Risk Management
The KEV list is useful but largely misunderstood. KEVology explains what it is, and how best to use it.
Hi, what are you looking for?
The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches.
The KEV list is useful but largely misunderstood. KEVology explains what it is, and how best to use it.
The security defect allows unauthenticated attackers to execute arbitrary code remotely via malicious HTTP requests.
CISA updated 59 KEV entries in 2025 to specify that the vulnerabilities have been exploited in ransomware attacks.
VS Code-integrated configuration files are automatically executed in Codespaces when the user opens a repository or pull request.
The vulnerability could allow attackers to execute arbitrary commands and steal credentials and other secrets.
The security defects can lead to DoS conditions, arbitrary command execution, and privilege escalation.
The flaws dubbed LookOut can be exploited for remote code execution and data exfiltration.
The critical vulnerability exists in the contextual trust in MCP Gateway architecture, as instructions are passed without validation.
Two IP addresses accounted for the majority of the 1.4 million exploitation attempts observed over the past week.
The critical-severity SolarWinds Web Help Desk flaw could lead to unauthenticated remote code execution.
Wiz and Permiso have analyzed the AI agent social network and found serious security issues and threats.
Albeit mainly considered a theoretical risk, the flaw has been exploited to disable protections and deliver malware.
The attacks targeting Europe were analyzed by Ukraine’s CERT-UA and the cybersecurity company Zscaler.
The critical-severity vulnerabilities could allow unauthenticated attackers to execute arbitrary code remotely.
The two bugs impacted n8n’s sandbox mechanism and could be exploited via weaknesses in the AST sanitization logic.
The four critical flaws could be exploited without authentication for remote code execution or authentication bypass.
Russian and Chinese state-sponsored threat actors have been exploiting CVE-2025-8088 since July 2025.
Tracked as CVE-2026-24858, the bug allows attackers to log into devices registered to other FortiCloud accounts.
A total of 12 vulnerabilities have been fixed in OpenSSL, all discovered by a single cybersecurity firm.
The flaws allow threat actors to obtain root privileges or bypass authentication via Telnet and gain shell access as root.