Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
Hitachi Energy RTU500 CMU Firmware Vulnerabilities: Patch Guidance
Hitachi Energy issues critical patches for RTU500 series CMU firmware addressing high-severity DoS and information disclosure risks (CVE-2026-1773, CVE-2024-8176).
CVE-2023-20887: VMware Aria Operations for Networks RCE Exploit Guide
CISA adds CVE-2023-20887 to its KEV catalog. Learn how to detect and patch this critical RCE flaw in VMware Aria Operations for Networks.
Mobiliti e-mobi.hu EV Chargers: Critical Auth Bypass & DoS Vulnerabilities
Critical vulnerabilities in Mobiliti e-mobi.hu EV charging stations (all versions) allow unauthenticated attackers to gain administrative control or disrupt services.
Google Chrome Two-Week Release Cycle: Reducing the Patch Gap
Google transitions Chrome to a two-week stable release cycle to accelerate security patching and minimize the window for n-day vulnerability exploitation.
CrushFTP Bruteforce Scans: Protecting Against RCE & Auth Bypass
Ongoing bruteforce scans are targeting CrushFTP servers, likely attempting to exploit past critical vulnerabilities like CVE-2024-4040 (RCE) and CVE-2025-31161 (auth…
Coruna Exploit Kit: iOS 13-17.2.1 Targeted by Multiple APTs
Google Threat Intelligence Group details Coruna, a powerful iOS exploit kit targeting versions 13.0 to 17.2.1, used by commercial vendors and nation-state actors for…
Honeywell IQ4 Vulnerability: Assessing Internet Exposure & Impact
A researcher claims thousands of internet-exposed Honeywell IQ4 building controllers are vulnerable. Understand the potential impact and mitigation strategies.
Critical OpenClaw Flaw in AI Agents: Risks and Remediation Guide
A critical OpenClaw vulnerability in widely adopted AI agents could lead to severe security risks. Understand the impact and crucial remediation steps.
CyberStrikeAI Exploitation: AI Tools Targeting Fortinet Firewalls
Threat actors are repurposing CyberStrikeAI to automate reconnaissance and exploit critical vulnerabilities in Fortinet FortiGate firewalls and edge devices.
CVE-2026-0628: Chrome Gemini Panel Exploit Enables Privilege Escalation
A high-severity flaw in Google Chrome's Gemini side panel allowed malicious extensions to bypass security policies and access local files on target systems.
Google Gemini Side Panel Bug Enables Session Hijacking — Update Now
Researchers discovered a security flaw in the Google Gemini side panel that allows for unauthorized session hijacking and cross-origin data exfiltration.
OpenClaw Hijacking Vulnerability: How Malicious Sites Control AI Agents
A critical vulnerability in the OpenClaw AI gateway allows malicious websites to hijack local AI agents via WebSocket connections and password brute-forcing.
Chrome Gemini Live Hijacking: Malicious Extension Vulnerability
A vulnerability in Google Chrome’s Gemini Live AI assistant allowed malicious extensions to hijack sessions and steal user files. Learn more about the impact.
SD-WAN Zero-Day and Smart TV Proxy SDK Vulnerabilities Recap
Technical analysis of recent SD-WAN zero-day exploits and Smart TV proxy SDK risks, detailing how network infrastructure is increasingly targeted.
Wireshark 4.6.4 Patch Fixes Dissector Vulnerabilities — Update Guide
Wireshark 4.6.4 addresses multiple dissector vulnerabilities, including CVE-2025-1811 and CVE-2025-1812, which could lead to application crashes.
APT28 Exploits CVE-2026-21513: MSHTML 0-Day Intelligence
Akamai reports Russia-linked APT28 exploited CVE-2026-21513 in the MSHTML Framework as a zero-day before Microsoft's February 2026 security patch updates.
CVE-2025-24036: Critical RCE in Ivanti Connect Secure — Patch Now
Exploit analysis of CVE-2025-24036 in Ivanti Connect Secure and Policy Secure. Learn to detect unauthenticated RCE attempts and apply mitigation strategies.
ClawJacked Vulnerability in OpenClaw AI Agent Enables Data Hijacking
Analysis of the ClawJacked attack where malicious websites can hijack local OpenClaw instances to steal sensitive LLM API keys and private conversation data.
ClawJacked: Hijacking Local OpenClaw AI Agents via WebSocket
A high-severity vulnerability in the OpenClaw AI gateway allows malicious websites to take control of local AI agents by exploiting WebSocket flaws.
900+ Sangoma FreePBX Servers Compromised via Web Shell Exploitation
Over 900 Sangoma FreePBX instances are currently infected with web shells following a command injection campaign first observed in late 2025.
Addressing Enterprise Risk in Third-Party Software Patching
Analyze the security risks of third-party software drift and learn why automated patch management is essential for reducing the modern attack surface.
CISA Warns of RESURGE Malware Persistence on Ivanti Devices
CISA details RESURGE, a sophisticated implant exploiting CVE-2025-0282 in Ivanti Connect Secure, capable of remaining dormant to bypass detection and recovery.
Juniper PTX Routers Face Critical RCE via Junos OS Evolved Flaw
Juniper Networks patches a critical 9.8 CVSS RCE vulnerability (CVE-2024-21602) in PTX Series routers. Learn the technical details and mitigation steps.
Critical Vulnerabilities in Gardyn Smart Gardens Enable Remote Takeover
CISA warns of critical flaws in Gardyn Smart Gardens, including CVE-2024-39682 and CVE-2024-39683, allowing remote code execution and unauthorized access.