CISA and the Federal Bureau of Investigation (FBI) have released a joint Cybersecurity Advisory identifying active exploitation of a vulnerability — CVE-2021-44077 — in Zoho ManageEngine ServiceDesk Plus....
Security researchers analyzed nine popular WiFi routers and found a total of 226 potential vulnerabilities in them, even when running the latest firmware. The tested routers...
Email authentication checks could be hoodwinked by phishing emails impersonating nearly 200 Australian organizations due to a vulnerability discovered more than two years after its conception. Now fixed,...
The mishandling of HTTP headers left websites built on top of the Symfony platform vulnerable to web cache poisoning attacks. Symfony, a popular PHP framework for web applications,...
HP has patched two high-severity flaws impacting more than 150 of its multifunction printers (MFPs) that could allow attackers to seize control of vulnerable devices, steal...
Russia and China continue to engage in IP theft to bolster their defense technology and economic standing, respectively. The National Counterintelligence and Security Center urges action....
Researchers have released a new fuzzing tool used for finding novel HTTP request smuggling techniques. The tool, dubbed ‘T-Reqs’, was built by a team from Northeastern University,...
Researchers have disclosed 13 vulnerabilities in the Nucleus TCP/IP stack, the worst of which can be used to remotely execute code. On November 9, Forescout Research...
A “serious” security flaw affecting around six million Sky routers left customers open to hackers for more than 17 months, researchers have said. The security issue...
A URL parsing bug left an internal Google Cloud project open to server-side request forgery (SSRF) attacks, security researcher David Schütz has found. Now fixed, the bug, which...