The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations.
Hi, what are you looking for?
The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations.
Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality.
Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days.
The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication.
The company plans to expand its research team, open new offices in Rome and San Francisco, and acquire new clients.
A threat actor has been using the compromised appliances to target the Microsoft 365 accounts of traveling corporate employees.
In May 2026, hackers stole personal and dental health information from DentaQuest’s computer network.
The startup will use the fresh investment to accelerate its go-to-market strategy and to expand its platform.
Using AI, the startup provides adaptive prevention through environment mapping, risk analysis, and automated policy enforcement.
The startup will use the investment to accelerate the development of its threat prediction and discovery products.
Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop.
Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025.
Using social engineering, hackers compromised employee accounts with access to personal and health information.
The latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects.
Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory.
Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform.
Targeting production infrastructure, the attack compromised internal datasets and service credentials.
The fresh security update resolves six critical and high-severity use-after-free vulnerabilities.
The startup helps organizations detect, hunt, and protect their assets across environments at machine speed.
The company disconnected its systems on July 13 and is starting to gradually restore operations.