Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
CISA ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. The vulnerabilities allow attackers to compromise the video conferencing and collaboration platform.
Artificial Intelligence is transforming Security Operations Centers (SOCs) by automating repetitive tasks and improving threat detection. Wazuh, an open-source security monitoring platform, integrates AI capabilities to enhance security analytics and incident response workflows.
Microsoft patched a maximum-severity vulnerability in the Entra ID identity and access management platform that has been exploited in attacks. The flaw, assigned a CVSS 10.0 rating, allows remote code execution through deserialization of untrusted data.
Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks.
Threat actors are abusing FTP server banners to hide commands that deliver two new remote access trojans named E4del and PINHOLE. The malware is delivered through malicious FTP banners that appear legitimate to users. E4del and PINHOLE provide attackers with remote access to compromised systems.
Toronto's Hospital for Sick Children (SickKids) reported a data breach exposing personal information of current and former employees and job applicants. The incident stemmed from a flaw in third-party software used by the hospital.