Sonatype has discovered and disclosed four vulnerabilities in picklescan, a tool designed to help developers scan Python ...
NSFOCUS CERT detected that Apache issued a security announcement and fixed the remote code execution vulnerability of Apache ...
Elastic patched a critical Kibana flaw (CVE-2025-25012, CVSS 9.9) enabling arbitrary code execution. Update to version 8.17.3 ...
With CISA’s warning now public, the window for mitigating the threat is rapidly closing. Organizations that depend on ...
Infosec bytes Kaspersky says it has found more than 200 GitHub repos hosting fairly convincing-looking fake projects laced ...
The US cybersecurity authority CISA says it has observed attacks on vulnerabilities in Adobe Coldfusion and Oracle Agile Product Lifecycle Management (PLM). Some vulnerabilities are very old and ...
IMPORTANT: Version 5.0 introduced changes to the API for deserialization which may be breaking changes for some users (and version 6.0 included further changes of a similar nature). This document ...
Software vendor Trimble is warning that hackers are exploiting a Cityworks deserialization vulnerability to remotely execute commands on IIS servers and deploy Cobalt Strike beacons for initial ...
This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS). Attack Vector: This metric reflects the context by which vulnerability ...
The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking ...