Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
CVE-2026-45247: Mirasvit Full Page Cache Warmer Exploited — Patch Now
CISA adds CVE-2026-45247, a deserialization vulnerability in Mirasvit Full Page Cache Warmer for Magento, to the KEV catalog after reports of active exploitation.
Continuous Security Testing: Closing the 345-Day Exposure Gap
Analyze why annual penetration tests leave 345 days of risk and how continuous security validation for financial institutions improves resilience.
Android and Linux Kernel Exploitation: CVE-2024-36971 and CVE-2024-21626
CISA adds Android CVE-2024-36971 and Linux CVE-2024-21626 to its KEV catalog following reports of active exploitation by sophisticated threat actors.
Google Gemini Indirect Prompt Injection via Malicious Notifications
Security researchers demonstrate how malicious notifications can manipulate Google Gemini's voice assistant to perform unauthorized tasks or exfiltrate data.
Evaluating AI Agent Security: 100 Agents Tested for Vulnerabilities
An industry-first evaluation of 100 AI agents highlights critical security gaps in defense and the high impact of potential agentic compromises.
WordPress Sites Targeted via Kirki and Burst Statistics Vulnerabilities
Attackers are exploiting unauthenticated stored XSS in Kirki and Burst Statistics plugins to achieve privilege escalation and website takeover.
Acer Wave 7 Router RCE via CVE-2024-41591 and CVE-2024-41592
Acer addresses two critical 10.0 CVSS zero-day vulnerabilities in Wave 7 mesh routers that allow unauthenticated remote code execution and full takeover.
GitHub.dev One-Click Attack: Stealing OAuth Tokens via VS Code
New research reveals a one-click exploit in GitHub.dev and VS Code that allows attackers to steal full GitHub OAuth tokens and access private repositories.
VS Code Zero-Day Exploit: Stealing GitHub Tokens via URI Handlers
Security researcher mthcht reveals a VS Code zero-day vulnerability allowing GitHub token theft via URI handlers. Learn how to defend against this exploit.
HTTP/2 Bomb: Remote DoS Affects NGINX, Apache, and Microsoft IIS
Researchers identify HTTP/2 Bomb vulnerability affecting NGINX, Apache, and IIS default settings, allowing remote denial-of-service attacks on web servers.
PHP RCE via CVE-2024-4577 — Windows Argument Injection Analysis
Technical analysis of the CVE-2024-4577 vulnerability affecting PHP on Windows. Learn how argument injection leads to RCE and how to secure PHP-CGI environments.
CISA KEV Update: Active Exploitation of CVE-2022-0492 and CVE-2025-48595
CISA adds Linux Kernel and Android Framework vulnerabilities to its Known Exploited Vulnerabilities catalog. Prioritize patching CVE-2022-0492 and CVE-2025-48595.
Gamaredon Exploits WinRAR CVE-2025-8088 to Target Ukraine
Russian threat actor Gamaredon weaponizes a WinRAR path traversal flaw to deploy GammaWorm and GammaSteel malware against Ukrainian entities.
CVE-2025-48595: Android June 2026 Update Patches Exploited Zero-Day
Google's June 2026 security update fixes 124 vulnerabilities, including CVE-2025-48595, a zero-day privilege escalation flaw under active exploitation.
AI Automation and the Shrinking Vulnerability Exploitation Window
Analyze the impact of AI-driven automation on the vulnerability lifecycle and the debate between tooling vs. operational security failures.
Windows 11 BitLocker Bypass: Nightmare Eclipse Exploit Analysis
Microsoft threatens legal action against researcher Nightmare Eclipse after the release of a Windows 11 BitLocker bypass. Learn how to detect and mitigate.
HP VoIP Phone RCE via CVE-2024-40615 — Mitigation Guide
HP Poly CCX and Edge E Series phones face a critical stack-based buffer overflow allowing unauthenticated RCE and enterprise network breaches.
AI-Driven Zero-Knowledge Threat Actors and the Erosion of Disclosure
AI enables low-skill attackers to automate malware creation and exploit development, significantly reducing the efficacy of traditional responsible disclosure.
Android June 2024 Update: CVE-2024-32896 Zero-Day Exploit Patched
Google fixes 124 vulnerabilities including an actively exploited Pixel firmware zero-day and critical RCE flaws in the June 2024 Android security update.
CVE-2022-21371: CISA Warns of Oracle WebLogic Exploitation
CISA adds CVE-2022-21371 to its KEV catalog, warning of active exploitation of an information disclosure flaw in Oracle WebLogic Server. Patch immediately.
Managing AI-Driven Vulnerability Exploitation Timelines
AI-driven exploitation tools are shrinking the window between vulnerability disclosure and weaponization to hours, forcing a shift in defensive strategies.
Oracle January 2025 CSPU: Addressing 77 Security Vulnerabilities
Oracle transitions to monthly Critical Security Patch Updates, resolving 77 flaws including critical RCE vulnerabilities in Communications and Hospitality suites.
Microsoft's Zero-Day Disclosure Stance Sparks Industry Debate
Microsoft's legal threats against a researcher for Zero-Day exploit disclosure spark industry backlash, prompting scrutiny of responsible disclosure practices.
CVE-2026-8732: WP Maps Pro Admin Creation Vulnerability Exploited
Critical vulnerability [CVE-2026-8732] in WP Maps Pro allows unauthenticated attackers to create admin accounts, leading to WordPress site takeovers. Patch immediately.