Coverage
Vulnerabilities
903 articles on vulnerability disclosures and exploits
Advertisement
CVE-2024-50498: Wing FTP Server Exploited in RCE Chains — Patch Now
CISA adds CVE-2024-50498 to its KEV catalog after reports of active exploitation. Learn how to secure Wing FTP Server versions prior to 7.5.0 from RCE chains.
2025 Ransomware TTP Analysis: Virtualization and Data Theft Trends
Analysis of shifting ransomware TTPs in 2025, highlighting the surge in data theft extortion, virtualization targeting, and exploitation of edge vulnerabilities.
Oracle EBS Exploitation: Risks to Enterprise Financial Integrity
Analysis of the Oracle EBS hack affecting major corporations and the technical risks associated with unpatched ERP systems and financial data theft.

Chrome Zero-Days and Router Botnets: Weekly Threat Intel Recap
Analysis of the latest Chrome zero-day vulnerabilities, router botnet infrastructure risks, and AWS cloud security breaches from March 2026.
Windows 11 24H2 RRAS RCE: Microsoft Issues OOB Hotpatch Fix
Microsoft releases an out-of-band hotpatch for Windows 11 24H2 to address critical RRAS remote code execution vulnerabilities CVE-2024-43513 and CVE-2024-49053.

OpenClaw AI Agent Flaws: Prompt Injection and Data Exfiltration Risk
CNCERT warns of critical security flaws in OpenClaw AI agents, enabling prompt injection and data exfiltration due to weak default configurations.
CVE-2024-47460: Critical HPE AOS-CX Password Reset Bypass - Patch Now
HPE Aruba Networking fixes a critical vulnerability (CVE-2024-47460) in AOS-CX switches allowing unauthenticated remote attackers to reset admin passwords.
Leveraging Community-Driven Threat Intelligence via Friday Squid Blogging
An analysis of the role of moderated community forums in cybersecurity intelligence gathering and the significance of the Bruce Schneier discussion model.
Windows 11 C: Drive Access Failure on Samsung PCs - Mitigation Guide
Microsoft investigates an issue where February 2026 Windows 11 security updates prevent C: drive access on Samsung laptops, blocking all applications.
CVE-2026-3909 & CVE-2026-3910: Actively Exploited Google Vulnerabilities
CISA added two Google vulnerabilities (Skia Out-of-Bounds Write, Chromium V8 unspecified) to its KEV Catalog due to active exploitation. Patch now.

Cisco SD-WAN vManage RCE: Fake PoCs & CVE-2023-20252 Exploitation
Threat intelligence reveals fake PoCs for Cisco SD-WAN vManage CVE-2023-20252. Understand actual RCE risks and critical patching for affected systems.

Google Cloud Attacks: Exploitation Outpaces Patching Cycles
Vulnerability exploitation, not stolen credentials, is the primary initial compromise vector for Google Cloud environments, often bypassing patching efforts.