Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
OpenLDAP and lldpd Vulnerabilities: Analyzing DoS Risks
Detailed analysis of CVE-2025-25164 in OpenLDAP and CVE-2025-25330 in lldpd, focusing on NULL pointer dereference and memory leak impacts on infrastructure.
Cisco SD-WAN Zero-Day Under Exploitation for 3 Years
A critical zero-day vulnerability, CVE-2026-20127, in Cisco SD-WAN has been actively exploited by a sophisticated threat actor for three years.
GetProcessHandleFromHwnd API: UAC Bypass Implications
Investigate the GetProcessHandleFromHwnd API's role in a Quick Assist UAC bypass. Understand its mechanism, UIAccess implications, and defender recommendations.
Multiple DoS/RCE Vulnerabilities in Yokogawa CENTUM VP R6, R7
CISA alerts to multiple medium-severity vulnerabilities in Yokogawa CENTUM VP R6 and R7, allowing DoS and RCE via crafted packets in critical infrastructure…
Critical Authentication Flaws in Chargemap EV Infrastructure
CISA warns of critical vulnerabilities in Chargemap EV charging stations, including unauthenticated WebSocket access and session hijacking (CVE-2026-25851).
Trend Micro Patches Critical RCE Flaws in Apex One Security Platform
Trend Micro addresses two critical vulnerabilities, CVE-2023-32524 and CVE-2023-32525, in its Apex One platform that allow for remote code execution.
Anthropic Patches Claude Code Vulnerabilities Enabling Silent Hacking
Anthropic addressed flaws in Claude Code that allowed attackers to execute arbitrary commands on developer devices via malicious repository configurations.
Threat Intelligence Analysis: Kali Linux AI Integration and Browser Crash Traps
Analysis of Kali Linux Claude AI integration, Chrome browser crash traps, and the ongoing exploitation of WinRAR vulnerabilities by LockBit affiliates.
US Sanctions Russian Exploit Broker Operation Zero
US Treasury sanctions Russian exploit broker Operation Zero and its owner Sergey Zaytsev for facilitating zero-day trades with Russian intelligence agencies.
Zyxel Fixes Critical RCE Vulnerability in UPnP Implementation
Zyxel releases patches for CVE-2024-42057, a command injection flaw in the UPnP function of several VMG and fiber router models, allowing unauthenticated RCE.
Cisco SD-WAN Zero-Day CVE-2026-20127 Exploited for Admin Access
CVE-2026-20127 is a critical CVSS 10.0 flaw in Cisco SD-WAN controllers exploited since 2023, allowing unauthenticated remote administrative access.
Cisco SD-WAN Exploitation: Critical Authentication Bypass & Escalation
CISA alerts on active global exploitation of Cisco SD-WAN, leveraging CVE-2026-20127 for initial access and CVE-2022-20775 for privilege escalation.
CISA Adds Two Cisco SD-WAN Exploits to KEV Catalog
CISA adds CVE-2022-20775 (Path Traversal) and CVE-2026-20127 (Auth Bypass) affecting Cisco SD-WAN to its Known Exploited Vulnerabilities Catalog.
Critical Cisco SD-WAN Zero-Day Exploited Since 2023
Cisco Catalyst SD-WAN critical authentication bypass (CVE-2026-20127) actively exploited since 2023, enabling remote compromise and rogue peer addition.
Claude Code Flaws Enable RCE & API Key Exfiltration
Multiple security flaws in Anthropic's Claude Code AI coding assistant allow remote code execution and API credential theft via configuration mechanisms.
Ex-L3Harris Executive Sentenced for Selling Zero-Days to Russia
Former Trenchant CEO James Michael Robinson sentenced to 90 months for stealing zero-day exploits and selling them to a Russian state-linked broker.
US Treasury Sanctions Russian Broker for Stolen Zero-Day Exploits
The US sanctions Artem Kruglov and associated firms for brokering stolen hacking tools and zero-day exploits for Russian intelligence services.
L3Harris Insider Sentenced for Selling Zero-Days to Russian Broker
Former defense contractor Peter Williams sentenced to seven years for selling eight zero-day exploits to Russian broker Operation Zero for millions in profit.
CISA Adds FileZen CVE-2026-25108 Command Injection to KEV Catalog
CISA confirms active exploitation of FileZen CVE-2026-25108, an OS command injection flaw. Organizations must patch immediately to prevent command execution.
SolarWinds Patches Four Critical RCE Flaws in Serv-U File Transfer
SolarWinds addresses four critical vulnerabilities (CVSS 9.1) in Serv-U 15.5, including CVE-2025-40538, which allows unauthorized root code execution.
January 2026 CVE Landscape: APT28 Zero-Day & Critical Flaws
Runtime Rebel details January 2026's 23 critical CVEs, including an APT28 zero-day in Microsoft Office and critical enterprise authentication bypass vulnerabilities.
macOS coreaudiod Type Confusion Exploitation: CVE-2024-54529
Analysis of CVE-2024-54529, a critical type confusion vulnerability in macOS coreaudiod, detailing its exploitation and necessary mitigations.
Windows Administrator Protection Bypassed via UI Access Abuse
Analysis of UI Access abuse techniques that bypassed Windows Administrator Protection, a new UAC feature, detailing historical context and fixes.
Open Redirects: Overlooked Vulnerability Impact & Analysis
An analysis of open redirect vulnerabilities, their historical context in OWASP, common exploitation vectors like phishing, and essential mitigation strategies.