Metabase says a CVSS 10.0 zero-day SQL injection was exploited in the wild; the flaw can grant admin access and expose ...
Open source may split as the EU Cyber Resilience Act and enterprise security demands favor reachable, patchable, accountable ...
ClickFix attacks deliver a Go-based macOS stealer that steals passwords and Keychain data and can drain part or all of ...
UNC6671 uses vishing and AitM phishing to steal cloud credentials and MFA tokens, then exfiltrate data from Microsoft 365, ...
WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under ...
N-able releases N-central Hotfix 2 amid CVE-2026-18577 exploitation that gave attackers admin access and persistent access to managed systems.
AitM phishing hijacks Microsoft 365 accounts, then uses residential proxies and Microsoft Graph API access to collect payroll ...
NatJack abuses NAT state to hijack TCP sessions and spoof DNS responses; Windows and Linux flaws are tracked under two CVEs.
Linux SCTP flaw CVE-2026-64564 dates back to 2008 and Tencent researchers say it could escape containers and gain host root.
Oligo links TeamPCP activity back to Redis attacks in 2020, tracing its shift from cloud exploitation to open-source supply ...
PortSwigger says HTTP Terminator generated 30,000 desync vectors, found roughly 700 vulnerable targets, and helped uncover an ...
Gemini CLI and Claude Code flaws let untrusted GitHub input reach CI workflows, including host command execution and API key ...