
Topic > vulnerabilities


Phylum strengthens mission to defend the software supply chains

Spring4Shell added to CISA’s list of exploited vulnerabilities

VMware says 3 Tanzu products impacted by Spring4Shell vulnerability

Spring4Shell: Researchers still looking for exploitable real-world apps

Spring4Shell vulnerability: Should you patch?

Don’t ignore Spring4Shell. But there’s still no sign it’s widespread

Spring4Shell vulnerability likely to affect real-world apps, analyst says

Spring Core vulnerability doesn’t seem to be Log4Shell all over again

Microsoft Azure Defender for IoT vulnerabilities could lead to ‘full network compromise’

Russian hackers exploited MFA and ‘PrintNightmare’ vulnerability in NGO breach, U.S. says

GreyNoise launches free tool to protect against ‘scary’ vulnerabilities like Log4j

Mandiant reminds us: Don’t forget about Log4j

Major Microsoft Azure cross-tenant vulnerability caught by Orca Security

Moderne aims to remediate OSS vulnerabilities

Report: 2021 hit a record high of security vulnerabilities

Vulnerability in Linux program enables local privilege escalation, researchers report

Critical Microsoft vulnerability from 2020 added to list of exploited flaws

Microsoft’s latest vulnerability: ‘Clear disclosure, rapid fix’

‘Very concerning’: Cisco router vulnerabilities bring broad risks

Major vulnerability found in open source dev tool for Kubernetes

Report: 75% of containers found to be operating with severe vulnerabilities

Cybersecurity’s challenge for 2022 is defeating weaponized ransomware

Linux vulnerability can be ‘easily exploited’ for local privilege escalation, researchers say

Accidental exposure of sensitive data has been surging, Bugcrowd finds

AI in 2022: What decision you need to make in the new year

Community
How to detect whether you have the Log4j2 vulnerability

As Log4j sent defenders scrambling, this startup made its threat data free

With Log4j vulnerability, the full impact has yet to come

The Log4j vulnerability is bad. Here’s the good news

Cycode raises $56M to scan apps for security vulnerabilities

Report: Applications and critical data vulnerable to attack

Cybersecurity startup Sonrai Security, which offers identity graph for public cloud, nabs $50M

Cybersecurity report reveals critical business vulnerabilities

Enterprise tech adoption fuels cyber risks

OpenSSF’s Allstar aims to fix vulnerabilities in open source projects

Vulcan Cyber launches free vulnerability management service with $21M in new funding

Researchers use AI classifiers to expose potential vulnerabilities in Microsoft remote desktop

GitHub acquires Semmle to help developers spot code exploits
