Advertisement
CVE-2026-66066: Unauthenticated File Read in Rails Active Storage
Unauthenticated attackers can exploit CVE-2026-66066 in Ruby on Rails Active Storage to read sensitive server files, potentially leading to full compromise.
24,650 Exposed BMCs Leak IPMI Password Hashes via RAKP Flaw
Over 24,000 BMC management interfaces are exposing IPMI password hashes to the internet, allowing attackers to perform offline cracking and server takeover.
Java Spring Boot Actuator: Mitigating /actuator/heapdump Scans
Learn how to protect Java Spring Boot applications from /actuator/heapdump scans. Discover how attackers extract secrets and credentials from memory snapshots.
Opera GX Mod Auto-Installation Vulnerability Analysis
A critical flaw in Opera GX allowed malicious sites to auto-install mods and exfiltrate sensitive data. Learn how to detect and mitigate this browser threat.
NetScaler Vulnerabilities: HTTP/2 Bomb & High-Severity Info Disclosure
Citrix addresses six NetScaler vulnerabilities, including a new HTTP/2 Bomb and a high-severity information disclosure bug similar to CitrixBleed.
CVE-2026-4020: Gravity SMTP Exploit Exposes WordPress API Keys
Unauthenticated attackers are exploiting CVE-2026-4020 in the Gravity SMTP WordPress plugin to extract API keys, secrets, and OAuth tokens from 100,000 sites.
Advertisement
CVE-2024-49403: Gravity SMTP Information Disclosure Patch Guidance
Exploitation of CVE-2024-49403 in the Gravity SMTP WordPress plugin allows unauthenticated actors to steal SMTP credentials. Learn how to secure your site now.
CVE-2022-21371: CISA Warns of Oracle WebLogic Exploitation
CISA adds CVE-2022-21371 to its KEV catalog, warning of active exploitation of an information disclosure flaw in Oracle WebLogic Server. Patch immediately.
CVE-2026-9082: Drupal Core RCE via Database API (PostgreSQL)
A highly critical flaw, CVE-2026-9082, in Drupal Core's database abstraction API allows RCE, privilege escalation, and info disclosure on PostgreSQL sites.
CVE-2024-24919: Critical Information Disclosure in Check Point Gateways
A technical analysis of CVE-2024-24919, a high-severity information disclosure flaw in Check Point Quantum Gateways, including exploit detection and mitigation.
CVE-2024-24919: Exploit Analysis and Check Point Gateway Mitigation
Technical analysis of CVE-2024-24919, a critical information disclosure vulnerability in Check Point Security Gateways exploited for credential harvesting.
WhatsApp Metadata Leak: Exposure Risks and Mitigation Strategies
WhatsApp's metadata leakage allows strangers to infer limited user information without interaction, potentially aiding targeted social engineering or other malicious…
Grafana AI Assistant Flaw Exposes User Data — Immediate Patch Required
Grafana patched an AI vulnerability where malicious instructions on web pages could trick its AI assistant into leaking sensitive user data. Immediate action needed.
Citrix NetScaler CVE-2026-3055 Memory Overread — Mitigation Guide
Attackers are actively scanning for CVE-2026-3055, a CVSS 9.3 memory overread flaw in Citrix NetScaler ADC and Gateway. Patch vulnerable instances immediately.
Citrix NetScaler Info Disclosure: CVE-2024-8069 Patch Guide
Citrix urges immediate patching of two NetScaler ADC and Gateway vulnerabilities, including a flaw similar to the high-impact CitrixBleed exploit.
CVE-2025-47813: CISA Warns of Wing FTP Server Path Leakage Exploitation
CISA adds CVE-2025-47813 to its KEV catalog, highlighting active exploitation of a Wing FTP Server information disclosure flaw that leaks internal server paths.
CVE-2025-47813: Wing FTP Server Information Disclosure Added to KEV
CISA adds CVE-2025-47813 to the Known Exploited Vulnerabilities catalog, signaling active exploitation of Wing FTP Server. Immediate patching is required.
Google Cloud API Keys Exposed via Public Gemini Access
Research reveals nearly 3,000 public GCP API keys exposed in client-side code grant unauthorized access to sensitive Gemini and Vertex AI endpoints.