FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
Before yesterdaySecurity

Critical libwebp Vulnerability Under Active Exploitation - Gets Maximum CVSS Score

By: THN
Google has assigned a new CVE identifier for a critical security flaw in the libwebp image library for rendering images in theΒ WebP formatΒ that has come under active exploitation in the wild. Tracked asΒ CVE-2023-5129, the issue has been given the maximum severity score of 10.0 on the CVSS rating system. It has been described as an issue rooted in theΒ Huffman coding algorithmΒ - With a specially

Apple Rushes to Patch 3 New Zero-Day Flaws: iOS, macOS, Safari, and More Vulnerable

By: THN
Apple has released yet another round of security patches to address three actively exploited zero-day flaws impacting iOS, iPadOS, macOS, watchOS, and Safari, taking the total tally of zero-day bugs discovered in its software this year to 16. The list of security vulnerabilities is as follows - CVE-2023-41991Β - A certificate validation issue in the Security framework that could allow a

North Korean Hackers Suspected in New Wave of Malicious npm Packages

By: THN
The npm package registry has emerged as the target of yet another highly targeted attack campaign that aims to entice developers into downloading malevolent modules. Software supply chain security firm Phylum told The Hacker News the activity exhibits similar behaviors to that of a previous attack waveΒ uncovered in June, which has since beenΒ linked to North Korean threat actors. As many as nine
❌