CISA Adds Microsoft Exchange XSS Flaw To KEV Catalog
CISA adds Microsoft Exchange Server XSS vulnerability to KEV Catalog amid active exploitation. Federal agencies have a deadline—but all orgs should patch now.
CISA adds Microsoft Exchange Server XSS vulnerability to KEV Catalog amid active exploitation. Federal agencies have a deadline—but all orgs should patch now.
Drupal drops emergency security update May 20. If you’re running a Drupal site, clear your calendar. The wording alone should have admins on high alert.
Law enforcement and cybersecurity partners have successfully disrupted the SocGholish malware distribution network, severing a critical access pathway used by the notorious Evil Corp cybercrime syndicate. The takedown targeted the Traffic Distribution System (TDS) infrastructure responsible for deli
Modern AI-powered email security systems are falling victim to decades-old text obfuscation techniques, allowing spam and phishing messages to bypass advanced machine learning filters. Attackers are successfully weaponizing simple character substitution, Unicode manipulation, and whitespace injectio
Microsoft has officially confirmed a critical zero-day vulnerability dubbed “RoguePlanet” affecting Microsoft Defender across multiple Windows versions. The flaw allows attackers to bypass real-time protection and execute malicious code without detection. Active exploitation has been observed in the
Anthropic’s Mythos AI isn’t just finding bugs—it’s chaining them into working exploits. Cloudflare’s tests show we’ve crossed a new threshold in automated vuln research.
A critical authentication bypass vulnerability in HP Poly VoIP phones (CVE-2024-41937) allows unauthenticated attackers to gain administrative access to affected devices. With a CVSS score of 9.8, this flaw affects multiple Poly phone models widely deployed across enterprise environments. Attackers
Tata Electronics, a key supplier for tech giants Apple and Tesla, has confirmed a significant data breach after threat actors claimed to have exfiltrated 630GB of sensitive corporate data. The leak allegedly contains proprietary manufacturing information, employee records, and confidential business
Palo Alto Networks has issued an urgent warning about active exploitation of CVE-2024-0257, a critical VPN bypass vulnerability in PAN-OS. The flaw allows unauthenticated attackers to bypass authentication mechanisms in GlobalProtect VPN implementations, potentially granting unauthorized network acc
A critical privilege escalation vulnerability in Veeam Backup & Replication allows authenticated attackers to gain SYSTEM-level privileges on affected servers. The flaw, tracked as CVE-2025-23120, impacts multiple versions of the widely-deployed enterprise backup solution and could enable attackers