Chinese operators tracked as DEV-0322 found behind the SolarWinds attacks that exploited zero-day flaws, the same threat group recently attacked software firm Autodesk... ...
Node.js patched crucial tar handling vulnerabilities tracked as CVE-2021-32803 and CVE-2021-32804 residing in the arborist and CLI modules... ...
JavaScript's popular NPM code package, Pac-Resolver, was downloaded 3M times through WPAD (Web Proxy Auto-Discovery Protocol), exposing apps to Proxy configs... ...
Banksy's official website was hacked following an NFT scam worth $336,000 through an unverified auctioning portal, the scammer returned the victim's money......
WhatsApp's Photo Filter bug tracked as CVE-2020-1910 could have allowed threat actors to steal sensitive data from internal memory through malformed images and .GIF files... ...
BrakTooth vulnerabilities, a collective consortium of 16 flaws (20+ CVEs) is affecting multiple SOC vendors and billions of Bluetooth users through arbitrary code execution... ...
WordPress' Gutenberg Template Library & Redux Framework Plugin detected with a pair of vulnerabilities enabling installation of arbitrary plugins... ...
US Securities And Exchange Services (SEC) imposed multiple sanctions and financial services against 3 companies following brute force attacks......
LockFile ransomware group developed previously unprecedented Intermittent Encryption strategies using Windows management interface to avoid detection......
WooCommerce's Dynamic Pricing and Discounts plugin vulnerability enabled unauthorized attackers to inject malicious code...
Sign up to our Weekley Threat Digest and keep apace of the trends shaping Cybersecurity.