A remote code execution (RCE) vulnerability in the client application of Overwolf, the popular gaming development platform, has been patched. The critical flaw (CVE-2021-33501), which has a CVSS...
Many electronic reading (e-reading) systems that support the open EPUB format have significant security vulnerabilities, new research shows. The EPUB format relies primarily on XHTML and...
A newly discovered threat group, Agrius, has been launching damaging wiper attacks aimed at Israeli targets. The malware is masquerading as ransomware to make its state-sponsored...
The bug in HPE SIM makes it easy as pie for attackers to remotely trigger code, no user interaction necessary. Hewlett Packard Enterprise (HPE) has fixed...
SonicWall urges customers to ‘immediately’ patch a post-authentication vulnerability impacting on-premises versions of the Network Security Manager (NSM) multi-tenant firewall management solution. The vulnerability tracked as CVE-2021-20026 affects...
A web server hosting the domain for a local government in the United States was recently breached by advanced hackers taking advantage of old vulnerabilities in...
With the Colonial Pipeline ransomware attacks that caused widespread East Coast fuel shortages still fresh in our minds, new WhiteHat Security research has found that application...
Hewlett Packard Enterprise (HPE) has released a security update to address a zero-day remote code execution vulnerability in the HPE Systems Insight Manager (SIM) software, disclosed...
Offices of multiple Japanese agencies were breached via Fujitsu’s “ProjectWEB” information sharing tool. Fujitsu states that attackers gained unauthorized access to projects that used ProjectWEB, and stole some customer...
Security researchers have traced an argument injection vulnerability in content management systems (CMS) to flaws in Ruby Gem Dragonfly, an image handling library. New Zealand security consultancy ZX Security...