§Topic · CVE & Vulnerabilities
CVE & Vulnerabilities
Newly disclosed CVEs, actively exploited vulnerabilities, and critical patches you need to apply now.
All dispatches
Loading
§Topic · CVE & Vulnerabilities
Newly disclosed CVEs, actively exploited vulnerabilities, and critical patches you need to apply now.
All dispatchesCritical Paperclip flaw allowed unauthenticated admin access and code execution via board-level API and company import feature.
Coldcard hardware wallet firmware bug exploited, resulting in $89M stolen and product inventory destroyed to prevent further compromise.
Three high-severity Diffusers library flaws let crafted model repositories execute arbitrary code, bypassing trust_remote_code protections.
Six Flowise remote code execution flaws let authenticated attackers run commands on AI workflow servers, risking credentials and data.
DarkSword iOS exploit kit expanded across 180 web properties, targeting iOS 18.4-18.7 to steal sensitive device data.
A decades-old BMC issue leaks authentication hashes pre-login across 24,000+ server-management interfaces, risking data center takeover.
Forescout found 15 Omada ZTP vulnerabilities that can be chained to achieve full network takeover of TP-Link Omada ecosystems.
INC ransomware group aggressively exploits SonicWall SMA 1000 zero-days to steal and encrypt data for extortion.
Proof-of-concept shows Microsoft Copilot can be abused to escalate access, hijack executive accounts, and redirect wire transfers.
Active exploitation of N-able N-central CVE-2026-18577 allows attackers admin access to RMM servers; urgent patching recommended.
TeamCity patched CVE-2026-63077, an unauthenticated code execution flaw exploitable via the agent polling protocol.
SANS NewsBites highlights Minnesota water utilities attacks, IPMI BMC hash leaks, and Cisco FMC hardcoded credential exploitation.
Ruby on Rails patched a critical unauthenticated flaw allowing arbitrary file reads and potential RCE via Active Storage.
Open-source AiTM phishing kits proxy live Microsoft 365 auth sessions, capturing tokens and bypassing MFA protections.
Get these articles delivered to your inbox.
Subscribe free