Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
(bleepingcomputer.com)
1.
2.
Trend Micro warns of Apex One zero-day exploited in the wild
(bleepingcomputer.com)
3.
Drupal: Critical SQL injection flaw now targeted in attacks
(bleepingcomputer.com)
4.
Max severity Cisco Secure Workload flaw gives Site Admin privileges
(bleepingcomputer.com)
5.
Microsoft warns of new Defender zero-days exploited in attacks
(bleepingcomputer.com)
6.
Hackers bypass SonicWall VPN MFA due to incomplete patching
(bleepingcomputer.com)
7.
Max-severity flaw in ChromaDB for AI apps allows server hijacking
(bleepingcomputer.com)
9.
Microsoft Exchange Zero-Day Under Attack, No Patch Available
(darkreading.com)
10.
Exploit available for new DirtyDecrypt Linux root escalation flaw
(bleepingcomputer.com)
11.
13.
Avada Builder WordPress plugin flaws allow site credential theft
(bleepingcomputer.com)
14.
O(x)Caml in Space
(news.ycombinator.com)
15.
Microsoft warns of Exchange zero-day flaw exploited in attacks
(bleepingcomputer.com)
16.
New Nginx Exploit
(news.ycombinator.com)
17.
Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin
(bleepingcomputer.com)
18.
Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks
(bleepingcomputer.com)
19.
18-year-old NGINX vulnerability allows DoS, potential RCE
(bleepingcomputer.com)
20.
New Fragnesia Linux flaw lets attackers gain root privileges
(bleepingcomputer.com)
21.
CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
(news.ycombinator.com)
22.
Dead.Letter (CVE-2026-45185) – How XBOW found an unauthenticated RCE on Exim
(news.ycombinator.com)
23.
Dead.letter (CVE-2026-45185) Humans vs. LLM for Unauthenticated RCE Race on Exim
(news.ycombinator.com)
24.
Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator
(bleepingcomputer.com)
25.
Incident Report: CVE-2024-YIKES
(news.ycombinator.com)
26.
Dirty Frag: Universal Linux LPE
(news.ycombinator.com)
27.
The React2Shell Story
(news.ycombinator.com)
28.
CISA gives feds four days to patch Ivanti flaw exploited as zero-day
(bleepingcomputer.com)
29.
GNU IFUNC is the real culprit behind CVE-2024-3094
(news.ycombinator.com)
30.
OpenAI launches new voice intelligence features in its API
(techcrunch.com)