Researchers from ETH Zurich have unveiled Phoenix, a new Rowhammer attack that successfully bypasses in-DRAM mitigations in...
privilege escalation
The PyInstaller project has released fixes for a local privilege escalation vulnerability that affected applications packaged with...
The CERT Coordination Center (CERT/CC) has issued a vulnerability note warning of two critical local security flaws...
NVIDIA has released a software update for its NVDebug tool, addressing three high-severity vulnerabilities (CVE-2025-23342, CVE-2025-23343, and...
FortiGuard Labs has uncovered a sophisticated phishing campaign that deploys a new Remote Access Trojan (RAT) dubbed...
Apple has patched a critical security vulnerability in macOS Sequoia, tracked as CVE-2025-24204 (CVSS 9.8), that could...
The GNU Guix team has issued a critical security advisory warning users to immediately update their systems...
Renowned operating system developer Canonical has announced that the upcoming Ubuntu 25.10 release will replace the long-standing...
MediaTek has published its September 2025 Product Security Bulletin, disclosing several high- and medium-severity vulnerabilities affecting a...
A security researcher has disclosed a serious flaw in the UDisks daemon, a widely used component for...
At DEF CON 2025, Akamai security researcher Yuval Gordon revealed the story of BadSuccessor (CVE-2025-53779), an Active...
The Hikvision Security Response Center (HSRC) has released a new advisory detailing three vulnerabilities affecting different versions...
Dell Technologies has issued a security advisory addressing several high-severity vulnerabilities in its ThinOS 10 platform, widely...
The Langflow project has issued an important security advisory regarding a newly discovered vulnerability that poses a...
In April, Microsoft has patched a high-severity, zero-day vulnerability (CVE-2025-29824) in the Windows Common Log File System...
A newly disclosed vulnerability in the Capsule Kubernetes multi-tenancy framework exposes organizations to privilege escalation and cross-tenant...
Zoom has released security updates addressing two significant vulnerabilities in its Windows-based clients—CVE-2025-49456 and CVE-2025-49457—that could enable...
Security researcher Jann Horn from Google Project Zero disclosed the technical details and proof-of-concept exploit code for...
Yesterday, Microsoft issued a critical security advisory addressing a newly identified vulnerability—CVE-2025-53786—in hybrid Microsoft Exchange environments. The...
Elastic has issued patches for two local privilege escalation (LPE) vulnerabilities affecting its popular observability tools—APM Server...
BeyondTrust, a global leader in intelligent identity and access security, has issued two advisories addressing two local...
The CERT Coordination Center (CERT/CC) has issued a Vulnerability Note detailing a critical privilege escalation flaw affecting...