Advertisement
Wireshark 4.6.6: Fixing Critical Vulnerability and Dissector Bugs
Wireshark 4.6.6 release addresses one security vulnerability and 11 functional bugs. Learn how this update secures packet analysis and prevents dissector crashes.
CVE-2025-26980: Ghost CMS SQL Injection Exploited in ClickFix Campaign
A critical SQL injection vulnerability in Ghost CMS (CVE-2025-26980) is being exploited to deliver ClickFix malware through malicious JavaScript injections.
Anthropic Project Glasswing Uncovers 10,000 High-Severity Flaws
Anthropic's Claude Mythos AI identifies over 10,000 critical and high-severity vulnerabilities in systemically important software via Project Glasswing.
Underminr Vulnerability: Bypassing DNS Filtering via Trusted Domains
The Underminr vulnerability affects 88 million domains, allowing attackers to hide C2 traffic and bypass DNS filtering using shared infrastructure.
CVE-2026-9082: Drupal Core SQL Injection Added to CISA KEV Catalog
CISA warns of active exploitation of CVE-2026-9082, a critical SQL injection vulnerability in Drupal Core. Organizations must patch to prevent data exposure.
CVE-2026-48172: LiteSpeed cPanel Plugin Privilege Escalation - Patch Now
Exploitation of CVE-2026-48172 in the LiteSpeed cPanel plugin allows local users to gain root access. Organizations should update to version 1.2.2 immediately.
ABB B&R Automation Studio <6.5: Multiple Critical SQLite Vulnerabilities
Critical SQLite vulnerabilities in ABB B&R Automation Studio <6.5 expose ICS to RCE, data exposure, and unauthorized access. Update to version 6.5 immediately.
CVE-2026-9082: Drupal Core SQL Injection Under Active Exploitation
CISA adds CVE-2026-9082, a critical Drupal Core SQL Injection vulnerability, to KEV Catalog due to active exploitation. Immediate patching required for all organizations.
CVE-2026-9082: Drupal Under Active Exploitation – Patch Now
Critical Drupal vulnerability CVE-2026-9082 is actively exploited shortly after disclosure. Urgent patching is required to prevent compromise of thousands of websites.
Huawei AR2500 Exploitation: Industrial Router Flaw Analysis
An analysis of the Huawei AR2500 industrial router exploitation that triggered a major telecom outage and CISA's new KEV nomination process.
CVE-2023-41179: Trend Micro Apex One RCE Exploited in Attacks
Trend Micro patches CVE-2023-41179, a critical zero-day in Apex One and Worry-Free Business Security exploited to execute arbitrary commands on Windows systems.
Ubiquiti Patches Critical UniFi OS Command Injection Vulnerabilities
Ubiquiti has addressed three critical vulnerabilities (CVE-2024-42025, CVE-2024-42027, CVE-2024-42028) in UniFi OS that allow unauthenticated RCE via local networks.
CVE-2026-34926: TrendAI Apex One Directory Traversal Exploit Analysis
TrendAI patches a critical zero-day directory traversal vulnerability (CVE-2026-34926) in Apex One on-premise currently exploited in the wild.
CVE-2025-34291 & CVE-2023-41179: CISA Warns of Active Exploitation
CISA adds Langflow and Trend Micro Apex One vulnerabilities to KEV. Learn how to mitigate CVE-2025-34291 and CVE-2023-41179 to prevent active exploitation.
CVE-2022-4304: Hitachi Energy GMS600 Timing Side Channel Vulnerability
Hitachi Energy GMS600 versions 1.3.0-1.3.1 affected by CVE-2022-4304, an OpenSSL timing side channel leading to TLS decryption. Patch to 1.3.2 now.
ABB Terra AC Wallbox <=1.8.33 Buffer Overflows: Patch Now
CISA warns of three buffer overflow vulnerabilities (CVE-2025-10504, CVE-2025-12142, CVE-2025-12143) in ABB Terra AC Wallbox EV chargers, leading to potential remote…
AI-Assisted macOS Kernel Exploit on Apple M5 Hardware
Security researchers used Anthropic’s Mythos AI to develop a macOS kernel memory corruption exploit for the Apple M5 chip in just five days. Patch now.
Chromium RCE Risk: Unfixed Flaw Allows Background JavaScript
Google accidentally exposed details of an unfixed Chromium flaw. This enables RCE via persistent background JavaScript execution, affecting many browsers.
Cisco Secure Workload RCE via CVE-2025-20165 — Mitigation Guide
Cisco patches a critical 9.8 CVSS vulnerability in Secure Workload REST APIs that allows unauthenticated attackers to gain Site Admin privileges.
Microsoft Defender CVE-2026-41091 Privilege Escalation Exploited
Microsoft warns of active exploitation of CVE-2026-41091 in Defender, a privilege escalation flaw allowing attackers to gain SYSTEM privileges on Windows.
CISA KEV Update: New Microsoft Defender and Legacy Flaws Exploited
CISA adds seven vulnerabilities, including CVE-2026-41091 and CVE-2026-45498, to the Known Exploited Vulnerabilities catalog. Patch now to prevent compromise.
CVE-2024-21338: Microsoft Defender Zero-Day Exploited by Lazarus
Microsoft patches two zero-day vulnerabilities in Defender and SmartScreen exploited by Lazarus Group for privilege escalation and malware delivery.
CVE-2026-46333: Nine-Year-Old Linux Kernel Privilege Escalation Flaw
A long-standing Linux kernel flaw, CVE-2026-46333, allows local users to achieve root access and disclose sensitive data on major Linux distributions.
CVE-2026-9082: Drupal Core RCE via Database API (PostgreSQL)
A highly critical flaw, CVE-2026-9082, in Drupal Core's database abstraction API allows RCE, privilege escalation, and info disclosure on PostgreSQL sites.