GitLab addressed critical auth bypass flaws in CE and EE

12 months ago

GitLab addressed two critical authentication bypass vulnerabilities in Community Edition (CE) and Enterprise Edition (EE). GitLab released security updates to…

North Korea-linked APT group ScarCruft spotted using new Android spyware KoSpy

12 months ago

North Korea-linked APT group ScarCruft used a new Android spyware dubbed KoSpy to target Korean and English-speaking users. North Korea-linked…

Experts warn of a coordinated surge in the exploitation attempts of SSRF vulnerabilities

12 months ago

Researchers warn of a "coordinated surge" in the exploitation attempts of SSRF vulnerabilities in multiple platforms. Threat intelligence firm GreyNoise…

Meta warns of actively exploited flaw in FreeType library

12 months ago

Meta warned that a vulnerability, tracked as CVE-2025-27363, impacting the FreeType library may have been exploited in the wild. Meta warned that…

Medusa ransomware hit over 300 critical infrastructure organizations until February 2025

12 months ago

The Medusa ransomware operation hit over 300 organizations in critical infrastructure sectors in the United States until February 2025. The…

China-linked APT UNC3886 targets EoL Juniper routers

12 months ago

Mandiant researchers warn that China-linked actors are deploying custom backdoors on Juniper Networks Junos OS MX routers. In mid-2024, Mandiant identified…

U.S. CISA adds six Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog

12 months ago

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds six Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity…

Microsoft Patch Tuesday security updates for March 2025 fix six actively exploited zero-days

12 months ago

Microsoft Patch Tuesday security updates for March 2025 address 56 security vulnerabilities in its products, including six actively exploited zero-days.…

New Ballista Botnet spreads using TP-Link flaw. Is it an Italian job?

12 months ago

The Ballista botnet is exploiting an unpatched TP-Link vulnerability, targeting over 6,000 Archer routers, Cato CTRL researchers warn. Cato CTRL…

Apple fixed the third actively exploited zero-day of 2025

12 months ago

Apple addressed a zero-day vulnerability, tracked as CVE-2025-24201, that has been exploited in "extremely sophisticated" cyber attacks. Apple has released…

This website uses cookies.