Coverage
Vulnerabilities
903 articles on vulnerability disclosures and exploits
Advertisement
AirSnitch: Cross-Layer Desynchronization Enables Wi-Fi MitM Attacks
Research reveals AirSnitch, a vulnerability exploiting Wi-Fi Layers 1 and 2 to execute bidirectional MitM attacks across home and enterprise networks.

Chinese APT Group Targets Asian Critical Infrastructure via Web Exploits
A Chinese threat actor is targeting high-value infrastructure across Asia using web server exploits and Mimikatz for long-term cyber espionage campaigns.
CVE-2026-20127: Cisco Catalyst SD-WAN Exploited — Patch Guide
WatchTowr reports widespread exploitation attempts targeting a recent CVE-2026-20127 vulnerability in Cisco Catalyst SD-WAN devices, urging immediate action.

Firefox 148 Security Update: Anthropic AI Uncovers 22 Vulnerabilities
Anthropic's Claude Opus 4.6 AI model identified 22 security vulnerabilities in Firefox, including 14 high-severity flaws addressed in the version 148 release.

OpenAI Codex Security: Scanning 1.2 Million Commits for Vulnerabilities
OpenAI's Codex Security identifies over 10,000 high-severity vulnerabilities across 1.2 million commits using AI-driven detection and automated remediation.
ArmorCode Raises $16M to Scale Exposure Management Platform
ArmorCode secures $16 million in funding to advance its AI-powered exposure management platform, focusing on vulnerability prioritization and ASPM workflows.
Apple iOS CVE-2023-41993: Patching Exploited Spyware Vulnerabilities
CISA warns of three Apple iOS vulnerabilities, including CVE-2023-41993, exploited in mercenary spyware and cryptocurrency theft attacks. Patch immediately.
Iranian APT Exploits Edge Vulnerabilities in US Infrastructure
Iranian state-sponsored actors breached US airports and banks by exploiting edge device vulnerabilities, likely serving as initial access brokers for ransomware.

Hikvision and Rockwell Automation CVEs: CISA KEV Mitigation Guide
CISA adds Hikvision CVE-2017-7921 and Rockwell Automation flaws to the KEV catalog. Learn how to detect and mitigate these critical CVSS 9.8 vulnerabilities.
CVE-2024-28182: Python Cryptography RSA DoS Mitigation Guide
Technical deep dive into CVE-2024-28182, a denial-of-service vulnerability in the Python cryptography library. Learn how to detect and patch RSA-based DoS.

Optimizing Mutational Grammar Fuzzing for Enhanced Vulnerability Discovery
Explore the effectiveness and inherent flaws of mutational grammar fuzzing, a key technique for vulnerability discovery, and a method to improve its efficacy.
CISA KEV Update: Five Actively Exploited CVEs in Apple, Hikvision, Rockwell
CISA adds five actively exploited vulnerabilities, including Apple iOS/iPadOS use-after-free and Hikvision improper authentication, to its KEV Catalog. Patch these