Coverage
Vulnerabilities
903 articles on vulnerability disclosures and exploits
Advertisement
CVE-2026-31431: Analyzing the Copy.Fail Linux Kernel LPE
Technical analysis of CVE-2026-31431 (Copy.Fail), a critical Linux kernel vulnerability enabling local privilege escalation via page cache corruption.
SAP S/4HANA and Commerce Cloud Critical Vulnerabilities — Patch Now
SAP addresses critical vulnerabilities in S/4HANA and Commerce Cloud, including a 9.8 CVSS authentication bypass and SSRF risks. Implement patches immediately.
Apple macOS Sonoma 14.5 and iOS 17.5 Patch Technical Analysis
Apple addresses critical security flaws in macOS and iOS, including kernel-level RCE and a privacy bug causing deleted media to reappear on devices.
SAP Commerce Cloud and S/4HANA Critical Vulnerabilities - Patch Now
SAP May 2024 updates address critical vulnerabilities in Commerce Cloud and S/4HANA. Learn how to mitigate RCE and SSRF risks to protect enterprise ERP systems.
Apple May 2024 Security Updates Address 84 Vulnerabilities
Apple's May 2024 security updates patch 84 vulnerabilities across iOS, macOS, watchOS, tvOS, and visionOS. Immediate patching is crucial for all users.

cPanel CVE-2026-41940 Exploited for Authentication Bypass, Backdoor
A critical authentication bypass vulnerability, CVE-2026-41940, in cPanel and WHM is under active exploitation to deploy the Filemanager backdoor.

CVE-2024-1086: Dirty Frag Local Privilege Escalation in Linux Kernels
Analysis of CVE-2024-1086 (Dirty Frag), a netfilter vulnerability enabling local privilege escalation to root across major enterprise Linux distributions.
Canvas LMS Vulnerability Leads to Portal Defacement — Patch Guidance
Instructure confirms a Canvas LMS vulnerability allowed attackers to deface login portals with extortion messages. Learn how to secure your LMS environment.

AI-Developed Zero-Day 2FA Bypass: Analyzing Google's Disclosure
Google identifies the first in-the-wild zero-day exploit for 2FA bypass developed using AI, signaling a shift in cybercriminal vulnerability discovery.
AI-Augmented Zero-Day Exploitation and Autonomous Malware Orchestration
GTIG report reveals how threat actors leverage generative AI for zero-day discovery, autonomous Android malware orchestration, and AI supply chain attacks.

AI-Driven Exploit Development: How Adversaries Automate Attacks
Cyber adversaries are leveraging Large Language Models to accelerate exploit development and automate complex attack chains, posing new risks to cloud security.
Skoda Online Shop Data Breach: Portal Vulnerability Analysis
Skoda Auto confirms a data breach affecting online shop customers. Attackers exploited a portal vulnerability to access PII including names and addresses.