§Topic · CVE & Vulnerabilities
CVE & Vulnerabilities
Newly disclosed CVEs, actively exploited vulnerabilities, and critical patches you need to apply now.
All dispatches
Loading
§Topic · CVE & Vulnerabilities
Newly disclosed CVEs, actively exploited vulnerabilities, and critical patches you need to apply now.
All dispatchesMalicious SIM cards can run attacker code on cellular modems inside EV chargers, industrial routers, and telematics units, enabling device takeover.
Malware running in a signed Windows session can quietly use Windows Hello for Business keys to authenticate to Entra ID and persist.
Flaws in Claude Code and Google's Gemini CLI let an unprivileged GitHub issue execute code on CI runners and expose secrets.
Threat actors exploited unpatched TrueConf servers to replace client installers with trojanized backdoors for remote access.
Campaign published nearly 800 malicious npm packages delivering a cross-platform RAT and infostealer for Windows, macOS and Linux.
Varonis found a one-click RovoBlast vulnerability that could expose Confluence, Jira and SharePoint data to attackers.
CSS bomb technique manipulates webmail UI to spy on user activity and capture passwords and tokens without JavaScript.
Active AitM phishing campaign hijacks Microsoft 365 accounts to collect payroll and finance emails using residential proxies.
N-able released hotfixes after active exploitation of N-central enabled persistent attacker access to managed systems.
Chrome 151 fixes multiple memory-safety bugs, including critical use-after-free issues — prioritize browser updates.
Critical Metabase SQLi zero-day allows unauthenticated admin access and active data-theft; immediate mitigation required.
Critical one-click RCE affecting Cursor, VS Code, and Google Antigravity could compromise developers by executing code via malicious links.
Researcher demonstrated a PoC providing C2-style influence over ChatGPT's isolated sandbox, highlighting container escape risks.
Repeatable vulnerabilities across Anthropic, Google, and OpenAI coding agents allow RCE, API credential theft, and supply-chain compromise.
Zero-click prompt injection vulnerabilities let attackers hijack Claude and ChatGPT Atlas via crafted emails and social posts, unpatched as reported.
Get these articles delivered to your inbox.
Subscribe free