Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
FortiBleed Data Leak: Securing Fortinet VPNs Against Exposure
CISA warns organizations after 74,000 Fortinet VPN credentials were leaked online. Learn how to mitigate the FortiBleed threat and secure your network.
CVE-2025-20701: Apple Patches Beats Studio Buds Eavesdropping Flaw
Apple addresses CVE-2025-20701, a high-severity flaw in Beats Studio Buds allowing nearby attackers to bypass pairing consent and access the microphone.
CVE-2026-42530 & -42531: NGINX RCE via Use-After-Free
F5 addresses critical RCE flaws [CVE-2026-42530, CVE-2026-42531] in NGINX Open Source. Unauthenticated attackers can exploit use-after-free issues. Patch now.
Rockwell RSLinx <4.50.00 RCE via CVE-2020-13573 — Patch Now
Urgent advisory for Rockwell RSLinx Classic users. CVE-2020-13573, a stack-based buffer overflow, enables remote code execution and DoS. Patch <=4.50.00.
CVE-2026-11317: Rockwell Logix DoS via CIP — Patch Critical ICS
Critical Manufacturing faces high-severity DoS risk in Rockwell Automation Logix 5370 & 5570 controllers from CVE-2026-11317. Patch now.
MongoBleed: Unauthenticated Credential Theft via Server Memory
Analysis of MongoBleed, a critical vulnerability enabling unauthenticated credential and session token extraction from server memory, highlighting attack surface…
Isira Adithya: Research Insights and Bug Bounty Defense Strategies
Examine the methodologies of security researcher Isira Adithya and how ethical hacker insights improve vulnerability management and web application security.
Microsoft Copilot 'SearchLeak' Attack: AI Prompt Injection Data Theft
Analysis of the critical Microsoft Copilot 'SearchLeak' attack. Learn how prompt injection allowed 1-click data theft and crucial defense strategies for AI applications.
CVE-2026-54420: LiteSpeed cPanel Plugin Flaw Under Active Exploit
CISA warns of active exploitation targeting CVE-2026-54420 in LiteSpeed cPanel user-end plugin, urging immediate patching for server security.
Fortinet FortiSandbox: Attackers Exploit CVE-2026-39813, -39808, -25089
Critical Fortinet FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are under active exploitation. Patch immediately.
Tech Coalition Athena: Collaborative OSS Vulnerability Pre-Disclosure
The Athena coalition, comprising over two dozen organizations, establishes a shared platform to proactively triage and remediate open-source software vulnerabilities…
Earth Lusca Deploys New SprySOCKS Windows Variant Against Governments
Earth Lusca has ported the SprySOCKS Linux malware to Windows, targeting government entities globally. Analyze the TTPs and learn how to detect this threat.
FortiSandbox RCE via CVE-2024-23108 and CVE-2024-23109 — Patch Now
Unauthenticated attackers are exploiting critical command injection flaws in Fortinet FortiSandbox to achieve RCE. Apply security updates immediately.
Cisco Catalyst SD-WAN Manager CVE-2026-20262 Exploited in the Wild
Cisco patches an actively exploited medium-severity vulnerability in Catalyst SD-WAN Manager (CVE-2026-20262) that allows authenticated file creation.
CVE-2023-6110: Rogue Account Creation in SimpleHelp — Patch Now
Attackers can exploit an OIDC implementation flaw in SimpleHelp servers to create unauthorized technician accounts. Immediate update to 5.2.24 is required.
CVE-2026-20262: Cisco SD-WAN vManage Root Privilege Escalation Fix
Cisco patches CVE-2026-20262, a critical Zero-Day flaw in Catalyst SD-WAN Manager allowing authenticated attackers to escalate to root privileges.
OptinMonster 2.6.5 Update: Managing CDN Supply Chain Attack Risks
Learn how the OptinMonster CDN supply chain attack compromised over 1 million WordPress sites and how to mitigate the risk of malicious script injection.
Microsoft 365 Copilot SearchLeak: One-Click Data Exfiltration
Varonis Threat Labs uncovered 'SearchLeak', a one-click flaw in Microsoft 365 Copilot Enterprise Search allowing exfiltration of emails, files, and MFA codes.
LiteLLM Proxy Server Takeover via Critical Vulnerability Chain
Researchers at Obsidian Security have identified a three-vulnerability chain in LiteLLM that allows low-privilege users to gain full server control.
CVE-2026-0257: Palo Alto Networks PAN-OS GlobalProtect Bypass Active
Palo Alto Networks warns of active exploitation of CVE-2026-0257, an authentication bypass flaw in PAN-OS GlobalProtect. Apply critical security patches now.
FortiSIEM RCE via CVE-2024-23108: Technical Mitigation Guide
Analysis of critical RCE vulnerabilities CVE-2024-23108 and CVE-2024-23109 in Fortinet FortiSIEM, including detection methods and remediation steps.
CVE-2026-20253: Unauthenticated RCE in Splunk Enterprise <10.2.4
Critical flaw CVE-2026-20253 in Splunk Enterprise allows unauthenticated RCE by creating/truncating files. Patch versions <10.2.4 and <10.0.7 immediately.
Oracle PeopleSoft CVE-2026-35273 Exploit: CISA KEV Mitigation Guide
CISA adds CVE-2026-35273 in Oracle PeopleSoft to its KEV catalog. Learn how to mitigate this missing authentication vulnerability and protect enterprise systems.
ShinyHunters Exploits Oracle ERP Zero-Day to Breach Higher Ed
ShinyHunters is exploiting an unpatched zero-day vulnerability in Oracle ERP software, targeting US higher education institutions for data theft.