The threat group UNC3886 uses stolen credentials and custom malware implants to compromise end-of-life routers from Juniper Networks still in use by enterprises and ISPs.
Broadcom has patched three vulnerabilities in the VMware ESXi hypervisor and related products, with Microsoft reporting the flaws are being actively exploited to take control of host systems.
Security researchers have uncovered known firmware flaws in three Palo Alto enterprise firewall devices built on commodity hardware.
A design flaw in the decades-old RADIUS authentication protocol allows attackers to take over network devices from a man-in-the-middle position by exploiting MD5 hash collisions.
The moderate-severity vulnerability has been observed being exploited in the wild by Chinese APT Velvet Ant.
Researchers from Qualys say regreSSHion allows attackers to take over servers with 14 million potentially vulnerable OpenSSH instances identified.
In the past, virtual private networks were mainly used by companies to securely link remote branches together or connect roaming employees to the office network, but today they're an important service for consumers too.
The group plans to sell more Equation exploits and cyberespionage data through a subscription-based service
Researchers believe other attackers will start to exploit the same SMB flaw as the WannaCry ransomware
Based on a new risk assessment process, some apps that want to use Google's identity services might need to undergo a review