Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
TA446 Deploys Leaked DarkSword iOS Exploit Kit — Technical Analysis
Russian threat actor TA446 (Callisto) is targeting iOS users with the leaked DarkSword exploit kit. Learn how to detect and defend against this campaign.
OpenAI Model Behavior Bug Bounty: Reporting AI Safety Risks
OpenAI launches a bug bounty program targeting model abuse and safety risks. Learn how to report jailbreaks and bypasses to improve enterprise AI security.
CVE-2024-5035: TP-Link Archer C5400X RCE Vulnerability Patch
TP-Link fixes high-severity flaws including CVE-2024-5035 and CVE-2024-3922, preventing remote code execution and authentication bypass on gaming routers.
CVE-2026-33634: Aqua Trivy Embedded Malicious Code — Patch Now
CISA adds CVE-2026-33634, an Aqua Security Trivy Embedded Malicious Code Vulnerability, to KEV catalog due to active exploitation.
Langflow AI Platform: Critical Code Injection Under Active Attack
Threat actors are actively exploiting a critical code injection vulnerability in the Langflow AI platform, demanding immediate patching to prevent compromise.
Langflow CVE-2026-33017: AI Workflow Hijacking Under Active Exploitation
CISA warns of active exploitation of CVE-2026-33017 in Langflow, enabling attackers to hijack AI workflows and potentially compromise AI agents.
CVE-2026-4681: Critical RCE in PTC Windchill & FlexPLM
Critical RCE vulnerability CVE-2026-4681 affects PTC Windchill and FlexPLM via deserialization. Patch now to prevent code injection in critical manufacturing.
CVE-2026-3587: WAGO Switches CLI Escape Leads to Full Device Compromise
Critical flaw CVE-2026-3587 in WAGO Industrial Managed Switches allows unauthenticated remote attackers to fully compromise devices via CLI escape.
CVE-2023-50387: Critical BIND DNSSEC Vulnerabilities — Patch Now
ISC releases critical BIND security updates for CVE-2023-50387 and CVE-2023-50868, addressing high-severity resource exhaustion and KeyTrap DNSSEC vulnerabilities.
Claude Chrome Extension Zero-Click Prompt Injection Vulnerability
A critical flaw in Anthropic's Claude Chrome extension allowed websites to silently inject malicious prompts using zero-click XSS techniques.
Coruna iOS Kit Reuses Operation Triangulation Kernel Exploit Code
Kaspersky researchers reveal that the Coruna iOS exploit kit reuses sophisticated kernel exploit code from the 2023 Operation Triangulation campaign.
CVE-2024-38077: RCE in Windows Remote Desktop Licensing — Patch Now
Technical analysis of CVE-2024-38077, a critical heap overflow vulnerability in Windows Remote Desktop Licensing Service allowing unauthenticated RCE.
Apple Addresses 85 Vulnerabilities in Recent OS Updates
Apple released significant security updates patching 85 vulnerabilities across macOS, iOS, iPadOS, tvOS, watchOS, and visionOS, with no active exploitation reported.
CVE-2024-34102: PolyShell Exploits Target 56% of Magento Stores
Attackers are aggressively exploiting the CosmicSting vulnerability (CVE-2024-34102) in Magento and Adobe Commerce stores using PolyShell polyglot web shells.
GitHub Copilot Autofix: AI-Driven Vulnerability Remediation in GHAS
GitHub integrates AI-powered scanning into Advanced Security to detect and remediate vulnerabilities across more languages using Copilot Autofix.
CVE-2026-33017: Langflow Code Injection - Patch Immediately
CISA adds actively exploited Langflow Code Injection Vulnerability (CVE-2026-33017) to KEV catalog. Critical patch urged for all organizations.
Onit Security Raises $11M for Continuous Exposure Management
Israeli startup Onit Security secures $11 million in seed funding to scale its platform for identifying and prioritizing exploitable enterprise exposures.
Citrix NetScaler Info Disclosure: CVE-2024-8069 Patch Guide
Citrix urges immediate patching of two NetScaler ADC and Gateway vulnerabilities, including a flaw similar to the high-impact CitrixBleed exploit.
Archer NX200 and NX510v Auth Bypass: CVE-2024-5035 Patch Guidance
TP-Link patches critical auth bypass CVE-2024-5035 and command injection in Archer NX routers, preventing unauthorized firmware uploads and remote code execution.
PTC Windchill RCE via CVE-2024-38472 — Mitigation and Patch Guide
PTC warns of imminent RCE threats against Windchill and FlexPLM systems. Learn how to secure your PLM environment and apply critical security updates now.
Schneider Electric Plant iT/Brewmaxx RCE via Multiple Redis Vulnerabilities
Multiple critical and high-severity vulnerabilities in Schneider Electric Plant iT/Brewmaxx 9.60+ (Redis component) enable RCE and privilege escalation, affecting…
CVE-2026-2417: Pharos Controls RCE via Missing Authentication
Critical vulnerability (CVE-2026-2417) in Pharos Controls Mosaic Show Controller firmware 2.15.3 allows unauthenticated root RCE. Upgrade to 2.16+ immediately.
Microsoft Outlook Fixes Gmail IMAP Sync Bug in Version 2404
Microsoft resolves a persistent bug in Classic Outlook causing IMAP synchronization failures and connection errors for Gmail and Yahoo mail users.
CVE-2023-4966: Critical Citrix NetScaler Memory Leak Patching Guide
Critical unauthenticated memory leak in Citrix NetScaler ADC and Gateway allows session hijacking. Learn to mitigate CVE-2023-4966 and secure your network.