In a recent revelation, Socket’s Threat Research Team has uncovered a stealthy npm supply chain attack leveraging...
Remote Code Execution
A newly disclosed vulnerability affecting Netcomm Wireless devices—now under Lantronix ownership—has been assigned CVE-2025-4010, and it poses...
Roundcube Webmail, a widely-used browser-based IMAP client, has patched a critical security vulnerability, tracked as CVE-2025-49113 (CVSS...
Apple has patched a high-severity zero-day vulnerability in CoreAudio, the framework responsible for audio playback and processing...
Esri has issued a critical security patch for its widely used Portal for ArcGIS software, addressing a...
Veritas has issued a security advisory warning users of its Desktop Laptop Option (DLO) platform about two...
Security researchers at Rapid7 have uncovered a troubling trio of vulnerabilities in MICI Network Co., Ltd.’s NetFax...
Hitachi Energy has issued a cybersecurity advisory warning of multiple vulnerabilities impacting its Asset Suite product—a widely...
IBM has issued a critical security update for its Tivoli Monitoring suite, addressing a high-severity vulnerability that...
A critical vulnerability in the Tenda W18Ev2 Enterprise Router allows unauthenticated attackers to remotely change the administrator...
Redis, the lightning-fast in-memory data store beloved by developers for real-time data applications, has recently patched a...
A newly disclosed vulnerability in Apache Commons BeanUtils has raised serious concerns for Java-based applications relying on...
The Mozilla Foundation has released a security advisory addressing a critical vulnerability affecting Firefox and other Mozilla-based...
Weidmueller Interface GmbH & Co. KG, a global manufacturer of industrial connectivity and automation solutions, has disclosed...
A newly disclosed vulnerability in vBulletin, one of the most widely used commercial forum platforms on the...
A newly identified Chinese-speaking threat actor cluster, tracked as UAT-6382, is actively exploiting a zero-day vulnerability in...
Researchers have disclosed two critical vulnerabilities in Langroid, a popular Python framework designed for building large language...
Lexmark has released a security advisory for a critical vulnerability—CVE-2025-1127—affecting a wide range of its printer models....
A critical vulnerability—CVE-2025-47277—has been disclosed in vLLM, a high-performance inference and serving engine for large language models...
A critical vulnerability in TP-Link’s widely deployed Archer AX50 router has been uncovered, potentially allowing remote attackers...
In a recent revelation, OP Innovate has uncovered early evidence of real-world exploitation of CVE-2025-31324 (CVSS 10),...
A newly disclosed vulnerability in Microsoft’s Remote Desktop Gateway (RD Gateway) reveals a dangerous race condition that...