12 Jan Juniper warns of critical RCE bug in its firewalls and switches Juniper Networks has released security updates to fix a critical pre-auth remote code execution (RCE) vulnerability in its SRX Series firewalls and EX Series switches. […]
12 Jan Ivanti Connect Secure zero-days exploited to deploy custom malware Hackers have been exploiting the two zero-day vulnerabilities in Ivanti Connect Secure disclosed this week since early December to deploy multiple families of custom malware for espionage purposes. […]
11 Jan Major T-Mobile outage takes down account access, mobile app A major T-Mobile outage is preventing customers from logging into their accounts and using the company’s mobile app. […]
11 Jan Framework discloses data breach after accountant gets phished Framework Computer disclosed a data breach exposing the personal information of an undisclosed number of customers after Keating Consulting Group, its accounting service provider, fell victim to a phishing attack. […]
11 Jan Over 150k WordPress sites at takeover risk via vulnerable plugin Two vulnerabilities impacting the POST SMTP Mailer WordPress plugin, an email delivery tool used by 300,000 websites, could help attackers take complete control of a site authentication. […]
11 Jan Halara probes breach after hacker leaks data for 950,000 people Popular athleisure clothing brand Halara is investigating a data breach after the alleged data of almost 950,000 customers was leaked on a hacking forum. […]
11 Jan Microsoft testing Windows 11 USB 80Gbps support, Copilot on login Microsoft is now testing support for the USB4 Version 2.0 specification in Windows 11, enabling transfer speeds of up to 80 Gbps over USB Type-C cables. […]
11 Jan Bitwarden adds passkey support to log into web password vaults The open-source Bitwarden password manager has announced that all users can now log in to their web vaults using a passkey instead of the standard username and password pairs. […]
10 Jan Mandiant’s X account hacked by crypto Drainer-as-a-Service gang Cybersecurity firm and Google subsidiary Mandiant says its Twitter/X account was hijacked last week by a Drainer-as-a-Service (DaaS) gang in what it described as “likely a brute force password attack.” […]
10 Jan Cisco says critical Unity Connection bug lets attackers get root Cisco has patched a critical Unity Connection security flaw that can let unauthenticated attackers remotely gain root privileges on unpatched devices. […]