Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
Ivanti EPMM RCE via CVE-2025-22514: Technical Analysis and Patching
Critical security alert for Ivanti EPMM: CVE-2025-22514 and CVE-2025-22515 allow remote command injection and file uploads. Patch to version 12.1.0.1 immediately.
LMDeploy SSRF: CVE-2026-33626 Exploit and Mitigation Guide
Attackers are actively exploiting CVE-2026-33626, a high-severity SSRF in LMDeploy, to access sensitive LLM data. Learn how to detect and patch this flaw.
CVE-2024-52317: Critical File Upload Bug in Breeze Cache — Patch Now
Attackers are actively exploiting a critical unauthenticated file upload vulnerability (CVE-2024-52317) in the Breeze Cache WordPress plugin.
CVE-2025-65856: Authentication Bypass in Xiongmai XM530 IP Cameras
Critical authentication bypass (CVE-2025-65856) in Xiongmai XM530 IP Camera firmware allows unauthenticated remote access to video streams and sensitive data.
CVE-2026-3893: Unauthenticated Access in Carlson VASCO-B GNSS Receiver
Critical CVE-2026-3893 in Carlson VASCO-B GNSS Receivers <1.4.0 allows unauthenticated remote alteration of critical system functions. Update to v1.4.0+.
FIRESTARTER Backdoor: Persistent Threat to Cisco Firepower & Secure Firewall
CISA and NCSC warn of FIRESTARTER, an APT-deployed backdoor maintaining persistence on Cisco Firepower and Secure Firewall devices post-patching.
Anthropic AI Agent Memory Vulnerability: Data Exposure Risks
Cisco discovered a significant memory handling vulnerability in Anthropic AI agents, risking data exposure. This highlights persistent security challenges in AI systems.
AI in Vulnerability Discovery: 360 Digital Security Group's Claims Examined
Runtime Rebel examines 360 Digital Security Group's claims of using AI to discover over 1,000 vulnerabilities, including at Tianfu Cup, and the implications for security…
Analyzing the $290M DeFi Breach and macOS LotL Exploitation
An analysis of the $290 million DeFi protocol hack, macOS living-off-the-land techniques, and ProxySmart SIM farming operations identified in recent reports.
CVE-2024-23296: Apple Patches Actively Exploited Notification Flaw
Apple releases urgent security updates for iOS and iPadOS to address CVE-2024-23296, a memory corruption vulnerability in Notification Services seeing active use.
CVE-2024-38107: Microsoft Defender BlueHammer Flaw Exploited - Patch Now
CISA orders federal agencies to patch the BlueHammer zero-day, a critical Microsoft Defender privilege escalation flaw currently under active exploitation.
Anthropic Project Glasswing: The Shift to AI-Driven Zero-Day Discovery
Anthropic delays Project Glasswing after its AI model identifies critical zero-day vulnerabilities across major tech stacks, sparking a massive patching effort.
AI Impact on Vulnerability Management: Real-World Trends and Risks
Analyze how artificial intelligence impacts vulnerability research and discovery, separating industry hype from technical reality for security professionals.
CVE-2024-21412: Microsoft Defender Zero-Day Exploitation and Analysis
Analysis of a Microsoft Defender zero-day vulnerability used to extract NTLM hashes from the SAM database and achieve system-level privileges.
CVE-2026-28950: Apple Fixes iOS Notification Data Retention Flaw
Apple patches CVE-2026-28950 in iOS and iPadOS, a logging issue that allowed deleted notifications to persist on devices, impacting forensic privacy.
Critical RCE Threats: Confluence OGNL & Exchange Server Patching
Runtime Rebel analyzes critical RCE vulnerabilities affecting Atlassian Confluence and Microsoft Exchange Server, alongside a high-severity SQLi in WP Reset.
CVE-2026-33825: Microsoft Defender Access Control Exploit Analysis
CISA adds CVE-2026-33825 to the KEV catalog following active exploitation of Microsoft Defender's access control mechanisms. Learn how to secure your systems.
iOS 17.5.1 Notification Data Retention Bug — Mitigation Guide
Apple releases iOS 17.5.1 to address a Notification Services flaw where deleted data persisted on devices due to database corruption issues.
CVE-2025-29635: Mirai Exploits EoL D-Link Routers
A new Mirai campaign actively exploits CVE-2025-29635, a command-injection RCE in EoL D-Link DIR-823X routers, to expand its IoT botnet for DDoS attacks.
Telegram tdata Credential Harvesting: Risks and Mitigation Strategies
Learn how threat actors exploit Telegram Desktop tdata folders for session hijacking and credential harvesting, bypassing multi-factor authentication.
Redis RCE via CONFIG Command Abuse: Detection and Mitigation
Learn how attackers exploit exposed Redis instances using the CONFIG command to achieve RCE and the specific steps required to secure your infrastructure.
CVE-2026-27668: Privilege Escalation in Siemens RUGGEDCOM CROSSBOW
Authenticated User Administrators can escalate privileges in Siemens RUGGEDCOM CROSSBOW SAM-P versions prior to 5.8. Update to mitigate CVE-2026-27668 risks.
Silex SD-330AC and AMC Manager RCE via CVE-2026-32956 — Patch Now
Silex Technology devices face critical RCE and DoS risks via 13 vulnerabilities. Critical infrastructure defenders must update to firmware Ver 1.50 immediately.
Oracle April 2026 CPU: 481 Patches for Unauthenticated Flaws
Oracle's April 2026 Critical Patch Update addresses 481 vulnerabilities across 28 product families, including 300+ unauthenticated remote exploits.