Vulnerabilities
Disclosed at the end of January, the SolarWinds vulnerability was likely exploited as a zero-day since December 2025.
Hi, what are you looking for?
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
Disclosed at the end of January, the SolarWinds vulnerability was likely exploited as a zero-day since December 2025.
Three of the security defects are high-severity flaws, two of which were found and reported by Google.
Rewards for exploits are reportedly much smaller than in the contest’s glory days.
Developers must view AI as a collaborator to be closely monitored, rather than an autonomous entity to be unleashed. Without such a mindset, crippling...
Impacting the ‘dyld’ system component, the memory corruption issue can be exploited for arbitrary code execution.
It also fixed a high-severity authentication bypass that could be exploited remotely without authentication to obtain credentials.
More than two dozen advisories have been published by the chip giants for vulnerabilities found recently in their products.
The bugs could be exploited without authentication for command execution and authentication bypass.
Dozens of vulnerabilities, bugs, and potential improvements have been identified by the tech giants’ security teams.
Several vulnerabilities have been patched and mitigated across the industrial giants’ products.
Microsoft’s Patch Tuesday updates fix roughly 60 vulnerabilities found in the company’s products.
The company has fixed several critical vulnerabilities that can be exploited for arbitrary code execution.
SAP has released 26 new and one updated security notes on February 2026 security patch day.
Affecting both RS and PRA, the bug can be exploited remotely via crafted requests without authentication.
Vulnerable SolarWinds Web Help Desk instances were exploited in December 2025 for initial access.
The KEV list is useful but largely misunderstood. KEVology explains what it is, and how best to use it.
The security defect allows unauthenticated attackers to execute arbitrary code remotely via malicious HTTP requests.
CISA updated 59 KEV entries in 2025 to specify that the vulnerabilities have been exploited in ransomware attacks.
VS Code-integrated configuration files are automatically executed in Codespaces when the user opens a repository or pull request.
The vulnerability could allow attackers to execute arbitrary commands and steal credentials and other secrets.