Category: Vulnerabilities
BigCommerce Merchants Hit by Data Breach Tied to Compromised Ribon App Keys
Attackers stole credentials for the third-party Ribon apps and used them to inject malicious scripts and access shopper data across multiple BigCommerce…
CISA: Three Linux Kernel Flaws Under Active Attack, One Critical
CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, including a 14-year-old race condition and a critical TLS flaw,…
Critical Pre-Auth RCE in Orkes Conductor Exploited in the Wild
Fortinet warns that a critical unauthenticated remote code execution flaw in the Orkes Conductor workflow platform is being actively exploited, putting unpatched…
Maximum-Severity Cisco ISE Auth Bypass Added to CISA’s Exploited Vulnerability List
A perfect 10.0 CVSS flaw in Cisco Identity Services Engine is being actively exploited in the wild, prompting CISA to order federal…
Public Exploits Released for Four Linux Kernel Local Root Flaws
A researcher has published working exploit code for four separate Linux kernel vulnerabilities that allow a local user to escalate to root,…
Gyazo Breach Exposes 23.6 Million User Records After Server Flaw Exploited
Attackers exploited a vulnerability in Gyazo's image upload server to access a database containing tens of millions of user records and hundreds…
Cisco Patches Max-Severity ISE Zero-Day Under Active Exploitation
A CVSS 10.0 authentication bypass in Cisco Identity Services Engine and ISE-PIC is being actively exploited, letting unauthenticated attackers gain root-level access…
Check Point Patches Critical Root RCE Flaw in Management Servers
An unauthenticated attacker could exploit a buffer overflow in the login process of Check Point's Security Management and Log Servers to gain…
Google Patches Actively Exploited Pixel Modem Zero-Day, CISA Mandates Fix
A high-severity, zero-click flaw in the Pixel's cellular modem was exploited in targeted attacks before Google shipped a fix, prompting CISA to…
Windows 11 KB5124008 Update Breaks Domain Trust for Enterprise Devices
Microsoft is investigating reports that the KB5124008 security update severs the secure channel between domain-joined Windows 11 PCs and Active Directory, locking…
Windows Server 2022 Mainstream Support Ends October 13, 2026
Microsoft is reminding administrators that Windows Server 2022 exits mainstream support next month, shifting to extended security-only updates through October 2031.
Attackers Exploit WooCommerce Plugin Flaw to Plant PHP Web Shells
A critical unauthenticated file-upload vulnerability in the WooCommerce Wholesale Lead Capture plugin is being actively exploited to drop PHP backdoors on WordPress…