Advertisement
Critical Cisco SD-WAN Zero-Day Exploited Since 2023
Cisco Catalyst SD-WAN critical authentication bypass (CVE-2026-20127) actively exploited since 2023, enabling remote compromise and rogue peer addition.
Claude Code Flaws Enable RCE & API Key Exfiltration
Multiple security flaws in Anthropic's Claude Code AI coding assistant allow remote code execution and API credential theft via configuration mechanisms.
CISA Adds FileZen CVE-2026-25108 Command Injection to KEV Catalog
CISA confirms active exploitation of FileZen CVE-2026-25108, an OS command injection flaw. Organizations must patch immediately to prevent command execution.
SolarWinds Patches Four Critical RCE Flaws in Serv-U File Transfer
SolarWinds addresses four critical vulnerabilities (CVSS 9.1) in Serv-U 15.5, including CVE-2025-40538, which allows unauthorized root code execution.
January 2026 CVE Landscape: APT28 Zero-Day & Critical Flaws
Runtime Rebel details January 2026's 23 critical CVEs, including an APT28 zero-day in Microsoft Office and critical enterprise authentication bypass vulnerabilities.
macOS coreaudiod Type Confusion Exploitation: CVE-2024-54529
Analysis of CVE-2024-54529, a critical type confusion vulnerability in macOS coreaudiod, detailing its exploitation and necessary mitigations.
Advertisement
Windows Administrator Protection Bypassed via UI Access Abuse
Analysis of UI Access abuse techniques that bypassed Windows Administrator Protection, a new UAC feature, detailing historical context and fixes.
Open Redirects: Overlooked Vulnerability Impact & Analysis
An analysis of open redirect vulnerabilities, their historical context in OWASP, common exploitation vectors like phishing, and essential mitigation strategies.
CISA Alert: CVE-2026-25108 Soliton FileZen OS Command Injection Exploited
CISA adds CVE-2026-25108, a Soliton Systems FileZen OS Command Injection vulnerability, to KEV Catalog due to active exploitation. Immediate remediation advised.
Critical RCE Flaws in InSAT MasterSCADA BUK-TS Affect ICS
Two critical vulnerabilities (SQLi, OS Command Injection) in InSAT MasterSCADA BUK-TS lead to remote code execution, impacting critical infrastructure sectors globally.
VMware Aria Operations RCE Vulnerability Patched
Broadcom patched high-severity vulnerabilities in VMware Aria Operations, including an RCE flaw. Organizations must update immediately to mitigate risk.
Critical Flaws in PUSR USR-W610 Impact Critical Manufacturing
CISA identifies critical vulnerabilities in PUSR USR-W610 gateways, including authentication bypass and credential theft. No patches available for EOL hardware.
Valmet DNA Engineering Web Tools Vulnerable to Path Traversal
Unauthenticated attackers can exploit CVE-2025-15577 in Valmet DNA Engineering Web Tools to gain arbitrary file read access across critical infrastructure.
CISA Adds Roundcube Webmail Vulnerabilities to KEV Catalog
CISA adds CVE-2025-49113 and CVE-2025-68461 to its Known Exploited Vulnerabilities catalog, signaling active exploitation of Roundcube Webmail systems.
Chinese APTs Exploit CVE-2024-34351 in TeamT5 ThreatSonar
Taiwanese security firm TeamT5 confirms that a critical command injection flaw in ThreatSonar Anti-Ransomware has likely been exploited by Chinese APT groups.
Microsoft Investigating Mouse Pointer Bug in Classic Outlook
Microsoft confirms a bug in classic Outlook causing the mouse cursor to disappear during email composition. Discover the technical details and mitigation steps.
Security Flaws in Android Mental Health Apps Affect 14.7M Users
Multiple Android mental health apps suffer from hardcoded credentials and insecure data storage, putting sensitive patient information at risk.
Exploitation of SVG-Based XSS in RoundCube Webmail Instances
Technical analysis of a cross-site scripting (XSS) vulnerability in RoundCube Webmail triggered by improper sanitization of SVG animate elements.
Exploitation of Roundcube Webmail Cross-Site Scripting Vulnerabilities
CISA has added two Roundcube Webmail vulnerabilities to its Known Exploited Vulnerabilities catalog, signaling active exploitation of legacy flaws in webmail…
Microsoft February 2026 Security Update: Analysis of Six Actively Exploited Zero-Days
Microsoft's latest security release addresses 50+ vulnerabilities, including six zero-day exploits targeting Windows kernel components and browser engines.
Logic Flaws and Data Exfiltration in Autonomous AI Agent Architectures
Technical analysis of guardrail bypasses in LLM-integrated agents, highlighting the transition from conversational models to autonomous actors with privileged access.
Automated Reconnaissance Targeting React2Shell Implementations
Analysis of a specialized toolkit currently utilized by threat actors to identify and exploit React2Shell vulnerabilities within enterprise network perimeters.
Unauthenticated Root RCE in Grandstream IP Phones
A critical vulnerability tracked as CVE-2026-2329 allows unauthenticated remote code execution with root privileges on Grandstream VoIP endpoints.
CISA Catalogs Critical Roundcube Deserialization Vulnerability Under Active Exploitation
CISA has added CVE-2025-49113 to the Known Exploited Vulnerabilities catalog, addressing a critical RCE flaw in Roundcube webmail software resulting from untrusted data…