The Python Package Index (PyPI) has removed malware-deploying and data-stealing packages that were collectively downloaded thousands of times. The trio of malicious packages duped unsuspecting users...
In May 2021, a set of five vulnerabilities in Dell computer drivers collectively tracked as CVE-2021-21551 was disclosed and fixed after it remained exploitable for 12 years. However,...
The three sectors paying the highest prices for cyber insurance all fall into the finance industry, according to a new study from AdvisorSmith. The business insurance...
Threat actors are actively exploiting a critical security flaw in Java logging library Apache Log4j. Log4j is an open-source, Java-based logging utility widely used by enterprise...
Computer chip giant Intel has launched a bug bounty program with Belgium-based Intigriti, after switching from rival, US-based ethical hacking platform HackerOne. Intel is applying a 12-month bonus...
A high-severity vulnerability in several cardiac healthcare devices could allow attackers to access privileged accounts without a password and seize control of the devices. The authentication bypass flaw...
A local privilege escalation security vulnerability could allow attackers to gain root access on Ubuntu systems by exploiting a double-free memory corruption bug in GNOME’s AccountsService...
The Christmas holiday shopping season is around the corner and so are the Magecart attackers. Interestingly, these attackers have become more active than ever, with each...
One day in late November, an Australian electricity utility company was attacked. While it was initially suspected that the attack was conducted by Chinese hackers, it...
The MANGA (aka Dark Mirai) botnet operators have been discovered abusing a new vulnerability in the TP-Link TL-WR840N EU V5 that allows remote code execution. The abused flaw Botnets...