Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
CVE-2026-2273: Schneider Electric EcoStruxure Automation Expert RCE
Schneider Electric has addressed a high-severity code injection vulnerability (CVE-2026-2273) in EcoStruxure Automation Expert that risks full system compromise.
APT28 Targets Ukraine via CVE-2024-45519 Zimbra Exploit
Russian APT28 hackers exploit CVE-2024-45519 in Zimbra Collaboration Suite to target Ukrainian government entities via malicious email-based command injection.
DJI Romo Remote Camera Access via MQTT Vulnerability
An MQTT misconfiguration in DJI Romo vacuums allows unauthorized remote control and camera access for 7,000 devices. Learn the risks and mitigation steps.
CVE-2024-38094: SharePoint RCE Exploited in the Wild — Patch Now
CISA adds CVE-2024-38094 to its KEV catalog after active exploitation of a SharePoint RCE vulnerability. Learn how to detect and remediate this threat.
DarkSword iOS Exploit Kit: Full Takeover via 6 Flaws and 3 Zero-Days
Analysis of DarkSword, a sophisticated iOS exploit kit using six vulnerabilities, including three zero-days, for state-sponsored surveillance and data theft.
CISA KEV Update: CVE-2025-66376 Zimbra and SharePoint Exploits
CISA warns of active exploitation for Zimbra CVE-2025-66376, SharePoint flaws, and Cisco zero-days used in ransomware attacks. Secure your systems now.
Ivanti Connect Secure RCE via CVE-2025-0551 — Mitigation Guide
Unauthenticated RCE vulnerabilities CVE-2025-0551 and CVE-2025-0552 impact Ivanti Connect Secure gateways. Learn how to detect and patch these critical flaws.
DarkSword iPhone Exploit Kit: Zero-Day Attacks on iOS Users
DarkSword, an advanced iPhone exploit kit, leverages multiple zero-day vulnerabilities to target users in Saudi Arabia, Turkey, Malaysia, and Ukraine for espionage and…
CVE-2025-66376: ZCS Cross-Site Scripting Actively Exploited
CISA adds CVE-2025-66376, a Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting vulnerability, to its KEV Catalog due to active exploitation.
CVE-2026-20963: Microsoft SharePoint Deserialization Exploit — Patch Now
CISA adds CVE-2026-20963, a Microsoft SharePoint deserialization vulnerability, to its KEV catalog due to active exploitation.
XBOW: AI-Powered Offensive Security Reshapes Vulnerability Discovery
XBOW, an autonomous offensive security firm, secured $120M, reaching a $1B+ valuation. Explore its AI-powered platform for vulnerability discovery and validation.
Machine-Speed Attacks: The Failure of Predictive Security Models
Analysis of why predictive security models fail against machine-speed attacks and the technical shift toward preemptive security strategies for defenders.
ConnectWise ScreenConnect Flaw Allows Unauthorized Access
ConnectWise ScreenConnect users must patch a critical cryptographic signature verification flaw enabling unauthorized access and privilege escalation.
CVE-2024-4510: Zimbra Collaboration Suite XSS Exploitation Guide
CISA adds CVE-2024-4510 to the KEV catalog following active exploitation of a Zimbra Collaboration Suite XSS vulnerability. Patch ZCS version 9.0.0 today.
DarkSword iOS Exploit Chain: Analyzing Multi-Actor Zero-Day Campaigns
Analysis of the DarkSword iOS exploit chain, used by multiple actors to deploy GHOSTBLADE and GHOSTKNIFE malware via zero-day vulnerabilities in iOS 18.7.
SideWinder APT Expands Southeast Asia Espionage Campaign
SideWinder APT targets government and telecom sectors in Southeast Asia using spear-phishing and rotating infrastructure for persistent espionage operations.
DarkSword iOS Exploit Kit: Analysis of State-Sponsored Spyware Chains
Analysis of the DarkSword exploit kit targeting six iOS vulnerabilities for state-sponsored surveillance and full device compromise via WebKit exploits.
CVE-2026-20131: Interlock Ransomware Exploits Cisco FMC — Patch Now
Interlock ransomware actors are exploiting CVE-2026-20131, a critical 10.0 CVSS zero-day in Cisco FMC, to gain unauthenticated root access and deploy malware.
Ivanti vTM Authentication Bypass: CVE-2024-7593 Mitigation Guide
Ivanti patches a critical authentication bypass in Virtual Traffic Manager. Learn how CVE-2024-7593 allows unauthenticated administrative access.
WhatsApp View Once Bypass via Modified Clients - Meta Won't Patch
A new WhatsApp View Once bypass allows recipients to persist media via modified clients. Meta declines patching, citing client-side enforcement limits.
Ubuntu CVE-2026-3888: Privilege Escalation via systemd Timing Flaw
A high-severity flaw in Ubuntu 24.04+ allows local attackers to gain root access via a systemd cleanup timing exploit tracked as CVE-2026-3888.
CVE-2026-32746: GNU InetUtils Telnetd RCE Mitigation Guide
Unauthenticated root RCE discovered in GNU InetUtils telnetd (CVE-2026-32746). Learn how to detect CVE-2026-32746 exploit attempts and secure port 23.
CVE-2026-20643: Apple Patches WebKit Same-Origin Policy Bypass
Apple addresses CVE-2026-20643, a critical WebKit Navigation API flaw allowing Same-Origin Policy bypass on iOS and macOS. Deploy updates immediately.
Apple CVE-2026-20643: WebKit Flaw Fixed via Background Update
Apple deploys the first Background Security Improvements update to address a critical WebKit vulnerability (CVE-2026-20643) across iOS and macOS platforms.