Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
Reducing MTTR with Autonomous Validation: The 73-Second Breach Gap
Attackers can breach systems in 73 seconds while patching takes over 24 hours. Learn how autonomous validation closes the gap for modern security teams.
Closing the Remediation Gap: Why Security Fixes Often Fail
Analysis of Mandiant and Verizon reports reveals a critical failure in verifying vulnerability remediation, highlighting the need for validation testing.
Intel and AMD Patch 70 Vulnerabilities in Feb 2024 Update
Intel and AMD released security patches for 70 vulnerabilities, including a critical flaw in Intel OneMono and privilege escalation risks in AMD SEV-SNP.
May 2026 Patch Tuesday: AI-Driven Bug Discovery Scales Patch Volumes
Software vendors report record security fixes for May 2026 as AI tools accelerate vulnerability discovery. Analyze the impact on enterprise patch management.
Microsoft Patch Tuesday: 9 Critical Flaws Among 137 Total Fixes
Microsoft's latest Patch Tuesday addresses 137 vulnerabilities, including 9 critical flaws. While no zero-days were reported, timely patching is essential.
Microsoft May 2026 Patch Tuesday: 274 Vulnerabilities Addressed
Microsoft's May 2026 Patch Tuesday addresses 137 vulnerabilities in Windows and 137 Chromium-related issues affecting Microsoft Edge.
Subnet Solutions PowerSYSTEM Center Vulnerabilities - Patch Now
CISA warns of high-severity vulnerabilities in Subnet Solutions PowerSYSTEM Center that allow sensitive data exposure and CRLF injection. Patch immediately.
CVE-2025-15467: ABB AC500 V3 Stack Buffer Overflow to RCE
Critical vulnerability [CVE-2025-15467](https://nvd.nist.gov/vuln/detail/CVE-2025-15467) in ABB AC500 V3 PM5xxx firmware could lead to unauthenticated remote code…
Microsoft's 137 Patches: Critical Flaws in Azure, Windows, Dynamics
Microsoft's latest security updates address 137 vulnerabilities, including critical flaws in Azure, Windows, and Dynamics 365, requiring immediate patching.
CVE-2026-45185: Exim BDAT Use-After-Free Vulnerability Mitigation
A critical use-after-free vulnerability in Exim Mail Transfer Agent builds using GnuTLS allows for memory corruption and remote code execution via BDAT commands.
CVE-2026-31431: Analyzing the Copy.Fail Linux Kernel LPE
Technical analysis of CVE-2026-31431 (Copy.Fail), a critical Linux kernel vulnerability enabling local privilege escalation via page cache corruption.
Apple macOS Sonoma 14.5 and iOS 17.5 Patch Technical Analysis
Apple addresses critical security flaws in macOS and iOS, including kernel-level RCE and a privacy bug causing deleted media to reappear on devices.
SAP Commerce Cloud and S/4HANA Critical Vulnerabilities - Patch Now
SAP May 2024 updates address critical vulnerabilities in Commerce Cloud and S/4HANA. Learn how to mitigate RCE and SSRF risks to protect enterprise ERP systems.
Apple May 2024 Security Updates Address 84 Vulnerabilities
Apple's May 2024 security updates patch 84 vulnerabilities across iOS, macOS, watchOS, tvOS, and visionOS. Immediate patching is crucial for all users.
cPanel CVE-2026-41940 Exploited for Authentication Bypass, Backdoor
A critical authentication bypass vulnerability, CVE-2026-41940, in cPanel and WHM is under active exploitation to deploy the Filemanager backdoor.
CVE-2024-1086: Dirty Frag Local Privilege Escalation in Linux Kernels
Analysis of CVE-2024-1086 (Dirty Frag), a netfilter vulnerability enabling local privilege escalation to root across major enterprise Linux distributions.
Canvas LMS Vulnerability Leads to Portal Defacement — Patch Guidance
Instructure confirms a Canvas LMS vulnerability allowed attackers to deface login portals with extortion messages. Learn how to secure your LMS environment.
AI-Developed Zero-Day 2FA Bypass: Analyzing Google's Disclosure
Google identifies the first in-the-wild zero-day exploit for 2FA bypass developed using AI, signaling a shift in cybercriminal vulnerability discovery.
AI-Augmented Zero-Day Exploitation and Autonomous Malware Orchestration
GTIG report reveals how threat actors leverage generative AI for zero-day discovery, autonomous Android malware orchestration, and AI supply chain attacks.
AI-Driven Exploit Development: How Adversaries Automate Attacks
Cyber adversaries are leveraging Large Language Models to accelerate exploit development and automate complex attack chains, posing new risks to cloud security.
Skoda Online Shop Data Breach: Portal Vulnerability Analysis
Skoda Auto confirms a data breach affecting online shop customers. Attackers exploited a portal vulnerability to access PII including names and addresses.
Google’s Big Sleep AI Agent Discovers Real-World SQLite Zero-Day
Google Project Zero and DeepMind’s Big Sleep agent identifies an exploitable stack-based buffer underflow in SQLite, marking a shift in AI vulnerability discovery.
CVE-2024-45785: AI-Generated Zero-Day Exploit Targets BigTree CMS
Google's Threat Intelligence Group discovered a zero-day in BigTree CMS exploited via AI-generated code. Update to version 4.4.16 to prevent remote execution.
CVE-2026-43284: 'Dirty Frag' Linux Vulnerability Exploited — Patch Now
Analysis of the 'Dirty Frag' (Copy Fail 2) Linux kernel vulnerabilities CVE-2026-43284 and CVE-2026-43500, which enable potential remote code execution.