Uncategorized

Critical Grafana Vulnerabilities Allow Malicious Redirects and Arbitrary Code Execution

Grafana Labs has released critical security patches addressing two significant vulnerabilities that could allow attackers to redirect users to malicious…

9 months ago

Ubiquiti UniFi Device Vulnerability Enables Remote Command Injection by Attackers

Ubiquiti Networks has disclosed a critical security vulnerability affecting multiple UniFi Access devices that could enable malicious actors to execute…

9 months ago

Lenovo Protection Driver Vulnerability Allows Privilege Escalation and Remote Code Execution

A critical buffer overflow vulnerability has been identified in Lenovo’s Protection Driver, exposing users of various Lenovo applications to potential…

9 months ago

Microsoft Defender for Office 365 Unveils Enhanced Dashboard with Comprehensive Threat Insights

Microsoft has announced two major initiatives aimed at increasing transparency in email security effectiveness, addressing the growing challenge faced by…

9 months ago

WAFFLED: Exploiting Web Application Firewalls via Parsing Inconsistencies

Web Application Firewalls (WAFs) are the first line of defense for countless online services, yet a new approach—dubbed WAFFLED—demonstrates how…

9 months ago

Ransomware Attack Targets Russian Vodka Maker Beluga

Russian premium vodka producer NovaBev Group, the parent company behind the prestigious Beluga brand, has fallen victim to a sophisticated…

9 months ago

New ‘Daemon Ex Plist’ Exploit Grants Hackers Root Access on macOS

A critical vulnerability in macOS that allows attackers to escalate privileges and gain root access through a vulnerability in the…

9 months ago

CISA Publishes 13 ICS Security Alerts on Vulnerabilities and Exploits

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a comprehensive set of Industrial Control Systems (ICS) advisories on July…

9 months ago

Hackers Exploit Signal App Clone Vulnerability to Steal Passwords

A critical security vulnerability in TeleMessageTM SGNL, an enterprise messaging system designed to mirror Signal's secure communication features, has been…

9 months ago

New BIND 9 Vulnerabilities Put Organizations at Risk of Cache Poisoning and DoS Attacks

Two critical vulnerabilities in BIND 9, one of the most widely deployed DNS server software solutions globally. Released on July…

9 months ago