Security News

Google’s AI Tool Big Sleep Finds Zero-Day Vulnerability in SQLite Database Engine
2024-11-04 10:04

Google said it discovered a zero-day vulnerability in the SQLite open-source database engine using its large language model (LLM) assisted framework called Big Sleep (formerly Project Naptime)....

Hackers target critical zero-day vulnerability in PTZ cameras
2024-10-31 18:23

Hackers are attempting to exploit two zero-day vulnerabilities in PTZOptics pan-tilt-zoom (PTZ) live streaming cameras used in industrial, healthcare, business conferences, government, and...

LiteSpeed Cache Plugin Vulnerability Poses Significant Risk to WordPress Websites
2024-10-31 10:24

A high-severity security flaw has been disclosed in the LiteSpeed Cache plugin for WordPress that could allow an unauthenticated threat actor to elevate their privileges and perform malicious...

Patching problems: The “return” of a Windows Themes spoofing vulnerability
2024-10-29 10:16

Despite two patching attempts, a security issue that may allow attackers to compromise Windows user’s NTLM (authentication) credentials via a malicious Windows themes file still affects...

New Research Reveals Spectre Vulnerability Persists in Latest AMD and Intel Processors
2024-10-29 05:53

More than six years after the Spectre security flaw impacting modern CPU processors came to light, new research has found that the latest AMD and Intel processors are still susceptible to...

Researchers Uncover OS Downgrade Vulnerability Targeting Microsoft Windows Kernel
2024-10-28 05:29

A new attack technique could be used to bypass Microsoft's Driver Signature Enforcement (DSE) on fully patched Windows systems, leading to operating system (OS) downgrade attacks. "This bypass...

AWS Cloud Development Kit Vulnerability Exposes Users to Potential Account Takeover Risks
2024-10-24 13:00

Cybersecurity researchers have disclosed a security flaw impacting Amazon Web Services (AWS) Cloud Development Kit (CDK) that could have resulted in an account takeover under specific...

Cisco Issues Urgent Fix for ASA and FTD Software Vulnerability Under Active Attack
2024-10-24 12:41

Cisco on Wednesday said it has released updates to address an actively exploited security flaw in its Adaptive Security Appliance (ASA) that could lead to a denial-of-service (DoS) condition. The...

Lazarus Group Exploits Google Chrome Vulnerability to Control Infected Devices
2024-10-24 09:53

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a now-patched security flaw in Google Chrome to seize control of infected devices....

Fortinet Warns of Critical Vulnerability in FortiManager Under Active Exploitation
2024-10-24 06:23

Fortinet has confirmed details of a critical security flaw impacting FortiManager that has come under active exploitation in the wild. Tracked as CVE-2024-47575 (CVSS score: 9.8), the...