Latest Briefings
CISA Orders Federal Patch on Actively Exploited LoadMaster Flaw
A critical unauthenticated command injection bug in Progress Kemp LoadMaster is being exploited in the wild after researchers published proof-of-concept code, prompting…
One-Click Flaw in Atlassian’s Rovo AI Let Attackers Hijack Sessions and Exfiltrate Data
Varonis researchers found that a single crafted link could seed attacker instructions into Rovo's chat window, letting the AI assistant's own research…
Metabase Zero-Day Under Active Exploitation Grants Unauthenticated Admin Access
Metabase has disclosed a maximum-severity, uncatalogued flaw in its BI platform that lets remote attackers inject SQL and seize control without credentials,…
Metabase SQL Injection Zero-Day Exploited to Steal Customer Data at Framework, Tally
An unauthenticated SQL injection flaw in Metabase, rated CVSS 10.0, was exploited as a zero-day to breach Metabase Cloud and self-hosted instances,…
CISA Confirms Active Exploitation of Critical TeamCity RCE Flaw CVE-2026-63077
JetBrains patched a critical deserialization vulnerability in on-premise TeamCity servers last week, and CISA has already added it to its Known Exploited…
Cisco Patches Two Dozen Flaws Including Critical FMC Auth Bypass and SD-WAN Bugs
Cisco's latest security update fixes critical vulnerabilities in Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center, including a maximum-severity authentication bypass…
CISA Flags Active Exploitation of Langflow, N-central, and Tomcat Bugs
CISA has added four actively exploited vulnerabilities in IBM Langflow OSS, N-able N-central, and Apache Tomcat to its Known Exploited Vulnerabilities catalog,…
N-able Patches Second Auth Bypass Flaw Under Active Attack on N-central Servers
N-able rushed out a hotfix after discovering that attackers were exploiting an incomplete patch for a prior authentication bypass, granting administrator access…
N-able N-central Flaw Let Attackers Seize Servers After Patch Failed
An authentication bypass in N-able's N-central remote monitoring platform allowed attackers to gain full administrative control and pivot into customer environments, and…
COLDCARD RNG Bug Tied to $88.6M Bitcoin Wallet Heist
A flawed random number generator in COLDCARD hardware wallet firmware let attackers predict private keys offline, enabling a wave of automated thefts…
Rails Patches Critical Active Storage Flaw That Enables Remote Code Execution
A critical arbitrary file read vulnerability in Rails' Active Storage component can expose secrets and escalate to RCE, with public proof-of-concept exploits…
Critical Cosmos DB Flaw Could Have Exposed Every Database on the Service
Wiz researchers found a sandbox escape in Azure Cosmos DB's Gremlin API that led to a platform-wide master key, potentially granting full…