experts warn - so patch now By Sead Fadilpašić published 18 April 25 A 10/10 bug in the library can trigger RCE, but a patch is already available.
These vulnerabilities in Apache HTTP Server enable HTTP Request Smuggling and SSL Authentication Bypass, posing severe threats to organizations worldwide By Efosa Udinmwen published 7 October 24 Protect your systems by patching Apache HTTP Server and reviewing configurations immediately.
An OpenPGP.js flaw just broke public key cryptography By Sead Fadilpašić published 21 May 25 Researchers found a bug that allowed malicious actors to spoof messages. Users are advised to patch up.
Linux users beware — this security flaw could allow attackers to get root on major distros, so take extra care By Luke Hughes published 31 January 24 Flaw in versions 2.36 and 2.37 of the GNU C (glibc) library could grant unauthorised root access to attackers, bad news helped only by the fact that it’s unlikely to be exploitable remotely.
Don’t fall prey to this worrying Google Chrome exploit – update your browser now By Darren Allan published 21 December 23 Attackers are already exploiting this flaw in Chrome’s security, so be sure to patch quickly.
CISA warns hackers are actively exploiting critical CitrixBleed 2 By Sead Fadilpašić published 14 July 25 CISA adds bug to its Known Exploited Vulnerabilities catalog, giving agencies just a day to patch up.
Wi-Fi software found in many major laptops and smartphones has a major security flaw — here's what you need to know By Sead Fadilpašić published 22 February 24 Do you know which SSID you're connecting to? Researchers find a way to clone it.
An ancient Linux flaw might be opening up users to dangerous cyberattacks By Sead Fadilpašić published 29 March 24 Hackers can easily trick you into giving away your password, or tamper with your clipboard.
Thousands of servers could be at risk due to major OpenSSH security flaw By Sead Fadilpašić published 2 July 24 OpenSSH reintroduced a "glaring hole" four years ago which could allow for full device takeover.
Top Android and iOS apps used by millions could shed unencrypted cloud logins By Sead Fadilpašić published 23 October 24 Almost a dozen popular apps kept hardcoded AWS and Azure cloud credentials.
Bluetooth devices could soon face a whole new level of security threats By Sead Fadilpašić published 30 November 23 Researchers from Eurecom found two vulnerabilities affecting Bluetooth "at a fundamental level".
Xfinity admits data breach may have affected 36 million customers By Sead Fadilpašić published 19 December 23 The Citrix Bleed vulnerability claims another victim as hackers make off with sensitive data of 36 million Xfinity customers.
GitLab critical authentication flaw patched in Community and Enterprise edition By Sead Fadilpašić published 19 September 24 GitLab recommends installing the patch immediately.
Apache HugeGraph users told to patch immediately to stay safe from this dangerous bug By Sead Fadilpašić published 17 July 24 Shadowserver saw criminals scanning for vulnerable endpoints to exploit Apache HugeGraph bug.
Millions of airline customers possibly affected by OAuth security flaw By Sead Fadilpašić published 29 January 25 The bug has since been mitigated, but users should still take care.
SonicWall firewalls hit by worrying cyberattack By Sead Fadilpašić published 17 February 25 Thousands of endpoints are vulnerable, reports have warned
OpenSSH connections could be cracked by this all-new cyberattack By Sead Fadilpašić published 20 December 23 The SSH Binary Packet Protocol is no longer a secure channel, academics have found.
This hugely dangerous new DoS attack could crash web servers with just a single connection By Sead Fadilpašić published 5 April 24 Multiple platforms confirmed being vulnerable to a flaw dubbed CONTINUATION Flood.
OWASP Foundation reveals data breach following Wiki web server issue By Sead Fadilpašić published 2 April 24 Decade-old data was grabbed from OWASP servers.
Ecommerce sites across the world could be at risk from this dangerous security flaw, so patch now By Sead Fadilpašić published 21 June 24 Experts claim to have found a critical flaw in popular ecommerce platforms from Adobe Commerce and Magento, but many users don't seem to care.
Security flaw in top SSH client could let hackers recover cryptographic private keys By Sead Fadilpašić published 17 April 24 Researchers found a way to recover private keys, via a vulnerability in PuTTY.
This popular WordPress security plugin has a worrying flaw which exposed user data By Sead Fadilpašić published 30 October 25 An authenticated WordPress user could read almost any file on the server, including wp-config.php.
Over a million WordPress sites exposed to attack from W3 Total Cache plugin flaw By Sead Fadilpašić published 17 January 25 A recently discovered WordPress plugin flaw allows threat actors to access sensitive information, run unauthorized actions, and more.
Google has fixed the first major Chrome security flaw of 2024 - so here's what you need to know before you update By Sead Fadilpašić published 17 January 24 An out-of-bounds Google Chrome flaw allowed hackers to grab sensitive data from vulnerable endpoints and launch denial of service attacks.
Redis warns major security flaw could be impacting thousands of instances - so patch now By Sead Fadilpašić published 7 October 25 All older versions of the Redis tool are vulnerable, so update ASAP.