Skip to main content

Coverage

Vulnerabilities

903 articles on vulnerability disclosures and exploits

Advertisement

SU
HIGH
Supply Chain

OptinMonster 2.6.5 Update: Managing CDN Supply Chain Attack Risks

Learn how the OptinMonster CDN supply chain attack compromised over 1 million WordPress sites and how to mitigate the risk of malicious script injection.

Runtime Rebel Intel
3 min read·Jun 15, 2026
Microsoft 365 Copilot SearchLeak: One-Click Data Exfiltration
HIGH
Vulnerabilities

Microsoft 365 Copilot SearchLeak: One-Click Data Exfiltration

Varonis Threat Labs uncovered 'SearchLeak', a one-click flaw in Microsoft 365 Copilot Enterprise Search allowing exfiltration of emails, files, and MFA codes.

Runtime Rebel Intel
5 min read·Jun 15, 2026
LiteLLM Proxy Server Takeover via Critical Vulnerability Chain
CRITICAL
Vulnerabilities

LiteLLM Proxy Server Takeover via Critical Vulnerability Chain

Researchers at Obsidian Security have identified a three-vulnerability chain in LiteLLM that allows low-privilege users to gain full server control.

Runtime Rebel Intel
3 min read·Jun 15, 2026
CVE-2026-0257: Palo Alto Networks PAN-OS GlobalProtect Bypass Active
CRITICAL
Vulnerabilities

CVE-2026-0257: Palo Alto Networks PAN-OS GlobalProtect Bypass Active

Palo Alto Networks warns of active exploitation of CVE-2026-0257, an authentication bypass flaw in PAN-OS GlobalProtect. Apply critical security patches now.

Runtime Rebel Intel
3 min read·Jun 15, 2026
VU
CRITICAL
Vulnerabilities

FortiSIEM RCE via CVE-2024-23108: Technical Mitigation Guide

Analysis of critical RCE vulnerabilities CVE-2024-23108 and CVE-2024-23109 in Fortinet FortiSIEM, including detection methods and remediation steps.

Runtime Rebel Intel
3 min read·Jun 15, 2026
CVE-2026-20253: Unauthenticated RCE in Splunk Enterprise <10.2.4
CRITICAL
Vulnerabilities

CVE-2026-20253: Unauthenticated RCE in Splunk Enterprise <10.2.4

Critical flaw CVE-2026-20253 in Splunk Enterprise allows unauthenticated RCE by creating/truncating files. Patch versions <10.2.4 and <10.0.7 immediately.

Runtime Rebel Intel
4 min read·Jun 13, 2026
VU
CRITICAL
Vulnerabilities

Oracle PeopleSoft CVE-2026-35273 Exploit: CISA KEV Mitigation Guide

CISA adds CVE-2026-35273 in Oracle PeopleSoft to its KEV catalog. Learn how to mitigate this missing authentication vulnerability and protect enterprise systems.

Runtime Rebel Intel
3 min read·Jun 13, 2026
TH
INFO
Threat Intel

Securing Biomimetic Fluid Pumps in ICS: A Threat Intel Analysis

Analysis of the security surface of squid-inspired fluid pumps in climate tech and the role of community intelligence in identifying emerging hardware risks.

Runtime Rebel Intel
3 min read·Jun 13, 2026
ShinyHunters Exploits Oracle ERP Zero-Day to Breach Higher Ed
CRITICAL
Vulnerabilities

ShinyHunters Exploits Oracle ERP Zero-Day to Breach Higher Ed

ShinyHunters is exploiting an unpatched zero-day vulnerability in Oracle ERP software, targeting US higher education institutions for data theft. Learn mitigation

Runtime Rebel Intel
4 min read·Jun 13, 2026
VU
HIGH
Vulnerabilities

phpBB Authentication Bypass: Admin Login Vulnerability Patched

A decade-old authentication bypass in phpBB forum software, affecting versions up to 3.3.11, allowed attackers to log in as any user, including administrators.

Runtime Rebel Intel
4 min read·Jun 12, 2026
TH
CRITICAL
Threat Intel

CVE-2026-35273: Oracle PeopleSoft RCE Exploited as Zero-Day by ShinyHunters

Mandiant and GTIG identified ShinyHunters (UNC6240) exploiting CVE-2026-35273, a critical RCE in Oracle PeopleSoft, targeting higher education.

Runtime Rebel Intel
6 min read·Jun 12, 2026
VU
CRITICAL
Vulnerabilities

CVE-2026-28742 & Others: Naxclow IoT Platform Critical Flaws

CISA warns of multiple critical vulnerabilities in Naxclow IoT Platform, including hard-coded cryptographic keys, authorization bypasses, and credential exposure.

Runtime Rebel Intel
5 min read·Jun 12, 2026