7-Zip Fixes Critical XZ Vulnerability
A plain archive file can easily turn into a bad hacking tool. Luckily, the maker of 7-Zip just launched version 26.02 to fix a huge flaw in XZ file tasks. During a real attack,...
A plain archive file can easily turn into a bad hacking tool. Luckily, the maker of 7-Zip just launched version 26.02 to fix a huge flaw in XZ file tasks. During a real attack,...
The security firm Searchlight Cyber just found a major flaw inside the core WordPress code. This remote code execution flaw does not require any login steps. Any rogue user can run harmful code on...
The standard synchronization feature in Google Chrome can quietly transform your browser into a surveillance tool. Furthermore, an attacker requires no malicious software or technical expertise. They merely need brief physical access to another...
Active Exploitation of Critical SharePoint Vulnerabilities The United States Cybersecurity and Infrastructure Security Agency issued an urgent warning. Indeed, this warning concerns active exploits targeting on-premises Microsoft SharePoint servers. Currently, malicious actors leverage three...
The Illusion of Early-Stage Security The Secure Boot mechanism must block malicious code before Windows or Linux even launches. However, ESET researchers recently made a startling discovery. Specifically, attackers could bypass this protection almost...
A Historic Season for Security Experts typically consider summer a quiet season for software updates. Nevertheless, the July patch release from Microsoft proved to be monumental. The corporation resolved an astonishing 570 vulnerabilities simultaneously....
Renowned cybersecurity researcher Nightmare-Eclipse has once again disclosed an unpatched local privilege escalation vulnerability affecting Windows 10 and 11. Orchestrated as a calculated act of retaliation, the researcher deliberately timed the public disclosure to...
Malicious firmware can seize control of a device before Linux starts. It can remain nearly invisible to security software running at the OS level. Researchers at Binarly discovered six vulnerabilities in U-Boot. The open-source...
Corporate storage systems are rarely taken offline unless the risk is serious. Progress Software has asked customers to shut down their ShareFile Storage Zone Controller servers immediately. The request comes in response to a...
Invisible Threats in Code Reviews A malicious pull request can bypass code reviews flawlessly. Days later, it compels an AI assistant to covertly exfiltrate project secrets. Attackers simply conceal instructions within an ordinary PNG...
A single crafted network request can transform a Palo Alto Networks firewall from a security boundary into an entry point. A vulnerability in PAN-OS allows a remote, unauthenticated attacker to disrupt device operation and...
A security research firm has disclosed a two-vulnerability exploit chain named IonStack that affects Android 17. Nebula Security identified both vulnerabilities and has already notified the relevant developers. The company reports no evidence of...