Vulnerabilities
A desync attack method leveraging HTTP/1.1 vulnerabilities impacted many websites and earned researchers more than $200,000 in bug bounties.
Hi, what are you looking for?
Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges.
A desync attack method leveraging HTTP/1.1 vulnerabilities impacted many websites and earned researchers more than $200,000 in bug bounties.
Trend Micro has rushed to fix two Apex One zero-days that may have been exploited by Chinese threat actors.
Microsoft handed out $17 million in rewards to 344 security researchers through its bug bounty programs over the past year.
An AI extension to the Ox Security platform automatically generates organization specific code to fix vulnerabilities in the codebase.
Adobe has released urgent security updates to resolve two AEM Forms vulnerabilities for which proof-of-concept (PoC) code exists.
As AI makes software development accessible to all, security teams face a new challenge: protecting applications built by non-developers at unprecedented speed and scale.
Research demonstrating high-impact cloud and AI security flaws will be rewarded at Microsoft’s Zero Day Quest competition in spring 2026.
Threat actors might be exploiting a zero-day vulnerability in SonicWall firewalls in a fresh wave of ransomware attacks.
Nvidia has patched over a dozen vulnerabilities in Triton Inference Server, including another set of vulnerabilities that threaten AI systems.
Attackers could silently modify sensitive MCP files to trigger the execution of arbitrary code without requiring user approval.
Valid, complete reports detailing remote code execution or elevation of privilege bugs in .NET qualify for the maximum rewards.
Meta is sponsoring ZDI’s Pwn2Own hacking competition, where participants can earn big prizes for smartphone, WhatsApp and wearable device exploits.
Google Project Zero now publicly shares the discovery of a vulnerability and when its 90-day disclosure deadline expires.
Tracked as CVE-2025-6558, the flaw was found in Chrome’s ANGLE and GPU components and was flagged as exploited by Google TAG.
The TCC bypass could expose information cached by Apple Intelligence, including geolocation and biometric data.
Threat actors are exploiting a two-year-old vulnerability in PaperCut that allows them to execute arbitrary code remotely.
The Post SMTP email delivery WordPress plugin is affected by a critical vulnerability and half of websites using it remain unpatched.
An authentication bypass vulnerability in Mitel MiVoice MX-ONE could allow attackers to access user or admin accounts on the system.
LG Innotek LNV5110R security cameras are affected by a vulnerability that can be exploited for unauthenticated remote code execution.
SonicWall advises organizations to patch SMA 100 appliances and look for IoCs associated with Overstep malware attacks.