A critical vulnerability in Microsoft Copilot Personal, tracked as CVE-2026-24301 and nicknamed CoSnitch, lets attackers silently siphon sensitive data…
Tag: Vulnerability
Cl0p Hackers Exploit PTC Windchill Vulnerability to Deploy Custom Web Shell and Steal Data
The Cl0p ransomware and extortion operation is likely exploiting a critical PTC Windchill vulnerability to deploy a purpose-built Java web shell that can…
Microsoft’s August Patch Tuesday: 400+ Bugs Fixed, One Zero-Day Under Attack
Microsoft’s August Patch Tuesday fixes about 400 security flaws, including an actively exploited Windows zero-day and multiple 9.8-rated RCE bugs.
Critical MLflow SSRF Vulnerability Exploited by Hackers in the Wild
Threat actors are actively exploiting a critical, unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, the popular open-source…
AI-Driven Vulnerability Surge Breaks the Traditional Patching Model
Rapid7 warns that traditional patch cycles cannot keep pace with soaring vulnerability disclosures and faster exploitation, forcing defenders to…
SAP Commerce Cloud CVE-2026-58231 Under Active Exploitation
SAP Commerce Cloud is facing active exploitation of a critical security vulnerability that carries the maximum severity rating.
China-Nexus APT Exploits VMware vCenter CVE-2026-59310
Cybersecurity researchers have identified active exploitation of a critical VMware vCenter Server vulnerability by a suspected Chinese state-sponsored…
CISA Warns of Ray-Project Ray Code Injection Vulnerability Exploited in Attacks
CISA has added a critical Ray-Project Ray vulnerability, tracked as CVE-2025-62593, to its Known Exploited Vulnerabilities catalog after confirming…
AI-powered vulnerability clearinghouse faces deep skepticism, major challenges
The U.S. government’s promises about the “Gold Eagle” coordination program are overblown, experts said, but the initiative could help organizations…
Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)
GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The…
CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.…
Critical WordPress Plugin Vulnerability Exposes 600,000 Sites to File Upload Attacks
A critical security flaw in the Forminator Forms WordPress plugin could allow unauthenticated attackers to upload malicious PHP files, potentially…
GitLab Patches Critical Unauthenticated GraphQL Vulnerability
GitLab patched a critical GraphQL flaw that let unauthenticated attackers remotely modify or delete public projects on self-managed servers. GitLab pushed…
GitLab Patches Critical Code Injection Vulnerability
The security defect allows unauthenticated attackers to modify or delete user data and public projects.
Critical GitLab GraphQL Vulnerability Allow Attackers to Delete Public Projects
GitLab has released urgent security updates to fix a critical GraphQL vulnerability that could allow unauthenticated attackers to modify or delete public…
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415…
Public Exploit Code Released for Microsoft SCCM Remote Code Execution Vulnerability
Public proof-of-concept exploit code is now available for CVE-2026-47301, a critical remote code execution vulnerability affecting Microsoft Configuration…
PoC Exploit Released for Microsoft SCCM Vulnerability Enabling SYSTEM-Level Code Execution
A recently disclosed proof-of-concept (PoC) exploit for Microsoft Configuration Manager, previously known as System Center Configuration Manager (SCCM),…
GitLab Released GraphQL Vulnerability (CVE-2026-19478) Emergency Patch
GitLab released an emergency, out-of-band security update to address a critical access control flaw affecting self-managed instances of…
600,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Forminator Forms WordPress Plugin
On July 14th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Forminator Forms, a WordPress plugin with more…
