Cloudflare recently thwarted the largest distributed denial-of-service (DDoS) attack ever recorded, peaking at an unprecedented 5.6 terabits per second (Tbps).
The attack, which occurred on October 29, 2024, targeted an Internet Service Provider (ISP) in Eastern Asia and was...
As of January 22, 2025, nearly 50,000 Fortinet firewall devices remain exposed to a critical zero-day vulnerability (CVE-2024-55591) despite urgent warnings and available patches.
The flaw, which has been actively exploited since November 2024, allows attackers to bypass authentication and...
The Open Web Application Security Project (OWASP) has released its much-anticipated Smart Contract Top 10 for 2025, a comprehensive awareness document aimed at equipping Web3 developers and security teams with the knowledge to combat the most critical vulnerabilities in...
Let’s Encrypt, the non-profit certificate authority, has introduced six-day validity certificates, commonly referred to as short-lived certificates.
This new offering, set to roll out in stages throughout 2025, represents a major shift in how digital certificates are managed and utilized...
Chinese state-sponsored hackers have successfully breached the computer systems of the U.S. Treasury Department, gaining access to Secretary Janet Yellen's personal computer.
This incident, described as a "major incident" by the Treasury Department, marks one of the most high-profile...
Microsoft's January 2025 Patch Tuesday update has encountered significant compatibility issues with certain Citrix software installations, causing widespread concern among enterprise users and IT administrators.
The problem primarily affects devices running Citrix Session Recording Agent (SRA) version 2411, a tool...
A hacking collective known as the "Belsen Group" has released over 15,000 unique FortiGate firewall configurations online.
The data dump, reportedly obtained by exploiting a zero-day vulnerability in Fortinet’s systems back in October 2022, includes sensitive information such as usernames,...
The Cybersecurity and Infrastructure Security Agency (CISA) has released the Microsoft Expanded Cloud Logs Implementation Playbook, a comprehensive guide aimed at empowering organizations to enhance their cybersecurity defenses.
Developed in collaboration with Microsoft, the Office of Management and Budget (OMB),...
Palo Alto Networks has disclosed multiple critical security vulnerabilities in its Expedition migration tool, including a concerning OS command injection flaw that enables attackers to execute arbitrary commands and access sensitive firewall credentials.
The command injection vulnerability (CVE-2025-0107) allows authenticated...
The notorious Cl0p ransomware group has published a list of companies compromised through vulnerabilities in Cleo's managed file transfer (MFT) software.
The announcement, made on the group’s dark web leak site, highlights the exploitation of a critical vulnerability, CVE-2024-50623....