Follow Cyber Kendra on Google News! | WhatsApp | Telegram

Security

Critical Vulnerability in SonicWall SMA1000 Devices Actively Exploited

SonicWall has issued an urgent security advisory for a critical vulnerability affecting its SMA1000 series appliances, which is actively being explo…

Critical Zero-Click Vulnerability in Windows OLE Poses Widespread Risk

Microsoft has addressed a severe security vulnerability ( CVE-2025-21298 ) in Windows Object Linking and Embedding ( OLE ) that could allow attackers…

Cookie Sandwich - New Attack Steals HttpOnly Cookies

A concerning new web security vulnerability dubbed " Cookie Sandwich " has been discovered that allows attackers to bypass HttpOnly cookie …

Critical 7-Zip Vulnerability Bypasses Windows Security

A high-severity vulnerability has been discovered in the popular file compression tool 7-Zip, potentially enabling attackers to bypass crucial Window…

Critical Vulnerabilities Discovered in SimpleHelp Remote Support Software

Security researchers at Horizon3.ai have uncovered three critical vulnerabilities in SimpleHelp, a remote support software solution used globally. T…

Attackers Discover APIs in 29 Seconds and Steal 10m User Entities in a Minute

Wallarm, the recognized leader in API security, has built a globally distributed API honeypot spanning 14 locations. It baits attackers by simulating…

Critical Auth Bypass Vulnerability in Fortinet Products Actively Exploited

Fortinet has disclosed a critical authentication bypass vulnerability ( CVE-2024-55591 ) affecting FortiOS and FortiProxy products that allow remote …

New Ransomware Campaign Exploits AWS S3 Encryption Features

Researchers from Halcyon's RISE Team identified a new ransomware technique targeting Amazon Web Services (AWS) S3 storage. The attack, attributed…

Microsoft Discloses macOS Kernel Extension Vulnerability

Microsoft's Threat Intelligence team has uncovered a critical security vulnerability in Apple's macOS that could allow attackers to bypass Sy…

WorstFit - Critical Vulnerability Discovered in Windows Charset Conversion

Security researchers Orange Tsai and Splitline Huang have discovered a significant vulnerability in Windows systems that could allow attackers to by…

Ivanti Connect Secure VPN Targeted in New Zero-Day

Ivanti has released an urgent security update addressing two significant vulnerabilities affecting its Connect Secure, Policy Secure, and Neurons for…

Researcher Uncovers AWS S3 Ransomware Vulnerabilities

Security researchers at Rhino Security Labs have uncovered a concerning vulnerability in Amazon Web Services ( AWS ) S3 storage systems that could a…

Signature Verification Bypass Discovered in Nuclei Vulnerability Scanner

Security researchers at Wiz have uncovered a significant vulnerability in Nuclei, a widely-used open-source security scanning tool, that could allow …

LDAPNightmare - Windows Server LDAP Vulnerability Exploit Released

SafeBreach Labs researchers have published the first proof-of-concept exploit for CVE-2024-49113, a critical vulnerability affecting Windows Server s…

Alleged 7-Zip Zero-Day Vulnerability Claims Disputed by Developer

A recent claim of a zero-day vulnerability in the popular file compression software 7-Zip has been disputed by the program's developer, raising q…

Chinese State Hackers Breach Ninth US Telecom in Extensive Campaign

The White House has confirmed that a ninth US telecommunications company has fallen victim to the " Salt Typhoon " cyber-espionage campaign…

Apache Patches Critical Remote Code Execution Vulnerability in Tomcat

The Apache Software Foundation has issued an urgent security advisory regarding a critical remote code execution (RCE) vulnerability in Apache Tomcat…

6 Cloud Security Best Practices To Avoid Digital Blindspots

Cloud-based technologies provide consumers and organizations a flexible, cost-effective solution to share, optimize, and scale digital activities. Ho…

Vulnerability in Spring Boot Actuator Exposes Cloud Environments

A new research report from Wiz Threat Research has uncovered widespread security risks in Spring Boot Actuator implementations, affecting numerous cl…

New Android Spyware Operation Exploits Qualcomm Driver Vulnerabilities in Serbia

A new investigation by Amnesty International has revealed a sophisticated surveillance operation in Serbia that combined multiple spyware tools to ta…