#vulnerability


Hackers Are After the Gaps in Your Vulnerability Program: Here’s Their Playbook

Jun 4, 2026 // 17:16

A forum thread titled “Hacking for Profit. Working method” offers a rare glance into how underground communities pass information about vulnerability exploitation and hacking techniques […]

Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes

Jun 3, 2026 // 13:24

Cybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a user’s NTLMv2 hash to the attacker. Like in the […]

New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare

Jun 3, 2026 // 11:39

Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora. The vulnerability […]

AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.

Jun 2, 2026 // 15:04

AI-driven exploitation timelines are rapidly shrinking, and they are not going to stop shrinking. Vulnerabilities are being discovered, reproduced, and weaponized faster than ever in […]

Race Against Time: Why Faster Vulnerability Alerts Matter

Jun 1, 2026 // 17:16

A critical RCE vulnerability is disclosed in a widely used VPN application. Your company’s vulnerability alert service (if you even have one) is yet to […]

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

May 29, 2026 // 21:09

Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant’s implicit trust in Markdown links and images […]

Gitea Vulnerability Exposes Private Container Images without Authentication

May 27, 2026 // 13:08

Cybersecurity researchers have disclosed a security flaw in Gitea, an open-source, self-hosted platform for version control, that allows unauthenticated remote attackers to pull private container […]

CISA orders feds to patch actively exploited Drupal vulnerability

May 27, 2026 // 00:39

CISA has given U.S. government agencies until Wednesday evening to secure their servers against an SQL injection vulnerability in the Drupal content management system (CMS) […]

DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability

May 19, 2026 // 18:00

Proof-of-concept (PoC) exploit code has now been released for a recently patched security flaw in the Linux kernel that could allow for local privilege escalation […]

Microsoft rejects critical Azure vulnerability report, no CVE issued

May 16, 2026 // 23:57

A security researcher claims Microsoft quietly fixed an Azure Backup for AKS vulnerability after rejecting his report, and blocking a CVE from being issued. The researcher’s […]

Previous 1 2 3 4 5 … 8 Next