Coverage
Vulnerabilities
903 articles on vulnerability disclosures and exploits
Advertisement
Continuous Security Testing: Closing the 345-Day Exposure Gap
Analyze why annual penetration tests leave 345 days of risk and how continuous security validation for financial institutions improves resilience.
Android and Linux Kernel Exploitation: CVE-2024-36971 and CVE-2024-21626
CISA adds Android CVE-2024-36971 and Linux CVE-2024-21626 to its KEV catalog following reports of active exploitation by sophisticated threat actors.

Google Gemini Indirect Prompt Injection via Malicious Notifications
Security researchers demonstrate how malicious notifications can manipulate Google Gemini's voice assistant to perform unauthorized tasks or exfiltrate data.
Evaluating AI Agent Security: 100 Agents Tested for Vulnerabilities
An industry-first evaluation of 100 AI agents highlights critical security gaps in defense and the high impact of potential agentic compromises.
WordPress Sites Targeted via Kirki and Burst Statistics Vulnerabilities
Attackers are exploiting unauthenticated stored XSS in Kirki and Burst Statistics plugins to achieve privilege escalation and website takeover.
Acer Wave 7 Router RCE via CVE-2024-41591 and CVE-2024-41592
Acer addresses two critical 10.0 CVSS zero-day vulnerabilities in Wave 7 mesh routers that allow unauthenticated remote code execution and full takeover.

GitHub.dev One-Click Attack: Stealing OAuth Tokens via VS Code
New research reveals a one-click exploit in GitHub.dev and VS Code that allows attackers to steal full GitHub OAuth tokens and access private repositories.
VS Code Zero-Day Exploit: Stealing GitHub Tokens via URI Handlers
Security researcher mthcht reveals a VS Code zero-day vulnerability allowing GitHub token theft via URI handlers. Learn how to defend against this exploit.

HTTP/2 Bomb: Remote DoS Affects NGINX, Apache, and Microsoft IIS
Researchers identify HTTP/2 Bomb vulnerability affecting NGINX, Apache, and IIS default settings, allowing remote denial-of-service attacks on web servers.
PHP RCE via CVE-2024-4577 — Windows Argument Injection Analysis
Technical analysis of the CVE-2024-4577 vulnerability affecting PHP on Windows. Learn how argument injection leads to RCE and how to secure PHP-CGI environments.
CISA KEV Update: Active Exploitation of CVE-2022-0492 and CVE-2025-48595
CISA adds Linux Kernel and Android Framework vulnerabilities to its Known Exploited Vulnerabilities catalog. Prioritize patching CVE-2022-0492 and CVE-2025-48595.

Gamaredon Exploits WinRAR CVE-2025-8088 to Target Ukraine
Russian threat actor Gamaredon weaponizes a WinRAR path traversal flaw to deploy GammaWorm and GammaSteel malware against Ukrainian entities.