Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
ShinyHunters Breach NAIC via PeopleSoft Zero-Day: Public Data Stolen
ShinyHunters exploited an Oracle PeopleSoft zero-day to breach NAIC, exfiltrating public data, logs, and configuration files. Review PeopleSoft security.
Nissan Breach: Oracle PeopleSoft Zero-Day Exploited by ShinyHunters
Nissan discloses a data breach impacting current and former employees, attributed to an exploited Oracle PeopleSoft zero-day vulnerability linked to the ShinyHunters…
Weak RSA Keys with Many Zeros Found In-the-Wild: Factoring Risk
New research reveals a class of weak RSA keys containing many zero bits, making them vulnerable to factoring.
DirtyClone: Linux Kernel Privilege Escalation via Page Cache Manipulation
DirtyClone, a variant of DirtyFrag, allows unprivileged local users to exploit a Linux kernel flaw to manipulate the page cache and achieve root privileges.
libssh2 1.11.1 RCE via CVE-2026-55200 — Mitigation Guide
Exploit analysis and mitigation for CVE-2026-55200, a critical client-side RCE in libssh2 affecting versions up to 1.11.1. Public PoC now available.
Declining Confidence in Autonomous Penetration Testing: 2024 Analysis
Security leaders are re-evaluating autonomous penetration testing due to accuracy concerns, shifting focus toward human-led automated security validation.
Cisco Unified Communications Manager: Urgent Patch for Active Exploitation
CISA mandates urgent patching for an actively exploited vulnerability in Cisco Unified Communications Manager, posing immediate risk to federal agencies and beyond.
Amazon Q Flaw: Cloud Credential Theft via Malicious Repositories
AWS patches a critical Amazon Q flaw enabling cloud credential theft via malicious repositories. Understand its impact and recommended mitigations.
Amazon Q Developer RCE via CVE-2026-12957 - Cloud Credential Theft
High-severity CVE-2026-12957 in Amazon Q Developer allowed malicious repositories to execute arbitrary code and steal cloud credentials upon workspace trust. Patch now.
CVE-2026-46331: Linux pedit COW Exploit Grants Root Access
A critical Linux kernel flaw, 'pedit COW' (CVE-2026-46331), allows local unprivileged users to gain root access via an out-of-bounds write. Public exploits exist.
Linux Foundation's Project Akrites: Bolstering Open Source Security
Project Akrites aims to streamline vulnerability management across open source projects, enhancing reporting, patching, and disclosure processes for critical software.
CVE-2026-43503: Linux Kernel DirtyClone Flaw Grants Root Access
DirtyClone (CVE-2026-43503) is a Linux kernel privilege escalation allowing local users to gain root access via cloned network packets. Patch now.
Turla's STOCKSTAY Backdoor: Analysis of Campaigns & WinRAR Exploit
Google Threat Intelligence details STOCKSTAY, Turla's .NET backdoor for espionage targeting Ukraine and Europe, leveraging RDP & CVE-2025-8088.
CVE-2022-25247: PTC Windchill RCE Exploited in the Wild
CISA warns of active exploitation of CVE-2022-25247, an RCE flaw in PTC Windchill PLM software. Learn how to detect and mitigate this critical threat.
Cisco CUCM SSRF Flaw: Rapid Exploitation & Root Privilege Escalation
Attackers are rapidly weaponizing a Cisco Unified CM server-side request forgery (SSRF) flaw, escalating privileges to root. Immediate patching is critical.
ThreatsDay Bulletin: Proxyware, Legacy Flaws, and AI Crime Trends
Analysis of recent cybersecurity threats including smart TV proxyware, a 24-year curl bug, and AI-driven cybercrime trends impacting enterprise security.
LLM Prompt Injection: Role Confusion Exposes Core Architectural Flaws
An in-depth analysis of LLM prompt injection, detailing how 'role confusion' in model representations undermines tag-based security and demands architectural solutions.
Analyzing Internet Background Radiation and Automated Scanning Trends
An analysis of automated cybercrime traffic and internet background radiation, detailing how botnets exploit vulnerabilities like CVE-2017-17215.
CVE-2026-20245: Zero-Day Root Privilege Escalation in Cisco SD-WAN
Attackers are exploiting a zero-day vulnerability in Cisco Catalyst SD-WAN Manager to gain root access. Learn how to detect and remediate CVE-2026-20245.
Chrome 149 Update Patches 18 High-Severity UAF Vulnerabilities
Google releases Chrome 149 to address 18 severe vulnerabilities, including multiple use-after-free defects in Graphics, Dawn, and Mojo components.
Cisco Catalyst SD-WAN CVE-2026-20245 Root Access Exploit Analysis
Exploitation of Cisco Catalyst SD-WAN zero-day CVE-2026-20245 allows root access. Mandiant reveals active abuse months prior to the June 2026 disclosure.
Cisco SD-WAN CVE-2023-20252 Exploited via Rogue Peering - Patch Now
Attackers exploited Cisco SD-WAN Manager flaws like CVE-2023-20252 for two months before disclosure. Learn how to secure your vManage infrastructure today.
CVE-2025-67038: Lantronix EDS5000 Series Critical Code Injection
CISA warns of active exploitation of CVE-2025-67038, a critical code injection flaw impacting Lantronix EDS5000 Series devices. Patch immediately.
CISA Warns: Ubiquiti UniFi & Lantronix Flaws Actively Exploited
CISA warns of active exploitation against Ubiquiti UniFi OS and Lantronix serial-to-ethernet servers. Security professionals must patch immediately.