§Topic · CVE & Vulnerabilities
CVE & Vulnerabilities
Newly disclosed CVEs, actively exploited vulnerabilities, and critical patches you need to apply now.
All dispatches
Loading
§Topic · CVE & Vulnerabilities
Newly disclosed CVEs, actively exploited vulnerabilities, and critical patches you need to apply now.
All dispatchesThreat actors exploited a service-provider vulnerability to withdraw funds in a massive bank fraud affecting multiple customers and banking services.
Gunra actors exploit Fortinet vulnerabilities to exfiltrate large volumes of Microsoft service data, targeting critical infrastructure.
CISA ordered federal agencies to patch a Microsoft bug exploited in a long-running DPRK job-application campaign within two weeks.
Lazarus exploits AFD.sys zero-day (CVE-2026-68820) to deploy FudModule rootkit for stealthy kernel persistence.
Microsoft patched 'LegacyHive', a Windows zero-day vulnerability disclosed after July Patch Tuesday that allows privilege escalation.
CERT.PL reports Russian-linked hackers accessed a Polish power plant OT network via a private APN, impacting critical infrastructure.
Zoom annotation vulnerabilities could allow meeting participants to take control of other attendees' clients without interaction.
Browser extension vulnerabilities in Belgium's eID framework allow remote code execution and full compromise of citizen accounts.
Exploit 'ShieldBreak' enables any user to spawn a SYSTEM shell on Windows via a newly released zero-day toolset.
Critical Adobe Commerce vulnerability was targeted and exploited shortly after disclosure, risking customer account takeover.
Microsoft issued massive Patch Tuesday fixes including multiple zero-days, with some exploited in nation-state campaigns.
Critical VMware vCenter flaw (CVE-2026-59310) is being actively exploited to deploy reverse SSH persistence backdoors.
BdThemes supply-chain compromise poisoned JSON feeds to create rogue WordPress admin accounts, backdooring sites without modifying plugin files.
China-linked Storm-1175 deploys StormEncryptor ransomware, likely exploiting an N-able N-central vulnerability to gain initial access.
Microsoft warns China-linked actors are exploiting a critical flaw in N-able to deploy ransomware broadly as a launchpad.
Critical vulnerabilities discovered in Belgian eID software put two million users at risk of identity compromise.
CopyEscape (CVE-2026-17106) allows malicious docker cp operations to overwrite host files and potentially achieve root execution.
CISA confirms active exploitation of a high-severity Microsoft SharePoint RCE now used in ransomware intrusions and lateral movement.
Windows Plug and Play abuse can fetch signed vendor software and escalate to SYSTEM on fully updated Windows 11 via USB emulation.
Get these articles delivered to your inbox.
Subscribe free