Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
UNC6201 Exploits Dell RecoverPoint Zero-Day CVE-2026-22769
Mandiant and GTIG detail UNC6201's exploitation of CVE-2026-22769 in Dell RecoverPoint for VMs, deploying GRIMBOLT backdoor and novel VMware TTPs.
CISA Alert: CVE-2026-25108 Soliton FileZen OS Command Injection Exploited
CISA adds CVE-2026-25108, a Soliton Systems FileZen OS Command Injection vulnerability, to KEV Catalog due to active exploitation. Immediate remediation advised.
Critical RCE Flaws in InSAT MasterSCADA BUK-TS Affect ICS
Two critical vulnerabilities (SQLi, OS Command Injection) in InSAT MasterSCADA BUK-TS lead to remote code execution, impacting critical infrastructure sectors globally.
VMware Aria Operations RCE Vulnerability Patched
Broadcom patched high-severity vulnerabilities in VMware Aria Operations, including an RCE flaw. Organizations must update immediately to mitigate risk.
Critical Flaws in PUSR USR-W610 Impact Critical Manufacturing
CISA identifies critical vulnerabilities in PUSR USR-W610 gateways, including authentication bypass and credential theft. No patches available for EOL hardware.
Valmet DNA Engineering Web Tools Vulnerable to Path Traversal
Unauthenticated attackers can exploit CVE-2025-15577 in Valmet DNA Engineering Web Tools to gain arbitrary file read access across critical infrastructure.
CISA Adds Roundcube Webmail Vulnerabilities to KEV Catalog
CISA adds CVE-2025-49113 and CVE-2025-68461 to its Known Exploited Vulnerabilities catalog, signaling active exploitation of Roundcube Webmail systems.
Chinese APTs Exploit CVE-2024-34351 in TeamT5 ThreatSonar
Taiwanese security firm TeamT5 confirms that a critical command injection flaw in ThreatSonar Anti-Ransomware has likely been exploited by Chinese APT groups.
Microsoft Investigating Mouse Pointer Bug in Classic Outlook
Microsoft confirms a bug in classic Outlook causing the mouse cursor to disappear during email composition. Discover the technical details and mitigation steps.
Security Flaws in Android Mental Health Apps Affect 14.7M Users
Multiple Android mental health apps suffer from hardcoded credentials and insecure data storage, putting sensitive patient information at risk.
Cryptographic Flaws in Password Manager Zero-Knowledge Architectures
Technical analysis of Bitwarden, Dashlane, and LastPass reveals server-side attack vectors that bypass zero-knowledge encryption through account recovery and group…
Exploitation of SVG-Based XSS in RoundCube Webmail Instances
Technical analysis of a cross-site scripting (XSS) vulnerability in RoundCube Webmail triggered by improper sanitization of SVG animate elements.
Exploitation of Roundcube Webmail Cross-Site Scripting Vulnerabilities
CISA has added two Roundcube Webmail vulnerabilities to its Known Exploited Vulnerabilities catalog, signaling active exploitation of legacy flaws in webmail…
Microsoft February 2026 Security Update: Analysis of Six Actively Exploited Zero-Days
Microsoft's latest security release addresses 50+ vulnerabilities, including six zero-day exploits targeting Windows kernel components and browser engines.
Logic Flaws and Data Exfiltration in Autonomous AI Agent Architectures
Technical analysis of guardrail bypasses in LLM-integrated agents, highlighting the transition from conversational models to autonomous actors with privileged access.
Automated Reconnaissance Targeting React2Shell Implementations
Analysis of a specialized toolkit currently utilized by threat actors to identify and exploit React2Shell vulnerabilities within enterprise network perimeters.
Unauthenticated Root RCE in Grandstream IP Phones
A critical vulnerability tracked as CVE-2026-2329 allows unauthenticated remote code execution with root privileges on Grandstream VoIP endpoints.
Automated Exploitation Analysis: AI-Assisted Breach of FortiGate Infrastructure
Amazon threat intelligence identifies a high-velocity campaign leveraging LLM automation to compromise over 600 FortiGate firewalls across 55 countries in a five-week…
CISA Catalogs Critical Roundcube Deserialization Vulnerability Under Active Exploitation
CISA has added CVE-2025-49113 to the Known Exploited Vulnerabilities catalog, addressing a critical RCE flaw in Roundcube webmail software resulting from untrusted data…
Anthropic Claude Code Security: Automated Static Analysis and Remediation Preview
Anthropic has introduced Claude Code Security, a research-preview tool designed to perform static analysis for vulnerability detection and automated patch generation…
Critical Zero-Day in Linux Kernel Exposes Millions of Servers
A newly discovered zero-day vulnerability in the Linux kernel's netfilter subsystem allows local privilege escalation on systems running kernel versions 5.14 through…