A high-severity vulnerability in Microsoft Defender, tracked as CVE-2026-33825, allows attackers with low-level local access to escalate...
Cyber Attack
A maximum-severity vulnerability in the paperclipai server npm package enables any remote, unauthenticated attacker to execute arbitrary...
A moderate-severity path traversal flaw in the vite-plus The npm package (CVE-2026-41211) allows programmatic callers to escape the designated...
A newly disclosed vulnerability in RustFS, the Rust-based distributed object storage system, allows any low-privileged authenticated user...
The Progress Telerik team has confirmed a critical deserialization flaw tracked as CVE-2026-6023, affecting Progress Telerik UI for...
A critical unauthenticated remote code execution (RCE) vulnerability, tracked as CVE-2026-39808, has been publicly disclosed in Fortinet’s...
Attackers hijacked official Checkmarx KICS Docker Hub images and VS Code extensions to steal cloud credentials silently,...
Threat actors are actively exploiting a command injection vulnerability in discontinued D-Link DIR-823X routers to deploy a...
A critical authentication bypass vulnerability has been disclosed in OAuth2 Proxy (CVE-2026-40575), allowing unauthenticated remote attackers to...
A critical security vulnerability has been disclosed in Spring Security Authorization Server, exposing enterprise Java applications to...