Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
DirtyDecrypt: How Attackers Exploit Linux Kernel rxgk for Root Access
Learn about DirtyDecrypt, a local privilege escalation vulnerability in the Linux rxgk module. Discover how to detect and mitigate this root access threat.
Windows 11 KB5089549 Security Update Installation Failure Analysis
Microsoft confirms Windows 11 KB5089549 security update fails with error 0x800f0922. Learn how to troubleshoot and resolve these installation issues.
MiniPlasma 0-Day: Windows SYSTEM Privilege Escalation via cldflt.sys
Technical analysis of the MiniPlasma zero-day vulnerability in cldflt.sys enabling SYSTEM privilege escalation on fully patched Windows systems.
Pwn2Own Berlin 2026: Critical RCE and Escalation Targets Identified
Security researchers demonstrate critical zero-day exploits against Windows, VMware, and AI systems at Pwn2Own Berlin 2026, earning over $1.3 million.
Windows MiniPlasma Zero-Day Exploit: How to Mitigate LPE Threats
A new zero-day exploit dubbed MiniPlasma allows local attackers to gain SYSTEM privileges on fully patched Windows systems. Learn detection and mitigation steps.
NGINX CVE-2026-42945: Heap Buffer Overflow Exploited — Patch Now
Active exploitation of CVE-2026-42945 in NGINX ngx_http_rewrite_module allows for worker process crashes and remote code execution. Update to version 1.31.0.
Funnel Builder Plugin Exploited for WooCommerce Checkout Skimming
Attackers are exploiting a vulnerability in the Funnel Builder WordPress plugin to inject skimming scripts and steal payment data from WooCommerce sites.
NGINX HTTP/3 RCE via CVE-2024-24989 — Mitigation Guide
Proof of Concept code released for critical NGINX CVE-2024-24989 and CVE-2024-24990. Learn how to detect and patch these HTTP/3 vulnerabilities immediately.
AI-Generated Code and Autonomous Agents: New Risks for Defenders
AI agents are automating vulnerability discovery in AI-generated codebases, forcing a shift in defensive security strategies and response times.
CVE-2026-42897: Microsoft Exchange XSS Under Active Exploitation
CISA adds CVE-2026-42897, a Microsoft Exchange Server Cross-Site Scripting vulnerability, to KEV Catalog due to active exploitation. Immediate patching advised.
Pwn2Own Berlin: Microsoft Exchange, Windows 11 Zero-Day Exploits
Zero-day vulnerabilities in Microsoft Exchange, Windows 11, and Red Hat Enterprise Linux demonstrated at Pwn2Own Berlin. Runtime Rebel details the impact.
Funnel Builder WordPress Plugin Exploited for Credit Card Skimming
Critical vulnerability in Funnel Builder WordPress plugin actively exploited to inject credit card skimming JavaScript into WooCommerce checkout pages.
April 2026 CVE Landscape: Prioritizing 37 High-Impact Vulnerabilities
Runtime Rebel analyzes Recorded Future's April 2026 CVE landscape, highlighting 37 high-impact vulnerabilities for urgent remediation amidst rising risks.
CVE-2024-2123 & CVE-2024-2510: Avada Builder Patch Guidance
Critical flaws in Avada Builder WordPress plugin (CVE-2024-2123, CVE-2024-2510) allow for credential theft and LFI. Immediate update to version 3.11.7 required.
OpenClaw "Claw Chain" Flaws: Data Theft and Persistence Risks
Researchers at Cyera have identified the Claw Chain, a set of four OpenClaw vulnerabilities enabling data theft, privilege escalation, and persistent access.
Bypassing AI-Based Age Verification via Facial Obfuscations
Research reveals that AI-driven age estimation systems can be bypassed using physical facial alterations, highlighting flaws in biometric verification models.
20 Years of Cybersecurity: Strategic Insights from Industry Pioneers
Leading cybersecurity experts reflect on two decades of evolving threats, bug bounties, and the critical transition toward identity-centric security models.
CVE-2026-42897: Microsoft Exchange Server Zero-Day Exploited in Wild
Microsoft warns of CVE-2026-42897, a critical Exchange Server zero-day exploited in the wild. Implement Extended Protection mitigations immediately to secure systems.
CVE-2024-49040: Microsoft Exchange Server Spoofing Vulnerability
Microsoft warns of CVE-2024-49040, a zero-day spoofing vulnerability in Exchange Server exploited to bypass security filters and impersonate trusted senders.
PAN-OS RCE via CVE-2024-3400 — Critical Vulnerability Mitigation Guide
Exploit analysis and mitigation for CVE-2024-3400, a critical command injection flaw in Palo Alto Networks PAN-OS GlobalProtect allowing unauthenticated RCE.
Cisco SD-WAN RCE via CVE-2026-20182 — Mitigation Guide
Cisco patches CVE-2026-20182, the sixth SD-WAN zero-day exploited in 2026. Learn how threat actor UAT-8616 leverages this flaw for targeted attacks.
Chrome 148 Update: Patching Critical Use-After-Free Vulnerabilities
Google releases Chrome 148 addressing critical-severity use-after-free vulnerabilities.
Cisco Catalyst SD-WAN Authentication Bypass: CVE-2026-20182 Exploit
CISA adds CVE-2026-20182 to its KEV catalog after reports of active exploitation against Cisco Catalyst SD-WAN Controllers. Critical patch required.
CVE-2026-42897: How Attackers Exploit Microsoft Exchange Server
Microsoft warns of active exploitation of CVE-2026-42897, a critical spoofing and XSS vulnerability in on-premise Exchange Server triggered via email.