Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
Mythos Threat Actor Analysis: Novel SAST Chain Exploitation Revealed
Technical analysis of the Mythos threat actor methodology, involving complex chaining of common software vulnerabilities to achieve deep system compromise.
CVE-2024-28995: SolarWinds Serv-U Path Traversal Exploited — Patch Now
SolarWinds patches CVE-2024-28995, a high-severity path traversal flaw in Serv-U exploited in the wild. Learn how to detect and mitigate this file disclosure risk.
Emphere Raises $2.1M to Advance AI-Powered Vulnerability Remediation
Emphere secures $2.1M in seed funding to scale its AI-driven platform, focusing on automating the remediation of security vulnerabilities in software code.
CVE-2024-3300: Critical Everest Forms Pro Bypass Leads to Site Takeover
Hackers are actively exploiting an authentication bypass in the Everest Forms Pro WordPress plugin (CVE-2024-3300). Update immediately to prevent takeover.
SolarWinds Serv-U DoS Vulnerability CVE-2026-28318 Added to CISA KEV
CISA adds CVE-2026-28318 to its KEV catalog following active exploitation of a high-severity DoS vulnerability in SolarWinds Serv-U file server software.
Bright Data SDK: Smart TVs Used as AI Web-Scraping Proxies
Smart TVs and iOS apps are being converted into web-scraping exit nodes via embedded SDKs, fueling residential proxy networks used by AI companies.
CVE-2026-28318: SolarWinds Serv-U Uncontrolled Resource Consumption Exploit
CISA warns of active exploitation of CVE-2026-28318, an uncontrolled resource consumption flaw in SolarWinds Serv-U. Immediate patching is critical for all organizations.
CVE-2024-28995: SolarWinds Serv-U Exploit Leads to Server Crashes
CISA warns of active exploitation of SolarWinds Serv-U CVE-2024-28995. Attackers are leveraging this directory traversal flaw to crash vulnerable servers.
OWASP CVE Lite CLI: Strengthening Supply Chain Security for Developers
OWASP's CVE Lite CLI provides a fast, local method for developers to identify vulnerable dependencies and mitigate supply chain risks early in development.
Cisco Catalyst SD-WAN Manager RCE via CVE-2024-20468 — Patch Now
Cisco warns of a high-severity zero-day vulnerability in Catalyst SD-WAN Manager, tracked as CVE-2024-20468, currently exploited for root privilege escalation.
CVE-2026-3300: Critical RCE in Everest Forms Pro — Patch Now
Attackers are exploiting CVE-2026-3300 in Everest Forms Pro up to 1.9.12 to achieve RCE. Learn how to protect your WordPress site from full compromise.
Critical Fortinet, Apache, Cisco IOS XE Vulnerabilities: Patch & Monitor
Alert: New critical vulnerabilities impact FortiClient, FortiNAC, and Apache products. Cisco IOS XE continues to face active exploitation. Urgent patching is required.
DentaQuest Data Breach: 2.6 Million Accounts Exposed via MOVEit
DentaQuest confirms a massive data breach impacting 2.6 million users following the exploitation of a critical MOVEit Transfer vulnerability.
Hitachi Energy MACH HiDraw RCE via CVE-2026-7310 — Patch Guide
Hitachi Energy addresses a heap-based buffer overflow in MACH HiDraw version 9.22. Learn how to mitigate CVE-2026-7310 and protect critical ICS assets.
CVE-2026-21404: NAVTOR NavBox SOAP Credential Bypass and Mitigation
NAVTOR NavBox version 4.16.1.20 is vulnerable to hard-coded credentials in its SOAP implementation, allowing local attackers to manipulate application files.
Cisco Unified CM RCE via CVE-2026-20230 — Mitigation Guide
Cisco patches CVE-2026-20230, a high-severity SSRF in Unified Communications Manager. Learn how public PoC code impacts your security and find remediation steps.
Mirasvit Full Page Cache Warmer RCE via CVE-2024-34961 - Patch Now
Attackers are exploiting a critical RCE vulnerability in Mirasvit's Full Page Cache Warmer for Magento. Learn how to detect and mitigate CVE-2024-34961.
Google Gemini Hijack: Command Injection via Messaging Notifications
Researchers demonstrate how Google Gemini voice assistant can be hijacked via malicious messaging notifications to control smart homes and start video calls.
CVE-2024-20469: Critical Cisco Unified CM Root Escalation Risk
Cisco patches a critical SQL injection flaw (CVE-2024-20469) in Unified Communications Manager that allows remote attackers to gain full root-level access.
VS Code One-Click GitHub Token Theft via URI Handler Exploitation
A flaw in Visual Studio Code allows attackers to steal GitHub authentication tokens with a single click. Learn the technical details and mitigation steps.
Cisco Unified CM SSRF CVE-2024-20455 — Public PoC Mitigation Guide
Cisco warns of critical SSRF vulnerabilities in Unified CM with public PoC exploit code. Learn how to detect and patch CVE-2024-20455 to protect your network.
CVE-2026-45247: Magento Mirasvit Cache Warmer RCE Exploit Analysis
CISA adds CVE-2026-45247, a critical Mirasvit Cache Warmer RCE flaw impacting Magento sites, to the KEV catalog following reports of active exploitation.
Atlas RAT Deployment: Chinese Actors Target European Defense
Chinese-speaking threat actors are deploying the new Atlas RAT and exploiting CVE-2023-43208 to target European government and defense organizations.
Google Gemini Hijacked on Android via Poisoned Notifications
Researchers demonstrate how WhatsApp and Slack notifications can trigger indirect prompt injection in Google Gemini, leading to memory poisoning.