Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
Security Vendors Patch Severe RCE and LPE Vulnerabilities
Analysis of critical vulnerabilities in Trend Micro, Tanium, ESET, and Tenable products, including CVE-2024-48904 and local privilege escalation flaws.
UEFI Shim Bootloader Vulnerabilities: Secure Boot Blind Spot
Nearly a dozen vulnerable UEFI shim bootloaders remained trusted for years, allowing attackers to bypass Secure Boot for persistent malware and rootkit deployment.
CVE-2024-24691: Zoom Windows Client Account Takeover - Patch Now
Zoom has addressed CVE-2024-24691, a critical 9.6 CVSS vulnerability in Windows clients allowing unauthenticated account takeover. Learn how to patch and defend.
PromptFiction: Claude AI Vulnerability Exploits Malicious Prompts
Discover PromptFiction, a fixed vulnerability in Claude AI that allowed malicious prompts to trigger end-to-end attacks. Learn mitigation for AI agent security.
Microsoft SharePoint RCE via CVE-2024-38094: Mitigation Guide
CISA adds three exploited SharePoint vulnerabilities to the KEV catalog, including CVE-2024-38094. Learn how to detect and mitigate these critical RCE flaws.
Cursor RCE via Malicious Git Executable — Unpatched Vulnerability Alert
An unpatched vulnerability in the Cursor AI code editor allows RCE when users clone a malicious Git repository containing a crafted git.exe in the project root.
AI-Powered Vulnerability Discovery: Automated Zero-Day Mining with LLMs
Intruder reveals an AI-driven system combining code slicing and LLMs to automatically discover complex software vulnerabilities and zero-day exploits.
Firefox CVE-2026-15718 and CVE-2026-15719: Patch Guidance
Mozilla issues critical updates for Firefox to fix CVE-2026-15718 and CVE-2026-15719. Public exploit code for these flaws necessitates immediate remediation.
2-Click Cursor Exploit: Dev Environment Takeover Risks & Mitigations
Analyze the '2-click cursor exploit' leveraging 'age-old bugs' to compromise developer environments, risking source code and IP theft.
Windows User Profile Service EoP: LegacyHive Zero-Day PoC Released
A new Zero-Day PoC named LegacyHive targets the Windows User Profile Service (ProfSvc) for local privilege escalation, bypassing recent system patches.
Apple July 2024 Security Updates: Mitigation and Patch Analysis
Apple addresses critical vulnerabilities in macOS, iOS, and visionOS. This guide analyzes kernel-level RCE and privilege escalation risks in the latest patches.
Microsoft April 2024 Patch Tuesday Analysis: Three Zero-Days Patched
Analysis of Microsoft's April 2024 Patch Tuesday featuring 147 CVEs, including critical zero-days CVE-2024-26234 and CVE-2024-29988. Mitigation guide for SOCs.
Siemens and Schneider Patch Critical ICS Flaws — October 2024
Siemens, Schneider Electric, and Rockwell Automation release critical updates for ICS products including SCALANCE, SINEC, and EcoStruxure platforms.
CVE-2024-10022: Progress ShareFile Storage Zones Controller Zero-Day
Progress Software patches a critical zero-day in ShareFile Storage Zones Controller. Learn how to detect and mitigate this improper access control exploit.
CVE-2023-29357: CISA Warns of Active SharePoint Exploit Chain
CISA urges immediate patching of CVE-2023-29357 and CVE-2023-24955 in SharePoint Server due to active exploitation for remote code execution.
SonicWall SMA 1000 Series Zero-Days CVE-2026-15409 - Mitigation Guide
SonicWall warns of active exploitation of two zero-day vulnerabilities in SMA 1000 series appliances, including a critical CVSS 10.0 SSRF (CVE-2026-15409).
Microsoft Patch Tuesday: Addressing 570 Security Flaws
Microsoft released updates for a record 570 security flaws in Windows and other software, with AI aiding discovery. Learn the impact and mitigation.
SonicWall SMA1000 Series RCE via CVE-2026-15409 — Mitigation Guide
SonicWall warns of two critical zero-day vulnerabilities in SMA1000 series appliances (CVE-2026-15409, CVE-2026-15410) allowing remote code execution.
Microsoft Zero-Days: Active Directory & SharePoint Exploited
Microsoft addresses 622 vulnerabilities, including two actively exploited zero-days in Active Directory and SharePoint Server.
CVE-2026-15409: SonicWall SMA 1000 Zero-Day Patch Guide
SonicWall warns of active zero-day exploitation for CVE-2026-15409 and CVE-2026-15410 in SMA 1000 appliances. Apply firmware updates immediately to prevent RCE.
CVE-2026-44747: SAP NetWeaver ABAP Out-of-Bounds Write Flaw
SAP NetWeaver ABAP users must patch CVE-2026-44747 (CVSS 9.9) immediately to prevent authenticated attackers from exposing or modifying critical data via memory…
Microsoft Patches Record 622 Flaws and Two Zero-Days — Patch Now
Microsoft releases its largest Patch Tuesday ever, addressing 622 vulnerabilities and two zero-days under active attack. Analyze the security impact here.
FIFA Network Vulnerability: Minimal Access Leads to Broad Compromise
An unidentified vulnerability exposed FIFA's network to compromise with minimal access, highlighting risks of overlooked attack surfaces and privilege escalation.
VMware Avi Load Balancer: Severe Vulnerabilities Enable RCE, Bypass
VMware has patched 7 severe vulnerabilities in Avi Load Balancer, enabling authentication bypass, RCE, privilege escalation, and directory traversal.