vulnerability

GitLab Releases Urgent Security Updates for Critical Flaw
GitLab is rolling out security patches that fix a bug that could let attackers leverage scheduled security scan policies to run pipelines as an arbitrary user. Bad actors exploiting the flaw could ...

Zero-Day Flaws an Evolving Weapon in Ransomware Groups’ Arsenals
Ransomware gangs have for years gotten their malicious payloads into targeted systems primarily through phishing attacks or being dropped as a secondary payload from command-and-control frameworks. That is changing, according to researchers ...

Tunnel Vision: CloudflareD AbuseD in the WilD
Introduction Across the cybersecurity community, defenders are constantly finding threat actors using novel and innovative techniques to further their exploitation […] ...

New EMA Research Report Spotlights SSL/TLS Certificate Management Challenges
Digital certificates are essential for enabling trust and protecting online transactions and communications. They are employed to guard against many forms of cyberattacks, authenticate users, and encrypt sensitive data. However, because digital ...

How to avoid CVE burnout and alert fatigue in vulnerability scans?
An image of red alertsCVE ( Common Vulnerabilities and Exposures) scans are essential to securing your software applications. However, with the increasing complexity of software stacks, identifying and addressing all CVEs can be ...

Why Pentesting-as-a-Service is Vital for Business Security
Conducting regular penetration tests (pentests) is a proactive option that identifies, evaluates and mitigates risks ...

Meta’s Threads and Your Privacy, Airline Reservation Scams, IDOR Srikes Back
In this episode, we explore the rise of Threads, a new social media app developed by Meta, which has already attracted 10 million users in just seven hours. However, there’s a catch ...

How Audits + Testing = Long-Term Savings
Compliance audits and penetration testing play an important role in assessing, correcting and strengthening an organization’s security configuration ...

MOVEit Cyberattack, The Problem with Password Rotations, Military Alert on Free Smartwatches
Several major organizations, including British Airways and the BBC, fell victim to the recent MOVEit cyberattack. We discuss the alarming trend of hackers targeting trusted suppliers to gain access to customer data, ...

US Gov’t Puts $10M Bounty on CL0P as MOVEit Fallout Continues
The U.S. State Department is offering a $10 million bounty for information related to the Cl0p ransomware gang, which is thought to be behind the MOVEit Transfer vulnerabilities ...