Coverage
Vulnerabilities
903 articles on vulnerability disclosures and exploits
Advertisement
Autonomous Offensive Security Platforms: XBOW Secures $35M for AI
XBOW secures $35 million in Series C funding to accelerate the development of autonomous offensive security agents and automated vulnerability discovery tools.
NVIDIA Ampere GPU Rowhammer Attacks Enable Full Host Compromise
Researchers demonstrate Rowhammer attacks on NVIDIA Ampere GPUs using GDDR bitflips to gain full CPU memory control when IOMMU is disabled by default.

Evolution of Modern Threats: From Stuxnet to AI-Driven Vulnerabilities
An analysis of the 20-year evolution of the cybersecurity landscape, detailing the shift from industrial sabotage to automated, AI-driven exploitation.
PAN-OS RCE via CVE-2024-0012: Palo Alto Networks Exploitation Guide
Palo Alto Networks warns of active exploitation of CVE-2024-0012 and CVE-2024-0013 affecting PAN-OS management interfaces. Secure your firewall now.
CVE-2026-0300: Critical Zero-Day in PAN-OS Captive Portal Service
Palo Alto Networks warns of CVE-2026-0300, a critical zero-day vulnerability in the PAN-OS Captive Portal service currently being exploited in the wild.
ABB B&R Automation Runtime DoS via CVE-2025-11044 — Patch Now
An unauthenticated network DoS vulnerability (CVE-2025-11044) affects ABB B&R Automation Runtime, allowing permanent system halts. Immediate patching is critical.
CVE-2025-11043: ABB Automation Studio <6.5 Improper Certificate Validation
Critical manufacturing systems running ABB B&R Automation Studio <6.5 are vulnerable to CVE-2025-11043, allowing data interception and spoofing via improper certificate

Microsoft Edge Password Storage: Risk of Credential Dumping
Microsoft Edge stores sensitive user passwords in process memory. A PoC exploit demonstrates how attackers with admin privileges can dump credentials, posing significant

Apache HTTP Server CVE-2026-23918: Critical HTTP/2 RCE Mitigation
Apache Software Foundation addresses CVE-2026-23918, a critical double-free flaw in HTTP/2 handling. Learn how to patch and defend against potential RCE.
The EOL Blind Spot: Addressing CVE Gaps in Legacy Software
Learn why end-of-life software creates critical security blind spots in CVE feeds and how to improve your SCA tool detection for legacy dependencies.
Microsoft Edge Cleartext Password Exposure Risks — Mitigation Guide
Critical analysis of Microsoft Edge credential storage risks. Learn how to prevent cleartext password extraction and secure browser-based identities.
CVE-2024-51988: Critical RCE in Apache MINA and HTTP Server Patches
Apache patches critical RCE in MINA SSHD (CVE-2024-51988) and high-severity SSRF in HTTP Server. Detailed technical analysis and mitigation steps included.