Coverage
Vulnerabilities
903 articles on vulnerability disclosures and exploits
Advertisement

CVE-2026-50656: Microsoft Defender Privilege Escalation Zero-Day
Microsoft confirms CVE-2026-50656, a zero-day privilege escalation in Defender's Malware Protection Engine. Patch in development, prioritize mitigation.

MongoBleed: Unauthenticated Credential Theft via Server Memory
Analysis of MongoBleed, a critical vulnerability enabling unauthenticated credential and session token extraction from server memory, highlighting attack surface
Isira Adithya: Research Insights and Bug Bounty Defense Strategies
Examine the methodologies of security researcher Isira Adithya and how ethical hacker insights improve vulnerability management and web application security.

Microsoft Copilot 'SearchLeak' Attack: AI Prompt Injection Data Theft
Analysis of the critical Microsoft Copilot 'SearchLeak' attack. Learn how prompt injection allowed 1-click data theft and crucial defense strategies for AI applications.
CVE-2026-54420: LiteSpeed cPanel Plugin Flaw Under Active Exploit
CISA warns of active exploitation targeting CVE-2026-54420 in LiteSpeed cPanel user-end plugin, urging immediate patching for server security.

Fortinet FortiSandbox: Attackers Exploit CVE-2026-39813, -39808, -25089
Critical Fortinet FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are under active exploitation. Patch immediately.
Tech Coalition Athena: Collaborative OSS Vulnerability Pre-Disclosure
The Athena coalition, comprising over two dozen organizations, establishes a shared platform to proactively triage and remediate open-source software vulnerabilities
Earth Lusca Deploys New SprySOCKS Windows Variant Against Governments
Earth Lusca has ported the SprySOCKS Linux malware to Windows, targeting government entities globally. Analyze the TTPs and learn how to detect this threat.
FortiSandbox RCE via CVE-2024-23108 and CVE-2024-23109 — Patch Now
Unauthenticated attackers are exploiting critical command injection flaws in Fortinet FortiSandbox to achieve RCE. Apply security updates immediately.

Cisco Catalyst SD-WAN Manager CVE-2026-20262 Exploited in the Wild
Cisco patches an actively exploited medium-severity vulnerability in Catalyst SD-WAN Manager (CVE-2026-20262) that allows authenticated file creation.
CVE-2023-6110: Rogue Account Creation in SimpleHelp — Patch Now
Attackers can exploit an OIDC implementation flaw in SimpleHelp servers to create unauthorized technician accounts. Immediate update to 5.2.24 is required.
CVE-2026-20262: Cisco SD-WAN vManage Root Privilege Escalation Fix
Cisco patches CVE-2026-20262, a critical Zero-Day flaw in Catalyst SD-WAN Manager allowing authenticated attackers to escalate to root privileges.