Back to Feed

Tag

Vulnerabilities

50 items tagged #vulnerabilities

Articles

RondoDox Botnet Exploits Critical 2018 Vulnerability to Hijack ASUS Routers

RondoDox botnet exploits 2018 ASUS router vulnerability to hijack over 1 million devices.

RT @CISACyber: 🛡️ We added Drupal core SQL injection vulnerability CVE-2026-9082 to our KEV Cata...

CISA adds Drupal core SQL injection vulnerability CVE-2026-9082 to KEV catalog

Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days

Microsoft patches two exploited Defender zero-days allowing privilege escalation and DoS attacks.

Microsoft shares mitigation for YellowKey Windows zero-day

Microsoft releases mitigation for YellowKey BitLocker zero-day disclosed by Nightmare Eclipse.

Breach entry point, 2026 DBIR finds | About Verizon

Verizon's 2026 DBIR finds vulnerability exploitation now top breach entry point, surpassing stolen credentials.

Pwn2Own Berlin 2026 Closes With $1.3 Million in Zero-Day Payouts

Pwn2Own Berlin 2026 concludes with 47 zero-day exploits demonstrated and $1.3M in payouts.

Exploitation of Critical NGINX Vulnerability Begins

Active in-the-wild exploitation of critical NGINX heap buffer overflow CVE-2026-42945 begins days after patch release.

Another Windows zero day released by Nightmare Eclipse (sort of) It turns out Microsoft just str...

Microsoft failed to properly patch 2020 Windows CVE, allowing Nightmare Eclipse exploitation.

Daily Dose of Dark Web Informer - May 14th, 2026

Daily dark web threat intelligence digest reporting multiple breaches, CVEs, and exposed credentials across global

Maximum Severity Cisco SD-WAN Bug Exploited in the Wild

Cisco SD-WAN maximum severity vulnerability exploited in active attacks.

‼️CVE-2026-20182: Critical Cisco SD-WAN Auth Bypass Under Active Exploitation https://t.co/mm9rX...

CVE-2026-20182 critical Cisco SD-WAN authentication bypass under active exploitation

Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks

Cisco patches critical SD-WAN Controller authentication bypass (CVE-2026-20182) exploited in active zero-day attacks.

Windows 11 and Microsoft Edge hacked at Pwn2Own Berlin 2026

Pwn2Own Berlin 2026 day one: researchers exploit 24 zero-days in Windows 11, Edge, Linux, and AI tools for $523K.

ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories

Weekly threat roundup: PAN-OS RCE exploited, Mythos cURL bug, AI tokenizer attacks, and 10+ security stories.

‼️🇪🇬 mutreasury Allegedly Breached: Admin Credentials and API Keys Exposed From the Egyptian Un...

Egyptian mutreasury payment gateway breached; admin credentials and API keys exposed across 28+ universities.

When configuration becomes a vulnerability: Exploitable misconfigurations in AI apps

Microsoft warns of exploitable misconfigurations in cloud-native AI apps on Kubernetes enabling RCE and data leaks.

New Linux Kernel Vulnerability Fragnesia Allows Root Privilege Escalation

Linux kernel vulnerability CVE-2026-46300 (Fragnesia) allows local privilege escalation to root.

Siemens Ruggedcom Rox

Siemens Ruggedcom Rox OS command injection vulnerability allows authenticated RCE with root privileges.

Siemens Ruggedcom Rox

Siemens Ruggedcom Rox improper access control flaw allows authenticated remote file read with root privileges

F5 Patches Over 50 Vulnerabilities

F5 patches over 50 vulnerabilities in BIG-IP, BIG-IQ, and NGINX products.

Hackers Targeted PraisonAI Vulnerability Hours After Disclosure

Hackers probed PraisonAI authentication bypass CVE-2026-44338 within 3.75 hours of disclosure.

Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation

Anonymous researcher discloses two Windows zero-days: BitLocker bypass (YellowKey) and CTFMON privilege escalation

High-Severity Vulnerability Patched in VMware Fusion

Broadcom patches high-severity TOCTOU privilege escalation flaw in VMware Fusion.

Researcher Drops YellowKey, GreenPlasma Windows Zero-Days

Researcher publicly discloses YellowKey BitLocker bypass and GreenPlasma privilege escalation zero-days in Windows.

‼️ CVE-2026-42945: RCE Proof of concept for CVE-2026-42945, a critical heap buffer overflow in NG...

CVE-2026-42945: Critical heap buffer overflow RCE PoC released for NGINX ngx_http_rewrite_module

‼️🇬🇷 Municipality of Agrinio allegedly breached: 28 databases exposed via SQL injection on the...

Municipality of Agrinio breached; 28 databases exposed via SQL injection attack.

Researchers say AI just broke every benchmark for autonomous cyber capability

Claude Mythos Preview and GPT-5.5 break autonomous cyber capability benchmarks, solving previously unsolvable attack

Windows BitLocker zero-day gives access to protected drives, PoC released

Researcher releases PoC exploits for YellowKey BitLocker bypass and GreenPlasma privilege escalation zero-days.

Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises

Microsoft patches critical zero-click Outlook RCE vulnerability CVE-2026-40361 affecting enterprises.

Fortinet, Ivanti Patch Critical Vulnerabilities

Fortinet and Ivanti patch 18 vulnerabilities including three critical code execution flaws.

Chipmaker Patch Tuesday: Intel and AMD Patch 70 Vulnerabilities

Intel and AMD release 70 vulnerability patches across product portfolios on May 2026 Patch Tuesday.

ICS Patch Tuesday: New Security Advisories From Siemens, Schneider, CISA

Siemens, Schneider Electric, and CISA publish May 2026 Patch Tuesday advisories for ICS vulnerabilities.

Defense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark

Microsoft announces MDASH, an AI agentic system that discovered 16 new Windows vulnerabilities including four Critical

Yippie Two new Microsoft Windows 0days. The exploits have cool and badass mysterious names to be...

Two new Microsoft Windows zero-day vulnerabilities disclosed with codenames GreenPlasma and YellowKey.

Microsoft addresses 137 vulnerabilities in May’s Patch Tuesday, including 13 rated critical

Microsoft patches 137 vulnerabilities in May Patch Tuesday, including 13 critical flaws.

Microsoft and Adobe Patch Tuesday, May 2026 Security Update Review

Microsoft patches 137 vulnerabilities including 30 critical; Adobe addresses 52 vulnerabilities with 27 critical in May

Two more public disclosures, it will never stop

Researcher discloses two Microsoft vulnerabilities via GitHub, threatens escalation.

Microsoft May 2026 Patch Tuesday fixes 120 flaws, no zero-days

Microsoft May 2026 Patch Tuesday fixes 120 flaws with 17 critical vulnerabilities, no zero-days.

Microsoft Patches 137 Vulnerabilities

Microsoft patches 137 vulnerabilities including critical flaws in Azure, Windows, and Office products.

Škoda warns of customer data breach after online shop hack

Škoda Auto discloses data breach after attackers exploited unspecified vulnerability in German online shop.

Adobe Patches 52 Vulnerabilities in 10 Products

Adobe patches 52 vulnerabilities across 10 products, including critical code execution flaws.

Pwn2Own Berlin 2026 Hits Capacity as Rejected Hackers Release 0-Days

Rejected Pwn2Own Berlin 2026 researchers publicly disclose zero-days for Firefox, NVIDIA, and AI platforms.

‼️ Nightmare-Eclipse has just released two new GitHub repositories... Same user behind RedSun, Un...

Threat actor releases two new exploitation tools: YellowKey (BitLocker bypass) and GreenPlasma (Windows privilege

Apple Patches Dozens of Vulnerabilities in macOS, iOS

Apple patches 60+ iOS/iPadOS and 80+ macOS vulnerabilities including WebKit issues.

ABB Automation Builder Gateway for Windows

ABB Automation Builder Gateway for Windows exposes PLC networks via insecure default remote access on port 1217.

SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANA

SAP releases May 2026 patches for 15 vulnerabilities including two critical flaws in Commerce Cloud and S/4HANA.

OpenAI Launches Daybreak for AI-Powered Vulnerability Detection and Patch Validation

OpenAI launches Daybreak, an AI-powered platform for vulnerability detection and patch validation.

cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor

CVE-2026-41940 cPanel flaw exploited to deploy Filemanager backdoor across 2,000+ attacker IPs.

Google's Threat Intelligence Group has documented what it describes as the first confirmed instan...

Google TIG documents first confirmed AI-engineered zero-day exploit by threat actors

Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation

Google discloses first known zero-day 2FA bypass likely developed using AI by unknown threat actors.