Coverage
Vulnerabilities
903 articles on vulnerability disclosures and exploits
Advertisement
CVE-2024-0012: Critical PAN-OS Management Interface RCE Analysis
Technical analysis of CVE-2024-0012 affecting Palo Alto Networks PAN-OS. Learn how to detect CVE-2024-0012 exploit and implement immediate mitigation steps.
Apple A-Series BootROM Bypass: Usbliter8 Exploit Technical Analysis
Technical breakdown of the Usbliter8 exploit affecting millions of iPhones. Learn why this hardware-level BootROM vulnerability cannot be patched.

CVE-2026-4020: Gravity SMTP Exploit Exposes WordPress API Keys
Unauthenticated attackers are exploiting CVE-2026-4020 in the Gravity SMTP WordPress plugin to extract API keys, secrets, and OAuth tokens from 100,000 sites.
CVE-2024-49403: Gravity SMTP Information Disclosure Patch Guidance
Exploitation of CVE-2024-49403 in the Gravity SMTP WordPress plugin allows unauthenticated actors to steal SMTP credentials. Learn how to secure your site now.

usbliter8 Exploit Breaks Apple A12/A13 SecureROM Boot Chain
Paradigm Shift researchers disclose 'usbliter8', an unpatchable hardware exploit enabling arbitrary code execution in Apple A12 and A13 SecureROM, requiring physical
GCP Config Connector Takeover: Unpatched Flaw Critical for Cloud Environments
An unpatched flaw in GCP Config Connector poses a critical takeover risk to Google Cloud environments. Learn about Velvet Ant's decade-long stealth and the Popa Android

AutoJack: AI Browsing Agents Hijacked for Host RCE via Web Pages
Microsoft researchers reveal AutoJack, a novel exploit chain where malicious web pages hijack AI browsing agents to achieve remote code execution on host systems.
FortiBleed Data Leak: Securing Fortinet VPNs Against Exposure
CISA warns organizations after 74,000 Fortinet VPN credentials were leaked online. Learn how to mitigate the FortiBleed threat and secure your network.

CVE-2025-20701: Apple Patches Beats Studio Buds Eavesdropping Flaw
Apple addresses CVE-2025-20701, a high-severity flaw in Beats Studio Buds allowing nearby attackers to bypass pairing consent and access the microphone.

CVE-2026-42530 & -42531: NGINX RCE via Use-After-Free
F5 addresses critical RCE flaws [CVE-2026-42530, CVE-2026-42531] in NGINX Open Source. Unauthenticated attackers can exploit use-after-free issues. Patch now.
Rockwell RSLinx <4.50.00 RCE via CVE-2020-13573 — Patch Now
Urgent advisory for Rockwell RSLinx Classic users. CVE-2020-13573, a stack-based buffer overflow, enables remote code execution and DoS. Patch <=4.50.00.
CVE-2026-11317: Rockwell Logix DoS via CIP — Patch Critical ICS
Critical Manufacturing faces high-severity DoS risk in Rockwell Automation Logix 5370 & 5570 controllers from CVE-2026-11317. Patch now.