Critical Zimbra Classic Web Client XSS Flaw Enables Code Execution via Crafted Emails
Zimbra has disclosed a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client that could allow attackers to execute arbitrary…
Zimbra has disclosed a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client that could allow attackers to execute arbitrary…
Progress Software has instructed ShareFile customers to immediately shut down Windows servers running Storage Zone Controllers in response to a credible external…
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm…
Researchers at firmware security firm Binarly have discovered six new vulnerabilities in U-Boot, the widely used bootloader for devices ranging from home…
Security researcher Chinmohan Nayak has detailed a WhatsApp-to-host attack chain leveraging three now-patched vulnerabilities in the OpenClaw personal AI assistant. The flaws,…
Researchers at Ledger's Donjon security team have demonstrated a laser fault injection attack that can reset the password on Tangem crypto wallet…
The China-linked cybercrime group Silver Fox has been attributed to a new Rust-based remote access trojan (RAT) called MODBEACON. Chinese cybersecurity company…
Lumen Technologies, a telecommunications company with nearly a century of history, used the Axonius asset intelligence platform to reconcile data from over…
A critical unpatched vulnerability, dubbed XRING, has been disclosed in XQUIC, Alibaba's open-source QUIC and HTTP/3 library. Discovered by FoxIO researcher Sébastien…
A sophisticated threat actor tracked as O-UNC-066 by Okta is targeting organizations across multiple sectors with a voice-based phishing (vishing) scheme that…