Vulnerabilities
Attackers could exploit vulnerable deployments to intercept and tamper with communications in certain configurations.
Hi, what are you looking for?
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
Attackers could exploit vulnerable deployments to intercept and tamper with communications in certain configurations.
On Android, the out-of-bounds write issue can be triggered during the processing of media files without user interaction.
Other noteworthy stories that might have slipped under the radar: Capita fined £14 million, ICTBroadcast vulnerability exploited, Spyware maker NSO acquired.
Set for January 2026 at Automotive World in Tokyo, the contest will have six categories, including Tesla, infotainment systems, EV chargers, and automotive OSes.
CVE-2025-55315 is an HTTP request smuggling bug leading to information leaks, file content tampering, and server crashes.
The unauthenticated local file inclusion bug allows attackers to retrieve the machine key and execute code remotely via a ViewState deserialization issue.
AISLE aims to automate the vulnerability remediation process by detecting, exploiting, and patching software vulnerabilities in real time.
A public PoC existed when Adobe patched the Experience Manager Forms (AEM Forms) bug in early August.
Fortinet and Ivanti have announced their October 2025 Patch Tuesday updates, which patch many vulnerabilities across their products.
Adobe has published a dozen security advisories detailing over 35 vulnerabilities across its product portfolio.
SAP has rolled out additional protections for insecure deserialization bugs resolved in NetWeaver AS Java recently.
It’s unclear if the new Oracle E-Business Suite flaw, which can be exploited remotely without authentication, has been used in the wild.
Patches were rolled out for more than 200 vulnerabilities in Junos Space and Junos Space Security Director, including nine critical-severity flaws.
The unpatched vulnerabilities allow attackers to execute arbitrary code remotely and escalate their privileges.
Apple has announced significant updates to its bug bounty program, including new categories and target flags.
Hundreds of internet-exposed Oracle E-Business Suite instances may still be vulnerable to attacks.
The Medusa ransomware operators exploited the GoAnywhere MFT vulnerability one week before patches were released.
The Year 2036/2038 problem is a bug that will be triggered in more than a decade, but hackers could exploit it today against ICS...
The flaw could lead to local code execution, allowing attackers to access confidential information on devices running Unity-built applications.
Oracle has informed customers that it has patched a critical remote code execution vulnerability tracked as CVE-2025-61882.