Category: Vulnerabilities
New SynkLoader Malware Spread via Fake IT Help Desk Teams Phishing
A newly identified malware family called SynkLoader is being pushed through Microsoft Teams phishing attacks that impersonate corporate IT support, using a…
Microsoft Warns of Max-Severity Entra ID RCE Flaw Exploited in the Wild
Microsoft disclosed a CVSS 10.0 remote code execution vulnerability in Entra ID that has already been exploited, though it says customers do…
Critical Elementor Pro Flaw Lets Attackers Upload PHP and Execute Code
A CVSS 9.0 vulnerability in Elementor Pro's File Upload module lets attackers smuggle malicious PHP past validation and execute it on WordPress…
US Agencies Warn of AI-Generated Exploits Hitting Siemens S7 PLCs
NSA, CISA, FBI, DOE, and EPA say threat actors are using AI to build Python exploitation tools disguised as OT monitoring software,…
Citrix Patches Critical NetScaler Auth Bypass, Exploitation Expected Soon
A critical authentication bypass flaw in NetScaler ADC and Gateway lets unauthenticated attackers slip past login controls, and Rapid7 warns active exploitation…
Sakura Internet Breach Now Estimated to Affect 1.36 Million Accounts
A separate investigation into a rental server hack uncovered a much larger intrusion into Sakura Internet's sales management system, potentially exposing customer…
Firefox 154 and Chrome 151 Patch Dozens of High and Critical Severity Bugs
Mozilla and Google shipped major browser updates this week, fixing 58 vulnerabilities in Firefox and 15 in Chrome, including several memory safety…
Windows 11 24H2 Home and Pro Lose Security Updates in Two Months
Microsoft is warning that Windows 11 24H2 Home and Pro editions, along with Windows 10 Enterprise LTSB 2016, will stop receiving updates…
Apple Patches Dozens of WebKit Flaws in New macOS, iOS Security Updates
Apple released macOS Tahoe 26.6.2, iOS 26.6.1, iPadOS 26.6.1, and legacy iOS/iPadOS 18.7.10 updates fixing dozens of WebKit bugs alongside kernel and…
Microsoft Begins Stripping WMIC LOLBIN From Windows 11
Microsoft has removed the legacy WMIC command-line tool from Windows 11 24H2, 25H2, and current beta builds, closing off a utility long…
Critical SAP Commerce Cloud Flaw Exploited Just Days After Patch Release
A maximum-severity vulnerability in SAP Commerce Cloud, CVE-2026-58231, is already under active attack after threat intelligence firms spotted exploitation attempts within days…
SafePal Breach Exposes Order Data for Nearly 40,000 Crypto Wallet Customers
An authorization flaw in a third-party order-tracking plug-in let an attacker scrape SafePal customer order details, and the stolen data is now…