Security researcher João Domingos has published a comprehensive breakdown of a full exploit chain affecting the FiberGateway...
Exploit
Palo Alto Networks has issued a security advisory for a reflected cross-site scripting (XSS) vulnerability, tracked as...
RAGFlow, the open-source Retrieval-Augmented Generation (RAG) platform developed by Infiniflow, has been found vulnerable to a serious...
Security researcher Navy Titanium have released a technical deep-dive uncovering three severe vulnerabilities affecting pfSense, the popular...
Imperva researchers have disclosed a newly discovered vulnerability in WordPress that could expose sensitive draft and private...
A patched kernel vulnerability, CVE-2025-24203, has attracted great attention in the security community as well as the...
A newly disclosed vulnerability in Microsoft’s Remote Desktop Gateway (RD Gateway) reveals a dangerous race condition that...
Google has released a critical Stable Channel Update for Chrome Desktop, bumping the version to 136.0.7103.113/.114 for...
A comprehensive security audit by the SUSE Security Team has uncovered a collection of serious flaws in...
Netskope Threat Labs has recently uncovered a multi-stage infection chain involving custom PowerShell scripts, open-source tools, exploitation...
Symantec’s Threat Hunter Team has uncovered a sophisticated attack involving a zero-day privilege escalation vulnerability in Microsoft’s...
The Ladybird browser engine, a relatively new entrant originating from the SerenityOS project, has been found to...
A security flaw has been unearthed in WinZip, the popular file compression utility, placing millions of users...
A security researcher published a proof-of-concept exploit code for an Android zero-day exploit chain developed by Cellebrite...
In a rare window into the operations of an advanced persistent threat, a KeyPlug-linked infrastructure briefly went...
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning, adding three new vulnerabilities to its...
A critical security vulnerability, tracked as CVE-2024-58136 (CVSS 9.1), has been uncovered in the popular PHP web...
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning after adding two newly discovered Linux...
In a deep dive published by Guy Bruneau, Senior Security Consultant and former network engineer, the lingering...
Security researcher Robin recently disclosed details and a PoC exploit code of an XML external entity injection...