Coverage
Vulnerabilities
903 articles on vulnerability disclosures and exploits
Advertisement
Microsoft Patch Tuesday: 83 Vulnerabilities, Critical Flaw Addressed
Microsoft's latest Patch Tuesday addresses 83 vulnerabilities across its product line, including one critical flaw. Security teams must prioritize immediate patching.
Windows 10 KB5078885 ESU Fixes Two Zero-Days — Patch Guidance
Microsoft releases Windows 10 KB5078885 Extended Security Update to address two zero-day vulnerabilities and a critical system shutdown bug for ESU subscribers.

FortiGate NGFW Exploitation Leads to Service Account Credential Theft
Threat actors are exploiting FortiGate devices to extract configuration files and steal service account credentials, facilitating lateral movement in networks.
KadNap Botnet: ASUS Routers Hijacked for Faceless Proxy Network
The KadNap botnet hijacks ASUS routers via CVE-2024-3080 to fuel the Faceless proxy service, enabling cybercriminals to mask traffic through residential IPs.
Ivanti EPM CVE-2024-29824 Exploited: Technical Analysis and Patching
CISA warns of active exploitation of CVE-2024-29824 in Ivanti Endpoint Manager. Secure your Core server with our technical analysis and mitigation guide.
Microsoft Windows Hotpatching to be Enabled by Default in May 2026
Microsoft will enable hotpatching by default for Intune-managed Windows devices in May 2026, allowing security updates without reboots to reduce downtime.
CVE-2024-29847: Ivanti EPM RCE Under Active Exploitation - Patch Now
CISA warns of active exploitation of a critical Ivanti EPM vulnerability (CVE-2024-29847). Learn how to mitigate this unauthenticated RCE threat immediately.

Reducing Attack Surface to Prevent Zero-Day Scrambles
Learn how attack surface reduction limits internet-facing exposure and mitigates the impact of rapidly exploited zero-day vulnerabilities.

CISA Flags SolarWinds, Ivanti, and Workspace One Flaws in KEV Update
CISA adds vulnerabilities in SolarWinds, Ivanti, and Omnissa Workspace One UEM to its Known Exploited Vulnerabilities catalog following active exploitation.
Google Cloud Security: Exploits Surpass Weak Credentials
Google Cloud reports a major shift in attack vectors, with software vulnerability exploitation now outpacing weak credentials as the primary access method.
CVE-2026-1603: CISA Warns of Active Ivanti and SolarWinds Exploitation
CISA adds CVE-2026-1603, CVE-2025-26399, and CVE-2021-22054 to the KEV catalog, requiring immediate remediation for Ivanti, SolarWinds, and Omnissa systems.

Qualcomm 0-Day and iOS Exploit Chains: Impact & Mitigation Strategies
This weekly recap details active exploitation of a Qualcomm zero-day, iOS exploit chains, and emerging 'AirSnitch' attack methods. Learn what defenders should prioritize.