Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

Microsoft disclosed on Thursday a maximum-severity vulnerability in its Entra ID cloud identity service that attackers had already been exploiting, though the company says it has fully mitigated the flaw server-side and no customer action is required.

A critical remote code execution vulnerability in Alibaba's Fastjson library is under active exploitation, with no fix available for the affected 1.x branch and attackers already hitting production systems across the United States.

Two high-severity vulnerabilities that together lay dormant in the Linux kernel for more than 15 years were publicly disclosed this week, prompting urgent patching across major distributions and cloud providers. Both were demonstrated through Google Alphabet Inc. bug bounty programs…