Coverage
Vulnerabilities
903 articles on vulnerability disclosures and exploits
Advertisement
Dify AI Platform Data Exposure: Multi-Tenant Risks
Dify AI platform users face critical data exposure flaws, enabling access to private chats, documents, and internal APIs in multi-tenant environments.
Proactive Exploit Validation: Mitigating Rapidly Weaponized Vulnerabilities
Security teams face rapidly weaponized vulnerabilities. Learn how to proactively validate exploitability and fortify defenses against emerging threats, even before

Dify AI Platform Vulnerabilities: How to Mitigate DifyTap Exploit
Researchers discover DifyTap vulnerabilities in the Dify AI platform, allowing attackers to exfiltrate chat histories and secrets through SSRF and RCE.
Samsung KNOX Kernel Attack Flaw: Millions of Galaxy Devices Exposed
High-severity use-after-free vulnerability in Samsung KNOX exposed millions of Galaxy devices (S9-S25) to kernel attacks for years.
CVE-2024-40766: SonicWall SonicOS Patch and Configuration Guide
Analysis of CVE-2024-40766, a critical improper access control flaw in SonicWall SonicOS exploited by ransomware groups. Learn how to secure management interfaces.

OpenAI Expands Daybreak: Using GPT-5.5-Cyber to Patch Vulnerabilities
OpenAI enhances its Daybreak initiative with GPT-5.5-Cyber, a specialized model designed for deep codebase analysis to identify and remediate security flaws.
JaredFromSubway MEV Bot Exploit: $15 Million Lost in Logic Hack
An attacker drained $15 million from the JaredFromSubway Ethereum MEV bot by manipulating its trading logic through the use of malicious bait tokens.
Gravity SMTP Flaw Exploited: WordPress Data Harvest & Remediation
Attackers are actively exploiting a flaw in the Gravity SMTP WordPress plugin to exfiltrate sensitive data, including API keys and server info. Immediate patching is
Squidbleed: Heartbleed-Style Data Exposure in Squid Proxy
A critical flaw dubbed Squidbleed in Squid Proxy, affecting versions 3.5-6.x, enables Heartbleed-style memory leakage exposing user credentials and session data. Patch
Microsoft AutoGen Studio RCE via AutoJack Flaw — Patch Now
Microsoft patched the AutoJack vulnerability chain in AutoGen Studio, enabling remote code execution through malicious AI agent manipulation.

Squidbleed: 29-Year-Old Squid Proxy Bug Leaks Cleartext HTTP Requests
A 29-year-old heap over-read vulnerability, dubbed 'Squidbleed,' in Squid web proxy's default configuration can leak cleartext HTTP requests and credentials.

DifyTap Flaws Expose AI Chats in Dify Platform Without Auth
Zafran Security details DifyTap, a set of four vulnerabilities in Dify, allowing unauthenticated access to cross-tenant AI chat data. Learn impact and mitigation.