Category: Vulnerabilities
New CSS Attacks Break Out of Email Boundaries to Steal Webmail Credentials
Researcher demonstrates how CSS embedded in email content can escape message boundaries across major webmail providers, enabling credential theft, token leaks, and…
Metabase SQL Injection Zero-Day Exploited to Steal Customer Data at Framework, Tally
An unauthenticated SQL injection flaw in Metabase, rated CVSS 10.0, was exploited as a zero-day to breach Metabase Cloud and self-hosted instances,…
Truck Brake Recall Quietly Patched Wireless RCE Flaws, Researcher Says
NMFTA researchers reverse-engineered firmware from a 2024 Bendix EC80 safety recall and found it fixed multiple undisclosed vulnerabilities, including a wirelessly reachable…
CISA Confirms Active Exploitation of Critical TeamCity RCE Flaw CVE-2026-63077
JetBrains patched a critical deserialization vulnerability in on-premise TeamCity servers last week, and CISA has already added it to its Known Exploited…
Cisco Patches Two Dozen Flaws Including Critical FMC Auth Bypass and SD-WAN Bugs
Cisco's latest security update fixes critical vulnerabilities in Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center, including a maximum-severity authentication bypass…
ChainDrop Worm Infects 400+ NPM Packages in New Shai-Hulud Wave
A compromised maintainer account touched off a self-propagating supply chain attack that republished over 2,200 malicious package versions across the NPM ecosystem,…
CISA Flags Active Exploitation of Langflow, N-central, and Tomcat Bugs
CISA has added four actively exploited vulnerabilities in IBM Langflow OSS, N-able N-central, and Apache Tomcat to its Known Exploited Vulnerabilities catalog,…
N-able N-central Flaw Let Attackers Seize Servers After Patch Failed
An authentication bypass in N-able's N-central remote monitoring platform allowed attackers to gain full administrative control and pivot into customer environments, and…
Chrome Set to Block Policy-Abused New Tab Hijacker Extensions
Google is developing a Chromium feature that stops malware from abusing enterprise policy mechanisms to force-install extensions that hijack the New Tab…
COLDCARD RNG Bug Tied to $88.6M Bitcoin Wallet Heist
A flawed random number generator in COLDCARD hardware wallet firmware let attackers predict private keys offline, enabling a wave of automated thefts…
Rails Patches Critical Active Storage Flaw That Enables Remote Code Execution
A critical arbitrary file read vulnerability in Rails' Active Storage component can expose secrets and escalate to RCE, with public proof-of-concept exploits…
Amgen Discloses Cloud Breach Exposing Patient Health Data and Proprietary Information
The biotech giant says threat actors exfiltrated corporate and patient data from multiple third-party cloud environments, prompting an SEC filing and an…