Atlassian Rovo prompt injection can send Jira and Confluence data to attacker servers. One path is fixed; another remained ...
CISA adds Progress Kemp LoadMaster CVE-2026-8037 to KEV after active exploitation reports, with 792 attempts logged across 65 ...
Outlook CSS techniques can spoof Microsoft sign-in and capture passwords, while Gmail image-set() can trigger external ...
UNC6671 uses vishing and AitM phishing to steal cloud credentials and MFA tokens, then exfiltrate data from Microsoft 365, ...
ClickFix attacks deliver a Go-based macOS stealer that steals passwords and Keychain data and can drain part or all of ...
Metabase says a CVSS 10.0 zero-day SQL injection was exploited in the wild; the flaw can grant admin access and expose ...
N-able releases N-central Hotfix 2 amid CVE-2026-18577 exploitation that gave attackers admin access and persistent access to managed systems.
Open source may split as the EU Cyber Resilience Act and enterprise security demands favor reachable, patchable, accountable ...
Oligo links TeamPCP activity back to Redis attacks in 2020, tracing its shift from cloud exploitation to open-source supply ...
NatJack abuses NAT state to hijack TCP sessions and spoof DNS responses; Windows and Linux flaws are tracked under two CVEs.
WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under ...
Gemini CLI and Claude Code flaws let untrusted GitHub input reach CI workflows, including host command execution and API key ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results