Another zero-day in Apple’s software (CVE-2021-30869) is being actively exploited by attackers, forcing the company to push out security updates for macOS Catalina and iOS 12. About CVE-2021-30869 Flagged...
Hundreds of thousands of email credentials, many of which double as Active Directory domain credentials, came through to credential-trapping domains in clear text. Guardicore security researcher...
Security researchers have found a flaw in the Microsoft Windows Platform Binary Table (WPBT) that could be exploited in easy attacks to install rootkits on all...
Cloud apps are now the most common way digital attackers distribute malware. In the second quarter of 2021, researchers found that 68% of malware downloads originated...
Numerous vulnerabilities have been identified and fixed in Apache HTTP Server 2.4, including high-impact server-side request forgery (SSRF) and request smuggling bugs. The Apache HTTP Server Project is...
A new Chrome browser extension has been released to help bug bounty hunters find keys that have made their way into JavaScript online. The open source extension, now...
Proof-of-concept exploit code for three iOS zero-day vulnerabilities (and a fourth one patched in July) was published on GitHub after Apple delayed patching and failed to credit...
Cisco has patched three critical vulnerabilities affecting components in its IOS XE internetworking operating system powering routers and wireless controllers, or products running with a specific...
Multiple Netgear routers contained a third-party vulnerability that could lead to remote code execution (RCE) via Manipulator-in-the-Middle (MitM) attacks, security researchers have revealed. Now patched, the...
Beego has patched a severe cross-site scripting (XSS) vulnerability that could lead to the compromise of a victim’s session or account. Beego is an open source framework designed for building...