The vulnerability is CVE-2024-21182 and it can be exploited without authentication to hack affected WebLogic servers.
Hi, what are you looking for?
The vulnerability is CVE-2024-21182 and it can be exploited without authentication to hack affected WebLogic servers.
Dashlane’s security systems automatically locked accounts to protect them against the hacking attempts.
Novee researchers discovered an account takeover vulnerability in the open source CFP management tool Pretalx.
Catalin Dragomir previously pleaded guilty to selling access to an Oregon state government office’s network.
The attack was claimed by a hacktivist group, but evidence showed it used infrastructure linked to Iranian government threat actors.
The AI giant says the new plugin, which helps developers find vulnerabilities as they write code, has been used extensively internally.
Notable integrations include CrowdStrike, Palo Alto Networks, Microsoft, Okta, Zscaler, Netskope, Cloudflare, Fortinet, and Wiz.
Sites belonging to major universities such as Harvard and Oxford, as well as DuckDuckGo, have been compromised in the attack.
The affected third-party vendor has not been named, but one possible candidate is TriZetto.
Many findings have been confirmed to be critical or high-severity vulnerabilities and the number will continue to increase.
Drupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites.
Jacob Butler, 23, has been arrested in Canada and US authorities are seeking his extradition on computer hacking charges.
The FBI says First VPN has been used by dozens of ransomware groups for network reconnaissance and intrusions.
CVE-2026-34926 is a directory traversal flaw that can be exploited against the on-premise version of Apex One.
CVE-2026-9082 can be exploited without authentication for information disclosure, privilege escalation, and remote code execution.
More than 200 vulnerabilities patched in recent Chrome releases are marked as ‘reported by Google’.
The researcher who found it says the vulnerability could have been chained with a prompt injection to exfiltrate data.
SecurityWeek spoke with several ICS security experts and companies about their most memorable experiences in the field.
Drupal says attackers may develop an exploit for the vulnerability within hours or days.
Fox Tempest provides a service that cybercriminals use to distribute ransomware and other malware disguised as legitimate software.