§Topic · CVE & Vulnerabilities
CVE & Vulnerabilities
Newly disclosed CVEs, actively exploited vulnerabilities, and critical patches you need to apply now.
All dispatches
Loading
§Topic · CVE & Vulnerabilities
Newly disclosed CVEs, actively exploited vulnerabilities, and critical patches you need to apply now.
All dispatchesAuthentication bypasses CVE-2026-61979 and CVE-2026-15981 in miniOrange SAML 2.0 plugin are being exploited to forge admin logins.
wp2shell critical chain saw 45 million exploit attempts, illustrating compressed vulnerability exploitation windows for popular WordPress sites.
Encrypted prompt injection in xAI's Grok enables zero-click theft of names, locations, subscription tiers and prompt history.
Check Point shows Microsoft Defender's signed BTR.sys boot-time driver can be misused for kernel-level deletion of security files at boot.
Cisco fixes nine Crosswork and Secure Workload vulnerabilities, five rated CVSS 10.0 requiring urgent updates.
Three suspected Russian espionage clusters abuse OAuth and WhatsApp linking to hijack accounts at academia, aerospace and governments.
ToxicPanda Android malware abuses VPN permissions to block Google Play and expand remote command control across apps.
CISA ordered immediate patching of TrueConf Server vulnerabilities that are being actively abused to deploy malware.
Critical Entra ID RCE patched; exploited reports prompted emergency guidance and wide Microsoft updates.
Campaign 'Offside Wallet Theft Factory' uses 40 Firefox extensions impersonating Web3 wallets to steal crypto wallet secrets.
Researchers demonstrate Spectre-based Cloudflare Workers side-channel leaking JWTs from co-located workers at ~12 bits/second.
Investigation reveals Clop likely exploited critical PTC Windchill vulnerability in June, initiating extended extortion and data theft.
Clop-associated web shell on PTC Windchill/FlexPLM decrypts credentials and maps PLM engineering vault data for extortion.
Chain of AIT-GUI flaws (GHSA-p9r8-2q67-fp86) allows unauthenticated attackers to issue arbitrary spacecraft commands (CVSS 9.4).
CVE-2026-24301 'CoSnitch' in Microsoft Copilot Personal allowed one-click exfiltration of connected-account data; patched Aug 18.
US advisory warns AI-generated exploit scripts are targeting exposed Siemens S7 PLCs in industrial environments.
Get these articles delivered to your inbox.
Subscribe free