Check Point fixed a Management Server flaw exploited in targeted July attacks that can run scripts without login.
WordPress fixes a critical unauthenticated path traversal flaw that can load local PHP files and, on some servers, enable ...
Malicious npm package tw-pkgprobe-7731 targets Twilio developer environments and can exfiltrate credentials and environment ...
Microsoft disrupted EvilTokens after it was linked to more than 12,000 compromised inboxes across over 10,000 organizations.
Bifrost CVE-2026-90898 enables unauthenticated command execution with management auth disabled; transports/v2.1.0 fixes the flaw.
BigDiskBuster can block Microsoft Defender updates by filling disk space, leaving detection content stale; no patch or advisory exists.
Attackers are exploiting CVE-2026-93952 in certificate-authenticated VeloCloud Orchestrators, with some release trains still awaiting fixes.
AI agents can chain credentials and tools to reach beyond direct permissions, as a Hugging Face evaluation showed.
DORA’s second year shifts focus to proving ICT controls work, with network evidence supporting monitoring, detection, and incident response.
A Linux KVM flaw on ARM64 can expose host kernel memory to guests and enable guest-to-host escape when nested virtualization is enabled.
SharePoint CVE-2026-65660 enables authenticated RCE; Microsoft patched it on August 11, and no in-the-wild exploitation is reported.
Malicious npm package indexed-btree hid its loader in runtime code, avoiding install hooks after logging millions of downloads.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results