Application Security
A researcher has pointed out that only instances using a newer feature are impacted by CVE-2025-55182.
Hi, what are you looking for?
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
A researcher has pointed out that only instances using a newer feature are impacted by CVE-2025-55182.
A critical-severity vulnerability in the King Addons for Elementor plugin for WordPress has been exploited to take over websites.
Windows now displays in the properties tab of LNK files critical information that could reveal malicious code.
Chrome 143 stable was released with patches for 13 vulnerabilities, including a high-severity flaw in the V8 JavaScript engine.
Google warns that two out of the 107 vulnerabilities patched in Android this month have been exploited in limited, targeted attacks.
CISA has added CVE-2021-26829 to its Known Exploited Vulnerabilities (KEV) catalog.
Five flaws in the open source tool may lead to path traversal attacks, remote code execution, denial-of-service, and tag manipulation.
CISA has added CVE-2025-61757 to its Known Exploited Vulnerabilities (KEV) catalog.
CVE-2025-61757 is an unauthenticated remote code execution vulnerability affecting Oracle Identity Manager.
The vulnerabilities could be exploited to cause a denial-of-service (DoS) condition, execute arbitrary code, or access arbitrary files and directories.
SquareX claims to have found a way to abuse a hidden Comet API to execute local commands, but Perplexity says the research is fake.
Researchers demonstrated a now-patched vulnerability that could have been used to enumerate all WhatsApp accounts.
A proof-of-concept (PoC) exploit targeting the high-severity remote code execution (RCE) bug exists.
SolarWinds Serv-U is affected by vulnerabilities that can be exploited for remote code execution.
An OS command injection flaw, the exploited zero-day allows attackers to execute arbitrary code on the underlying system.
The total amount of money given to bug bounty hunters by the social media giant has reached $25 million.
The flaw was reported by Google's Threat Analysis Group and was likely exploited by a commercial spyware vendor.
The exploitation of the recent XWiki vulnerability has expanded to botnets, cryptocurrency miners, scanners, and custom tools.
Security firms say the flaw has been actively exploited for weeks, even as Fortinet quietly shipped fixes and CISA added the bug to its...
Other noteworthy stories that might have slipped under the radar: EchoGram attack undermines AI guardrails, Asahi brewer still crippled after ransomware attack, Sora 2...