As of January 22, 2025, nearly 50,000 Fortinet firewall devices remain exposed to a critical zero-day vulnerability (CVE-2024-55591) despite urgent warnings and available patches.
The flaw, which has been actively exploited since November 2024, allows attackers to bypass authentication and...
A segmentation fault vulnerability has been identified in the popular command-line text editor Vim, affecting versions before 9.1.1043.
This flaw, CVE-2025-24014, exposes users to a potential crash when operating Vim in silent Ex mode (-s -e) under specific conditions.
The vulnerability...
A critical remote code execution (RCE) vulnerability designated as CVE-2024-53691 has been identified in the QNAP QTS/QuTS hero operating system.
This vulnerability poses a significant risk, allowing remote attackers who have obtained user access to traverse the file system beyond...
VSCode Remote Tunnels, a legitimate feature of the popular development environment, are increasingly being used by malicious actors.
This feature allows developers to remotely access their local coding environment, which promotes engagement and flexibility.
Using this feature, malicious actors install...
Silverfort's cybersecurity research team has uncovered a significant flaw in Microsoft's Active Directory Group Policy that allows NTLMv1 authentication to persist despite being ostensibly disabled.
This discovery highlights a critical vulnerability where misconfigured on-premises applications can bypass the Group Policy...
Let’s Encrypt, the non-profit certificate authority, has introduced six-day validity certificates, commonly referred to as short-lived certificates.
This new offering, set to roll out in stages throughout 2025, represents a major shift in how digital certificates are managed and utilized...
Chinese state-sponsored hackers have successfully breached the computer systems of the U.S. Treasury Department, gaining access to Secretary Janet Yellen's personal computer.
This incident, described as a "major incident" by the Treasury Department, marks one of the most high-profile...
The Federal Trade Commission (FTC) has taken significant action against GoDaddy, one of the world’s largest web hosting companies, for failing to implement adequate security measures to protect its customers' data.
The FTC alleges that GoDaddy's "unreasonable security practices" led...
Security researchers have discovered vulnerabilities in Windows 11's core security features that could allow attackers to bypass multiple protection mechanisms and achieve arbitrary code execution at the kernel level.
The affected security components include Virtualization-based Security (VBS) and Hypervisor-Protected Code...
Security researchers have uncovered six critical vulnerabilities in rsync, a widely used file synchronization and transfer tool for Linux systems. The most severe flaw could allow attackers to execute arbitrary code on machines running rsync servers with just anonymous...