Advertisement
CISA Adds 8 Flaws to KEV: Cisco and PaperCut Exploited in the Wild
CISA adds 8 vulnerabilities to its KEV catalog, including PaperCut and Cisco SD-WAN Manager flaws, with federal patching deadlines set for May 2026.
Securing Serial-to-IP Devices: Mitigating Thousands of OT Bugs
Industrial serial-to-IP converters are riddled with thousands of vulnerabilities, posing a significant risk to legacy infrastructure and OT environments.
CVE-2026-5760: SGLang RCE via Malicious GGUF Models - Patch Now
Critical CVE-2026-5760 command injection in SGLang allows remote code execution via GGUF files. High-performance LLM serving environments are at risk.
Prioritizing Vulnerabilities with EPSS: Managing the CVE Flood
Learn how the Exploit Prediction Scoring System (EPSS) provides a data-driven approach to prioritize vulnerability remediation amid rising CVE volumes.
TP-Link Archer AX21 RCE via CVE-2023-1389 — Mitigation Guide
Hackers continue targeting discontinued TP-Link Archer AX21 routers with CVE-2023-1389, though many exploitation attempts currently fail to execute payloads.
Microsoft Releases OOB Updates to Fix Windows Server Boot Issues
Microsoft issues emergency out-of-band updates to resolve critical authentication failures and boot loops caused by the April 2026 security patches.
Android Dirty Stream Path Traversal: Detecting and Patching App Exploits
Microsoft identifies Dirty Stream vulnerabilities in Android apps, allowing path traversal and unauthorized file manipulation. Learn how to secure your apps.
NIST to Prioritize High-Impact CVEs Amid NVD Enrichment Backlog
NIST adjusts National Vulnerability Database operations to focus on significant flaws, leaving lower-priority vulnerabilities without official metadata.
Edge Update Breaks Microsoft Teams Right-Click Paste Functionality
A recent Microsoft Edge browser update has disabled the right-click paste feature in the Microsoft Teams desktop client, impacting global user productivity.
protobuf.js RCE via CVE-2023-32731 — Mitigation Guide
Technical breakdown of CVE-2023-32731, a critical prototype pollution vulnerability in protobuf.js that enables remote code execution in JavaScript environments.
Microsoft Defender Zero-Days BlueHammer and RedSun Actively Exploited
Huntress warns of active exploitation of three Microsoft Defender vulnerabilities, including BlueHammer and RedSun, allowing for privilege escalation.
CVE-2023-46604: Apache ActiveMQ RCE Exploited in the Wild
CISA warns of active exploitation for CVE-2023-46604, a critical RCE flaw in Apache ActiveMQ used by ransomware groups. Update to version 5.18.3 or later.
CVE-2026-34197: Apache ActiveMQ Exploit Added to CISA KEV Catalog
CISA alerts organizations to the active exploitation of CVE-2026-34197 in Apache ActiveMQ. Federal agencies must patch this input validation flaw immediately.
Cursor AI RCE via Indirect Prompt Injection — Mitigation Guide
Security researchers demonstrate how indirect prompt injection in Cursor AI could lead to full shell access on developer workstations. Patch immediately.
Windows Server Domain Controllers Hit by LSASS Reboot Loops
Microsoft confirms LSASS crashes causing persistent reboot loops on Windows Server Domain Controllers following the April 2024 security update cycle.
NIST Limits NVD Enrichment Amid 263% Surge in CVE Submissions
NIST scales back enrichment of the National Vulnerability Database (NVD) due to a 263% volume increase, impacting vulnerability management workflows.
CVE-2026-5387: AVEVA Pipeline Simulation Privilege Escalation
Unauthenticated attackers can exploit CVE-2026-5387 in AVEVA Pipeline Simulation <=2025_SP1_build_7.1.9497.6351 to modify critical ICS simulation parameters and training…
Apache ActiveMQ CVE-2026-34197: CISA KEV Update & Mitigation
CISA adds high-severity CVE-2026-34197 in Apache ActiveMQ to its Known Exploited Vulnerabilities catalog. Learn how to secure your message broker infrastructure.
CVE-2024-36985: Splunk Enterprise RCE via File Upload - Patch Guide
Splunk patches a high-severity RCE vulnerability (CVE-2024-36985) allowing low-privileged users to execute code on Windows-based Enterprise instances.
Cisco Webex Services CVE-2024-20419: Manual Patch Guidance
Cisco identifies a critical improper certificate validation flaw in Webex Services. This advisory details the required manual remediation steps for admins.
Cisco Patches Critical RCE and SSO Flaws in ISE and Webex Services
Cisco releases patches for four critical vulnerabilities, including CVE-2026-20184, which allows RCE and user impersonation in Identity Services and Webex.
Claude Code and Gemini CLI: Prompt Injection via Code Comments
Research reveals how Claude Code, Gemini CLI, and GitHub Copilot agents are vulnerable to prompt injection attacks via malicious source code comments.
Windows Server 2025 KB5082063 Update Fails to Install — Analysis
Microsoft is investigating reports of KB5082063 failing to install on Windows Server 2025, leaving systems potentially vulnerable to unpatched threats.
NGINX-UI Critical Flaw: Attackers Can Alter NGINX Configs
A critical flaw in nginx-ui allows attackers to remotely restart, create, modify, and delete NGINX configuration files, posing significant risk to web servers.