CISA adds three exploited Cisco, Citrix, and Fortinet flaws to KEV, requiring federal agencies to patch by September 12, 2026 ...
BlueMoon exploit kit, shared by four China-linked spy groups in 12 days, chains Chrome and Windows zero-days to hand ...
MCP is now stateless at the protocol level. The Mcp-Session-Id header and the initialize/initialized handshakes that linked ...
PEEP is described as a post-compromise framework as it lacks an initial access vector itself, meaning it requires the ...
Threat actors have been busy during the first half of 2026, waging various attacks against companies and individuals in Asia ...
Microsoft 365 phishing MFA bypass platform BigBear 2.0 compromised 258 organizations across 40+ countries by using custom ...
New measurements show H3 Max / H3 Max Turbo by fal, return finished video with synchronized audio in less time than the ...
Magento zero-day vulnerability CVE-2026-75650 exploited a fully patched store for three days before Adobe released APSB26-146 on September 7. A self-updating Rust backdoor survived the patch, evaded ...
HAProxy backdoor attributed to North Korea ran undetected inside two South Korean organizations for nine to ten months, using ...
U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog.
Critical ArangoDB flaws let attackers bypass authentication, access data, and gain root-level code execution on vulnerable hosts.
An active exploitation campaign targeting FortiGate firewalls, in which attackers weaponize a critical vulnerability to plant ...