Category: Vulnerabilities
Certighost PoC Exploit Lets Low-Privileged Users Hijack Windows Domains via AD CS
Researchers released a working exploit for CVE-2026-54121, an Active Directory Certificate Services flaw that lets an authenticated attacker impersonate a domain controller…
DentaQuest Breach Tied to ShinyHunters Exposes Data on Over 23 Million People
Dental and vision benefits administrator DentaQuest is notifying millions after attackers accessed sensitive health and identity data over a four-day window in…
GitHub and PyPI Roll Out Time-Delay Defenses Against Supply Chain Attacks
GitHub's Dependabot now enforces a default 72-hour cooldown before adopting new package versions, while PyPI blocks file additions to releases older than…
UK PM Burnham Keeps Cyber Minister in Place Despite Ministry Shakeup
New Prime Minister Andy Burnham reappointed Liz Lloyd to steer cyber policy even as he dismantled the department that housed it, preserving…
Rockwell Patches Four Code Execution Flaws in Arena Simulation Software
Rockwell Automation has fixed four high-severity memory corruption vulnerabilities in Arena Simulation that could let an attacker execute arbitrary code via a…
OnTrac Discloses Data Breach After Network Intrusion
The last-mile delivery firm says an attacker accessed files over a three-day span in March, and its response language hints at a…
NodeBB Patches Eight High-Severity Flaws Found by AI Pentest Agents
Aikido Security says its AI-driven code review uncovered eight high-severity vulnerabilities in the NodeBB forum platform in just six hours, exposing admin…
RefluXFS: Nine-Year-Old Linux Kernel Flaw Grants Root via XFS Race Condition
A race condition in the XFS filesystem's reflink copy-on-write path, present since kernel 4.11, lets unprivileged local users overwrite root-owned files and…
Russian APT ‘Laundry Bear’ Exploited Zimbra Zero-Day to Steal Email at Scale
A joint advisory from CISA, NSA, FBI and international partners details a Russian state-supported campaign that used a zero-click Zimbra Collaboration Suite…
Stadler Rail Refuses $12.3M Everest Ransom After Supplier Data Breach
Swiss rail manufacturer Stadler says a breach at a third-party file-sharing platform exposed technical supplier documents, but the company is refusing Everest's…
Check Point Zero-Day Under Active Attack, CISA Sets July 25 Deadline
A critical authentication bypass in Check Point's Security Management and Multi-Domain Management products is being exploited against internet-exposed environments, prompting an emergency…
House Defense Bill Passes With Decade-Long Extension of CISA 2015 Info-Sharing Law
The House approved its version of the 2027 NDAA, which includes a provision to reauthorize the 2015 Cybersecurity Information Sharing Act for…