Advertisement
GetProcessHandleFromHwnd API: UAC Bypass Implications
Investigate the GetProcessHandleFromHwnd API's role in a Quick Assist UAC bypass. Understand its mechanism, UIAccess implications, and defender recommendations.
Multiple DoS/RCE Vulnerabilities in Yokogawa CENTUM VP R6, R7
CISA alerts to multiple medium-severity vulnerabilities in Yokogawa CENTUM VP R6 and R7, allowing DoS and RCE via crafted packets in critical infrastructure
Critical Authentication Flaws in Chargemap EV Infrastructure
CISA warns of critical vulnerabilities in Chargemap EV charging stations, including unauthenticated WebSocket access and session hijacking (CVE-2026-25851).
Trend Micro Patches Critical RCE Flaws in Apex One Security Platform
Trend Micro addresses two critical vulnerabilities, CVE-2023-32524 and CVE-2023-32525, in its Apex One platform that allow for remote code execution.
Anthropic Patches Claude Code Vulnerabilities Enabling Silent Hacking
Anthropic addressed flaws in Claude Code that allowed attackers to execute arbitrary commands on developer devices via malicious repository configurations.
Zyxel Fixes Critical RCE Vulnerability in UPnP Implementation
Zyxel releases patches for CVE-2024-42057, a command injection flaw in the UPnP function of several VMG and fiber router models, allowing unauthenticated RCE.
Cisco SD-WAN Zero-Day CVE-2026-20127 Exploited for Admin Access
CVE-2026-20127 is a critical CVSS 10.0 flaw in Cisco SD-WAN controllers exploited since 2023, allowing unauthenticated remote administrative access.
CISA Adds Two Cisco SD-WAN Exploits to KEV Catalog
CISA adds CVE-2022-20775 (Path Traversal) and CVE-2026-20127 (Auth Bypass) affecting Cisco SD-WAN to its Known Exploited Vulnerabilities Catalog.
Critical Cisco SD-WAN Zero-Day Exploited Since 2023
Cisco Catalyst SD-WAN critical authentication bypass (CVE-2026-20127) actively exploited since 2023, enabling remote compromise and rogue peer addition.
Claude Code Flaws Enable RCE & API Key Exfiltration
Multiple security flaws in Anthropic's Claude Code AI coding assistant allow remote code execution and API credential theft via configuration mechanisms.
CISA Adds FileZen CVE-2026-25108 Command Injection to KEV Catalog
CISA confirms active exploitation of FileZen CVE-2026-25108, an OS command injection flaw. Organizations must patch immediately to prevent command execution.
SolarWinds Patches Four Critical RCE Flaws in Serv-U File Transfer
SolarWinds addresses four critical vulnerabilities (CVSS 9.1) in Serv-U 15.5, including CVE-2025-40538, which allows unauthorized root code execution.
January 2026 CVE Landscape: APT28 Zero-Day & Critical Flaws
Runtime Rebel details January 2026's 23 critical CVEs, including an APT28 zero-day in Microsoft Office and critical enterprise authentication bypass vulnerabilities.
macOS coreaudiod Type Confusion Exploitation: CVE-2024-54529
Analysis of CVE-2024-54529, a critical type confusion vulnerability in macOS coreaudiod, detailing its exploitation and necessary mitigations.
Windows Administrator Protection Bypassed via UI Access Abuse
Analysis of UI Access abuse techniques that bypassed Windows Administrator Protection, a new UAC feature, detailing historical context and fixes.
Open Redirects: Overlooked Vulnerability Impact & Analysis
An analysis of open redirect vulnerabilities, their historical context in OWASP, common exploitation vectors like phishing, and essential mitigation strategies.
CISA Alert: CVE-2026-25108 Soliton FileZen OS Command Injection Exploited
CISA adds CVE-2026-25108, a Soliton Systems FileZen OS Command Injection vulnerability, to KEV Catalog due to active exploitation. Immediate remediation advised.
Critical RCE Flaws in InSAT MasterSCADA BUK-TS Affect ICS
Two critical vulnerabilities (SQLi, OS Command Injection) in InSAT MasterSCADA BUK-TS lead to remote code execution, impacting critical infrastructure sectors globally.
VMware Aria Operations RCE Vulnerability Patched
Broadcom patched high-severity vulnerabilities in VMware Aria Operations, including an RCE flaw. Organizations must update immediately to mitigate risk.
Critical Flaws in PUSR USR-W610 Impact Critical Manufacturing
CISA identifies critical vulnerabilities in PUSR USR-W610 gateways, including authentication bypass and credential theft. No patches available for EOL hardware.
Valmet DNA Engineering Web Tools Vulnerable to Path Traversal
Unauthenticated attackers can exploit CVE-2025-15577 in Valmet DNA Engineering Web Tools to gain arbitrary file read access across critical infrastructure.
CISA Adds Roundcube Webmail Vulnerabilities to KEV Catalog
CISA adds CVE-2025-49113 and CVE-2025-68461 to its Known Exploited Vulnerabilities catalog, signaling active exploitation of Roundcube Webmail systems.
Chinese APTs Exploit CVE-2024-34351 in TeamT5 ThreatSonar
Taiwanese security firm TeamT5 confirms that a critical command injection flaw in ThreatSonar Anti-Ransomware has likely been exploited by Chinese APT groups.
Microsoft Investigating Mouse Pointer Bug in Classic Outlook
Microsoft confirms a bug in classic Outlook causing the mouse cursor to disappear during email composition. Discover the technical details and mitigation steps.