Ransomware threat actors are spending less time on compromised networks before security solutions sound the alarm. In the first half of...
Chrome is deprecating direct access to private network endpoints from public websites in order to protect users from cross-site request forgery (CSRF) attacks. Part two of the browser’s...
Cloud management firm Box has moved to patch a flaw in its SMS-based two-factor authentication (MFA), just weeks after its temporary one-time password (TOTP)-based MFA was...
A server-side request forgery (SSRF) vulnerability in versions of VMWare authentication software could allow an attacker to obtain administrative JSON Web Tokens (JWT), researchers warn. The...
The official app for Beijing 2022 Winter Olympics, ‘My 2022,’ was found to be insecure when it comes to protecting the sensitive data of its users....
Law enforcement authorities from 10 countries took down VPNLab.net, a VPN service provider used by ransomware operators and malware actors. The disruptive joint action was coordinated by Europol...
Bugcrowd released its 2022 Priority One report to spotlight the key cybersecurity trends of the past year, including the rise in the adoption of crowdsourced security due...
Over the past few years, Information Technology (IT) networks and Operational Technology (OT) environments have become interconnected, which has exposed a variety of vulnerabilities and weaknesses...
Russian authorities have arrested 14 alleged members of the notorious REvil ransomware gang. The crackdown operation, announced on Friday (January 14), was masterminded by the Russian Federal Security Service...
Zoho has addressed a new critical severity vulnerability that affects the company’s Desktop Central and Desktop Central MSP unified endpoint management (UEM) solutions. ManageEngine Desktop Central...
DHL was the most imitated brand in phishing campaigns throughout Q4 2021, pushing Microsoft to second place, and Google to fourth. This isn’t surprising considering that...
Recent Comments