Long-term monitoring of the Earth Centaur group has revealed additional information regarding its tools and techniques. It was found targeting transportation firms and government agencies related...
OSS-Fuzz is now on the lookout for the Log4j Java library flaw. The remotely exploitable flaw in Log4j – the widely deployed Java error logging library...
A basic Javascript WebSocket connection can trigger a local Log4j remote code attack via a drive-by compromise. Wonderful. Truly wonderful. It doesn’t rain, but it pours....
VMware on Thursday announced the release of patches for a critical server-side request forgery (SSRF) vulnerability in Workspace ONE UEM console. An attacker could exploit the...
Fraudsters are leveraging the latest Spider-Man movie to spread malicious files and phishing pages, researchers from Kaspersky have warned. The latest installment of the super-hero franchise, No Way Home,...
Users who have downloaded the app, which is contaminated with Joker malware, have been urged to uninstall it immediately. Over half a million Android users have...
Western Digital is urging customers to update their WD My Cloud devices to the latest available firmware to keep receiving security updates on My Cloud OS...
All set for the weekend? Not so fast. Yesterday, BleepingComputer summed up all the log4j and logback CVEs known thus far. Ever since the critical log4j zero-day saga started...
The Cybersecurity and Infrastructure Security Agency order comes as a prominent firm says nation states are exploiting the vulnerabilities. Federal agencies have until 5 pm on...
How to get the most out of your PSIRT investment The Product Security Incident Response Team (PSIRT) is not a firefighter team, but they should be...