Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
Autonomous Agentic AI Adversaries: Managing Machine-Speed Cyber Threats
The transition to agentic AI adversaries marks the end of human-speed threats. Learn how autonomous agents automate exploit discovery and execution at scale.
CVE-2024-6387: OpenSSH regreSSHion RCE — Mitigation Guide
Critical analysis of CVE-2024-6387 (regreSSHion) in OpenSSH. Learn technical details of the signal handler race condition and how to defend Linux systems.
CVE-2024-20230: Critical RCE in Cisco Unified CM Actively Exploited
Cisco confirms active exploitation of CVE-2024-20230, a critical 9.9 CVSS vulnerability in Unified Communications Manager. Urgent patching is required.
Cisco Unified CM CVE-2026-20230: File-Write Path to Root Exploited
Exploitation of CVE-2026-20230 in Cisco Unified CM allows unauthenticated root access via file-write. Critical security updates are required to prevent compromise.
CVE-2026-20230: Cisco Unified CM SSRF Actively Exploited
Cisco Unified CM Server is vulnerable to CVE-2026-20230, a high-severity SSRF flaw now under active exploitation. Patch immediately to prevent attacks.
Dify AI Platform Data Exposure: Multi-Tenant Risks
Dify AI platform users face critical data exposure flaws, enabling access to private chats, documents, and internal APIs in multi-tenant environments.
Proactive Exploit Validation: Mitigating Rapidly Weaponized Vulnerabilities
Security teams face rapidly weaponized vulnerabilities. Learn how to proactively validate exploitability and fortify defenses against emerging threats, even before…
Dify AI Platform Vulnerabilities: How to Mitigate DifyTap Exploit
Researchers discover DifyTap vulnerabilities in the Dify AI platform, allowing attackers to exfiltrate chat histories and secrets through SSRF and RCE.
Samsung KNOX Kernel Attack Flaw: Millions of Galaxy Devices Exposed
High-severity use-after-free vulnerability in Samsung KNOX exposed millions of Galaxy devices (S9-S25) to kernel attacks for years.
CVE-2024-40766: SonicWall SonicOS Patch and Configuration Guide
Analysis of CVE-2024-40766, a critical improper access control flaw in SonicWall SonicOS exploited by ransomware groups. Learn how to secure management interfaces.
OpenAI Expands Daybreak: Using GPT-5.5-Cyber to Patch Vulnerabilities
OpenAI enhances its Daybreak initiative with GPT-5.5-Cyber, a specialized model designed for deep codebase analysis to identify and remediate security flaws.
JaredFromSubway MEV Bot Exploit: $15 Million Lost in Logic Hack
An attacker drained $15 million from the JaredFromSubway Ethereum MEV bot by manipulating its trading logic through the use of malicious bait tokens.
Gravity SMTP Flaw Exploited: WordPress Data Harvest & Remediation
Attackers are actively exploiting a flaw in the Gravity SMTP WordPress plugin to exfiltrate sensitive data, including API keys and server info.
Squidbleed: Heartbleed-Style Data Exposure in Squid Proxy
A critical flaw dubbed Squidbleed in Squid Proxy, affecting versions 3.5-6.x, enables Heartbleed-style memory leakage exposing user credentials and session data.
Microsoft AutoGen Studio RCE via AutoJack Flaw — Patch Now
Microsoft patched the AutoJack vulnerability chain in AutoGen Studio, enabling remote code execution through malicious AI agent manipulation.
Squidbleed: 29-Year-Old Squid Proxy Bug Leaks Cleartext HTTP Requests
A 29-year-old heap over-read vulnerability, dubbed 'Squidbleed,' in Squid web proxy's default configuration can leak cleartext HTTP requests and credentials.
DifyTap Flaws Expose AI Chats in Dify Platform Without Auth
Zafran Security details DifyTap, a set of four vulnerabilities in Dify, allowing unauthenticated access to cross-tenant AI chat data. Learn impact and mitigation.
CVE-2024-0012: Critical PAN-OS Management Interface RCE Analysis
Technical analysis of CVE-2024-0012 affecting Palo Alto Networks PAN-OS. Learn how to detect CVE-2024-0012 exploit and implement immediate mitigation steps.
Apple A-Series BootROM Bypass: Usbliter8 Exploit Technical Analysis
Technical breakdown of the Usbliter8 exploit affecting millions of iPhones. Learn why this hardware-level BootROM vulnerability cannot be patched.
CVE-2026-4020: Gravity SMTP Exploit Exposes WordPress API Keys
Unauthenticated attackers are exploiting CVE-2026-4020 in the Gravity SMTP WordPress plugin to extract API keys, secrets, and OAuth tokens from 100,000 sites.
CVE-2024-49403: Gravity SMTP Information Disclosure Patch Guidance
Exploitation of CVE-2024-49403 in the Gravity SMTP WordPress plugin allows unauthenticated actors to steal SMTP credentials. Learn how to secure your site now.
usbliter8 Exploit Breaks Apple A12/A13 SecureROM Boot Chain
Paradigm Shift researchers disclose 'usbliter8', an unpatchable hardware exploit enabling arbitrary code execution in Apple A12 and A13 SecureROM, requiring physical…
GCP Config Connector Takeover: Unpatched Flaw Critical for Cloud Environments
An unpatched flaw in GCP Config Connector poses a critical takeover risk to Google Cloud environments.
AutoJack: AI Browsing Agents Hijacked for Host RCE via Web Pages
Microsoft researchers reveal AutoJack, a novel exploit chain where malicious web pages hijack AI browsing agents to achieve remote code execution on host systems.