Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
OpenSSL HollowByte Vulnerability: Mitigating Memory Exhaustion Risks
OpenSSL addresses the HollowByte Denial-of-Service vulnerability. Learn how buffer pre-allocation flaws impact server availability and memory management.
WordPress RCE and SonicWall Zero-Days: Weekly Threat Intel Update
Active exploitation of WordPress RCE and SonicWall zero-day vulnerabilities highlights critical risks for internet-facing systems. Learn how to mitigate.
Capital One VulnHunter: Open-Source AI Tool for Exploit Path Analysis
Capital One open-sources VulnHunter, an AI-powered agentic tool designed to trace complex exploit paths and validate software vulnerabilities autonomously.
KB5121767: Microsoft Fixes Windows 11 Dell PC Shutdown Bug
Microsoft issues emergency out-of-band update KB5121767 to resolve critical system shutdown issues affecting Dell PCs running the July 2026 Windows 11 update.
7-Zip RCE via CVE-2026-14266: XZ Archive Extraction Patch Guidance
7-Zip versions prior to 26.02 are vulnerable to a heap-based buffer overflow. Learn how to mitigate CVE-2026-14266 and secure XZ archive extractions.
WP2Shell Vulnerabilities CVE-2026-60137 & CVE-2026-63030 Exploited
WordPress sites face active exploitation via WP2Shell vulnerabilities CVE-2026-60137 and CVE-2026-63030. Learn the technical details and mitigation steps.
CVE-2026-42533: NGINX RCE and Denial of Service — Mitigation Guide
Exploit analysis of CVE-2026-42533, a critical heap buffer overflow in NGINX. Learn how to detect and patch worker process crashes and potential RCE.
Hikvision ISAPI Scanning Trends: Analysis and Mitigation Guide
Recent honeypot data reveals a surge in probes targeting the Hikvision Intelligent Security API. Learn how to identify and defend against these IoT scans.
SonicWall SMA 1000 Zero-Day Exploitation: Analysis of UTA0533 TTPs
A technical analysis of zero-day exploitation against SonicWall SMA 1000 series appliances by threat actor UTA0533 to gain root access and persistence.
WordPress wp2shell RCE: Public Exploits Released for Core Flaws
Public exploits for wp2shell RCE flaws in WordPress Core are now available. Learn how to detect, mitigate, and patch these critical vulnerabilities immediately.
7-Zip 24.05 RCE via Malicious Archives: Patch Guidance
7-Zip version 24.05 addresses a critical remote code execution vulnerability found in archive handling. Learn how to detect and mitigate this risk in your SOC.
WordPress Core RCE wp2shell: Versions 6.9 and 7.0 Vulnerable
Unauthenticated attackers can achieve RCE on WordPress 6.9 and 7.0 core installations via the wp2shell flaw. Learn how to secure your site today.
Inc Ransomware Exploits SonicWall SMA Zero-Days for Root Access
Inc Ransomware is actively exploiting chained zero-day vulnerabilities in SonicWall SMA appliances, achieving root-level capabilities.
HollowByte DDoS: OpenSSL Memory Exhaustion via 11-byte Payload
HollowByte enables unauthenticated DoS on OpenSSL servers, depleting memory with an 11-byte payload. Understand the impact and mitigation.
OpenSSL HollowByte Flaw: Memory Exhaustion via 11-Byte TLS Requests
The HollowByte vulnerability allows attackers to freeze OpenSSL server memory using 11-byte requests. Learn how to mitigate this denial-of-service risk.
Gold Eagle Clearinghouse: Centralizing AI Vulnerability Management
The White House Gold Eagle clearinghouse aims to coordinate AI vulnerability responses, yet technical implementation details remain unclear for security teams.
Windows LegacyHive Zero-Day Exploit Grants Admin Access — Patch Status
The LegacyHive Zero-Day exploit allows local attackers to gain SYSTEM privileges on patched Windows systems by targeting legacy registry hive permissions.
CVE-2026-58644: SharePoint RCE Zero-Day Exploited in the Wild
CISA adds CVE-2026-58644, a critical Microsoft SharePoint Server deserialization RCE vulnerability with a CVSS 9.8, to its Known Exploited Vulnerabilities catalog.
Anthropic Claude Chrome Extension: Malicious AI Action Trigger
A flaw in Anthropic's Claude for Chrome extension enables malicious extensions to trigger AI actions, potentially abusing access to connected services like Gmail, Google…
AI-Assisted Vulnerability Management: Operational Guardrails & Risks
Implement robust guardrails for AI-assisted vulnerability management. Learn to safely deploy LLM agents, reduce architectural risks, and prioritize human-led threat…
OT Security: Legacy System Vulnerabilities in Critical Infrastructure
Addressing the complex challenges of securing legacy OT systems in critical infrastructure, balancing vulnerability disclosure with operational continuity and safety.
n8n Token Exchange Flaw: Impersonation via `sub` Claim Bypass
A critical token exchange vulnerability in n8n Enterprise allows attackers to impersonate users by leveraging `sub` claim matching across multiple external issuers…
F5 BIG-IP and NGINX Vulnerabilities: CVE-2024-41730 and CVE-2024-39475
F5 releases critical security updates for BIG-IP and NGINX Plus, addressing authentication bypass, RCE, and memory corruption vulnerabilities.
Zoom CVE-2026-53412: Critical Windows Client Account Takeover Fix
Zoom releases critical security updates for CVE-2026-53412, a high-severity input validation flaw in Windows clients allowing unauthenticated account takeover.