Latest Briefings
Critical Joomla Extension Flaws Under Active Exploitation, CISA Adds to KEV
Unauthenticated file upload vulnerabilities in the Balbooa Forms and iCagenda Joomla extensions, both scoring a maximum CVSS of 10, are being exploited…
Attackers Exploit Critical Auth Bypass in Gitea’s Official Docker Image
A misconfigured default in Gitea's Docker image lets unauthenticated attackers impersonate any user, including admins, and exploitation began before public disclosure.
Critical Zimbra Classic Web Client Flaw Lets Emails Execute Malicious Code
Zimbra is pushing urgent updates for a critical stored XSS vulnerability in its Classic Web Client that lets specially crafted emails run…
Zimbra Patches Critical XSS Flaw in Classic Web Client After Google TAG Report
Zimbra has released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, flagged by Google's Threat Analysis…
Injective Labs npm SDK Backdoored to Steal Crypto Wallet Keys
Attackers compromised a contributor's GitHub account to publish a malicious version of the @injectivelabs/sdk-ts package, silently harvesting private keys and seed phrases…
GigaWiper Backdoor Combines Disk Wiping, Fake Ransomware, and Spyware
Microsoft has analyzed a modular Windows backdoor called GigaWiper that fuses three distinct destructive capabilities into a single operator-controlled toolkit.
Chrome 150 Patches 27 Vulnerabilities, Including Two Critical Flaws
Google's Chrome 150 update addresses 27 security vulnerabilities, with two critical use-after-free bugs in the Ozone and Views components leading the list.…
Prompt Injection Flaw in GitHub Agentic Workflows Can Expose Private Repos
A vulnerability dubbed GitLost allows unauthenticated attackers to leak private repository contents by hiding malicious instructions inside a public GitHub Issue, requiring…
Google Dialogflow CX Flaw Let Attackers Hijack AI Chatbot Conversations
A vulnerability dubbed Rogue Agent allowed an attacker with edit access to one Dialogflow CX agent to silently compromise all Code Block-enabled…
Critical Gitea Auth Bypass Flaw Under Active Exploitation
A critical vulnerability in Gitea's Docker images allows attackers to impersonate any user with a single HTTP header. Exploitation began just 13…
Januscape: 16-Year-Old Linux KVM Flaw Enables VM Escape on Intel and AMD
A use-after-free bug in the Linux kernel's KVM shadow MMU lets an attacker with guest root access execute code on the host,…
Hidden Backdoor in Tenda Router Firmware Grants Admin Access
A hardcoded secondary authentication mechanism in multiple Tenda router firmware versions allows any attacker who knows the backdoor password to gain full…