Nominet UK provider confirms cybersecurity incident after hack exploit on Ivanti VPN
Nominet, the prominent U.K. domain registry responsible for managing .co.uk domains, has confirmed a significant cybersecurity incident linked to a recently disclosed vulnerability in Ivanti’s VPN software. In...
Hackers are exploiting new vulnerability on Ivanti
Ivanti has issued a critical warning regarding the exploitation of a newly discovered vulnerability in its Connect Secure product, identified as CVE-2025-0282. This remote code execution flaw has...
Critical vulnerabilities in Oracle WebLogic Server and Mitel MiCollab, CISA warns
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding critical vulnerabilities in Oracle WebLogic Server and Mitel MiCollab systems that are currently being exploited...
DoS vulnerability CVE-2024-56332 in Next.js, update now
Next.js, a popular React framework, has recently addressed a critical denial-of-service (DoS) vulnerability identified as CVE-2024-56332. This security flaw was discovered in the server actions feature of Next.js,...
Glutton: a new PHP backdoor
On April 29, 2024, XLab’s threat analysis system detected unusual activities linked to a new malware named Glutton, designed to stealthily infiltrate popular PHP frameworks. This malware was...
Urgent: update your .NET installer link, new Microsoft issue
Microsoft has issued an urgent warning to .NET developers regarding the imminent shutdown of two critical domains used for installing .NET components: dotnetcli.azureedge.net and dotnetbuilds.azureedge.net. This action is...
Curl vulnerability exposes user credentials in redirects
A recently discovered vulnerability in cURL, identified as CVE-2024-11053, poses a significant risk by potentially exposing user credentials during HTTP redirects. This flaw affects various applications that utilize...
Cryptojacking: protecting Docker and Kubernetes environments from new attacks
Cryptojacking—the unauthorized use of systems to mine cryptocurrency—has seen a troubling surge, with attackers increasingly exploiting misconfigured Docker and Kubernetes environments. This alarming trend targets high-performance cloud infrastructures,...