Category: Vulnerabilities
Opera Adds Paste Protect to Block ClickFix Clipboard Attacks
Opera's new Paste Protect feature intercepts malicious commands before they reach the clipboard, offering browser-level defense against the increasingly popular ClickFix social…
CISA Warns of Auth Bypass and CSRF Flaws in iDirect Satellite Terminals
Two high-severity vulnerabilities in ST Engineering iDirect iQ-Series terminals could expose sensitive satellite credentials and allow unauthenticated denial-of-service attacks. Patches are available…
CISA Warns of Critical Hardcoded Credential Flaw in Gardyn IoT Hub
Three vulnerabilities in Gardyn's IoT Hub platform, including a CVSS 10 hardcoded credential bug, could let unauthenticated attackers access and control connected…
CISA Advisory: CubeSpace Reaction Wheel Vulnerable to Unsigned Firmware Upload
A missing cryptographic signature check in CubeSpace CW0057 Reaction Wheel firmware lets a physically present attacker flash arbitrary firmware. A patch is…
Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
Adobe released security updates for ColdFusion and Campaign Classic addressing 12 vulnerabilities, including seven rated at maximum severity with CVSS scores of…
CISA Adds Exploited SharePoint RCE Flaw to KEV, Orders Federal Patch
A high-severity deserialization vulnerability in Microsoft SharePoint is now actively exploited, prompting CISA to mandate federal agencies patch within three days under…
Quest NetVault Backup SQL Injection Flaw Enables Remote Code Execution
A high-severity SQL injection vulnerability in Quest NetVault Backup allows authenticated attackers to execute arbitrary code remotely, with the added complication that…
Unraid File Upload Flaw Enables Authenticated RCE, Patched in 7.3.0
A command injection vulnerability in Unraid's FileUpload.php allows authenticated remote attackers to execute arbitrary code. A fix is available in Unraid version…
X.Org Server Use-After-Free Bug Enables Local Privilege Escalation to Root
A use-after-free vulnerability in X.Org Server's SyncAwait object handling allows a local attacker with low privileges to escalate to root. A patch…
Kubota North America Breach Exposed Employee Data Over 35 Days
Kubota North America has disclosed a network intrusion lasting more than a month that exposed sensitive personal and financial data belonging to…
Medtronic Notifies Customers After ShinyHunters Breach Exposed 9M Records
Medical device giant Medtronic is sending breach notifications after the ShinyHunters extortion group accessed corporate IT systems in April, potentially exposing names,…
CISA Adds SharePoint RCE Flaw CVE-2026-45659 to KEV Catalog
CISA has added a high-severity Microsoft SharePoint Server remote code execution vulnerability to its Known Exploited Vulnerabilities catalog after confirming active exploitation…