Cybersecurity News
-
WordPress Plugin, Hunk Companion, Critical Vulnerability Patched
A serious security vulnerability has been discovered in the Hunk Companion plugin for WordPress, affecting versions before 1.9.0. Researches at WPScan found the vulnerability of the Hunk Companion, a plugin used for…
-
Apache Releases Update for Struts RCE Vulnerability
A new update has been released by Apache to address a critical Remote Code Execution (RCE) vulnerability affecting the open-source Apache Struts framework. Apache Struts is widely used for developing modern Java…
-
Apple’s iOS 18.2, iPadOS 18.2 & macOS 15.2 Updates Include Critical Security Patches
Apple has rolled out its iOS 18.2, iPadOS 18.2 and macOS 15.2 updates with a whole set of new features for its Apple AI Intelligence, along with several critical security patches across…
-
Microsoft Patch Tuesday Update Fixes Many Security Vulnerabilities, Flaws Including CLFS, LDAP Bugs
Microsoft has released it’s Patch Tuesday December update, usually available on the second Tuesday of every month, with a bunch of security updates and patches. Many of the patches are for vulnerabilities…
-
Zero-Day Vulnerability in Cleo File Transfer Software Found
A critical vulnerability has been found in Cleo’s file transfer software Harmony, VLTrader, and LexiCom affecting versions 5.8.0.21. Researches at Huntress identified this flaw, which exists in its lack of restrictions in…
-
Krispy Kreme Hit With Cyberattack Affecting Online Orders
Krispy Kreme, the popular doughnut and coffee chain restaurant, has been hit with a cyberattack affecting their online systems. This has been impacting their order fulfillment process for online orders. In an…
-
0patch Offers Patch for Windows NTLM Zero-Day Vulnerability
A zero-day vulnerability affecting many Windows versions from Windows 7 to Windows 11, has been found by researches at 0patch. A zero-day is a vulnerability that doesn’t have an official fix yet,…
-
Security Agencies Issue Guidance on Recent China-Affiliated Telecom Hacks
U.S. security and cybersecurity agencies (along with international partners) have issued a guidance in response to confirmed infiltration on telecom communication systems by China, officially known as People’s Republic of China (PRC),-affiliated…
-
DroidBot, a Malware-as-a-Service (MaaS), Is Targeting Banking, Crypto Apps
A new Android malware is making rounds and attempting to steal information from unsuspecting users and installs. Being classified as DroidBot, it’s a Remote Access Tool (RAT) utilized in a Malware-as-a-Service (MaaS)…
