Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
GhostApproval Symlink Flaws Threaten AI Coding Assistants
GhostApproval symlink vulnerabilities in six AI coding assistants allow malicious repositories to execute code, risking developer workstation compromise. Update software.
Zero-Day Acquisition Firm Raises Red Flags: Trust and Supply Chain Risks
A cybersecurity startup offering millions for zero-days is operated by convicted felons. This raises concerns about vulnerability integrity and supply chain risks.
Dialogflow CX 'Rogue Agent' Bug Enabled AI Conversation Hijacking
A 'Rogue Agent' vulnerability in Google Dialogflow CX could have allowed attackers to silently manipulate AI conversations, exfiltrate data, and compromise multiple…
Understanding Stack Overflow Exploitation: A Primer
Gain a foundational understanding of how program stacks work and why stack overflows are a critical attack vector for hijacking execution flow.
Gitea CVE-2026-20896 Authentication Bypass Under Active Exploitation
Attackers are exploiting CVE-2026-20896 in Gitea to bypass authentication via HTTP headers, risking unauthorized access to private code and secrets.
UniFi OS Command Injection: CVE-2024-42028 Exploitation & Patching
Ubiquiti patches critical vulnerabilities in UniFi OS, including a CVSS 10.0 command injection flaw. Immediate update to version 4.0.18 is required.
CVE-2024-37014: CISA Orders Federal Agencies to Patch Langflow
CISA added CVE-2024-37014, a critical authentication bypass in the Langflow AI framework, to its KEV catalog following reports of active exploitation.
CVE-2026-48282: Adobe ColdFusion Path Traversal RCE — Patch Now
CISA adds actively exploited Adobe ColdFusion vulnerability [CVE-2026-48282] to KEV catalog, warning of critical remote code execution risks.
CVE-2026-43499: GhostLock Linux Kernel Privilege Escalation Analysis
A 15-year-old Linux kernel flaw, CVE-2026-43499 (GhostLock), enables local root access and container escape across major distributions since 2011.
Google Dialogflow CX: Critical Flaw Allows Agent Hijack
A critical flaw in Google Dialogflow CX allowed attackers with edit rights to one agent to hijack others in the same project, exposing user data.
Writer AI Platform: Critical Session Isolation Flaw 'WriteOut'
Runtime Rebel details the critical 'WriteOut' session isolation vulnerability in Writer AI, enabling cross-tenant compromise and unauthorized agent takeover.
Linux Kernel Januscape Flaw: VM Escape on KVM Hypervisors
Analysis of the 16-year-old Januscape flaw affecting Linux KVM hypervisors, enabling VM escape and potential host code execution on Intel and AMD systems.
BeyondTrust RS/PRA Critical Authentication Bypass Flaws Addressed
BeyondTrust has issued an urgent advisory for critical authentication bypass flaws in Remote Support (RS) and Privileged Remote Access (PRA) software.
CVE-2026-11405: Tenda Router Firmware Admin Backdoor Exposed
CERT/CC warns of an undocumented admin backdoor, CVE-2026-11405, in Tenda router firmware, enabling full administrative access bypass. Immediate action advised.
CVE-2026-40138: BeyondTrust Pre-Auth Bypass in Remote Support & PRA
BeyondTrust patched CVE-2026-40138, a critical pre-authentication vulnerability in Remote Support and PRA, enabling unauthenticated device takeover. Patch immediately.
Critical RCEs: FortiNAC CVE-2023-33300 & SonicWall SMA Zero-Day
Two critical vulnerabilities, FortiNAC RCEs (CVE-2023-33300, CVE-2023-33299) and a SonicWall SMA zero-day SQLi, require immediate patching and mitigation.
NetScaler Memory Disclosure Flaw Under Active Exploitation
Attackers are actively exploiting a new memory disclosure flaw in Citrix NetScaler products, rapidly weaponizing a public proof-of-concept.
CVE-2026-53359: Linux KVM Guest-to-Host Escape via Januscape Flaw
A critical 16-year-old use-after-free vulnerability, Januscape (CVE-2026-53359), in Linux KVM allows guest VMs to escape to the host on Intel and AMD x86 systems.
Opera GX Mod Auto-Installation Vulnerability Analysis
A critical flaw in Opera GX allowed malicious sites to auto-install mods and exfiltrate sensitive data. Learn how to detect and mitigate this browser threat.
JadePuffer Ransomware: AI Agents Automate the Full Attack Lifecycle
Researchers have identified JadePuffer, a ransomware operation using LLM-driven AI agents to automate scanning, exploitation, and lateral movement.
Open Source Zero-Days and ATM Jackpotting: Analysis of Recent Threats
Legal actions against ATM jackpotting crews and hacktivists highlight ongoing risks in open-source security and financial infrastructure.
FatFs Vulnerabilities: Securing Embedded Devices Against RCE
Security researchers at runZero have disclosed seven vulnerabilities in the widely used FatFs library, impacting millions of IoT and industrial devices.
CVE-2026-46242: Linux Kernel Bad Epoll Flaw Grants Root on Servers, Android
Critical Linux kernel 'Bad Epoll' flaw (CVE-2026-46242) allows unprivileged users to gain root access on servers, desktops, and Android devices. Patch now.
Agentic AI Automates Ransomware Attacks via Langflow Exploitation
Agentic AI agents demonstrate automated multi-stage ransomware attacks using Langflow, raising concerns for AI development security and future threat automation.