Coverage
Vulnerabilities
903 articles on vulnerability disclosures and exploits
Advertisement

Ivanti Sentry Max-Severity Flaw Exploited Within 24 Hours
A critical Ivanti Sentry vulnerability was actively exploited within 24 hours of public disclosure. Defenders must patch immediately to prevent compromise.
Chrome 149 Update Patches 28 Vulnerabilities — Mitigation Guide
Google addresses 28 security flaws in Chrome 149, including critical use-after-free bugs. Learn about technical impacts and enterprise patching requirements.
Ivanti Sentry CVE-2023-35081: CISA Issues Urgent 3-Day Patch Mandate
CISA adds CVE-2023-35081 to its KEV catalog, ordering federal agencies to patch Ivanti Sentry path traversal flaws to prevent remote code execution.

Oracle PeopleSoft RCE via CVE-2026-35273 — Mitigation Guide
ShinyHunters (UNC6240) exploited an Oracle PeopleSoft zero-day (CVE-2026-35273) to breach university networks and exfiltrate data for extortion purposes.
Yarbo Mobile App & Cloud: Critical Robot Fleet Vulnerabilities
Critical vulnerabilities CVE-2026-10557 & CVE-2026-7368 in Yarbo mobile app and cloud allow attackers to control robot fleets via hard-coded credentials.
CVE-2024-21319: PeopleSoft Auth Bypass Exploited by ShinyHunters
Oracle PeopleSoft zero-day CVE-2024-21319, an authentication bypass, is being actively exploited by ShinyHunters. Patch PeopleSoft 8.59, 8.60, 8.61 now.
CISA BOD 26-04: Prioritizing KEV Catalog Vulnerability Patching
CISA's BOD 26-04 mandates federal agencies prioritize patching vulnerabilities in the KEV catalog. Learn its impact and how to enhance your vulnerability management.
CISA Mandates Critical Ivanti & ActiveMQ Patching in 3 Days
CISA's BOD 26-04 requires federal agencies to patch critical, exploited Ivanti Connect Secure and Apache ActiveMQ vulnerabilities within 72 hours.

AI and the Collapse of the Vulnerability Management Buffer
AI-driven exploitation has eliminated the time buffer between vulnerability discovery and weaponization, prompting a strategic shift toward BAS.
Ivanti Connect Secure RCE via CVE-2024-21887 — Mitigation Guide
Analysis of persistent scanning for Ivanti Connect Secure vulnerabilities CVE-2023-46805 and CVE-2024-21887 used by attackers for RCE and network access.
CISA KEV Update: Active Exploitation of Arista, Cisco, and Chrome
CISA adds CVE-2026-7473, CVE-2026-11645, and CVE-2026-20245 to its Known Exploited Vulnerabilities catalog following evidence of active exploitation.

CISA Updates Federal Patching Mandates to Combat AI-Driven Threats
CISA updates federal directive to require 3-day patching for critical flaws, addressing the rapid exploitation speeds enabled by artificial intelligence.