Bludit CMS 3.18.4 - RCE Vulnerability Discovered
Bludit CMS 3.18.4 - RCE Vulnerability 🚨 A Remote Code Execution (RCE) vulnerability has been identified as CVE-2026-25099 in Bludit CMS versions prior to 3.18.4. This exploit, dated 2026-03-28, wa...
Bludit CMS 3.18.4 - RCE Vulnerability 🚨 A Remote Code Execution (RCE) vulnerability has been identified as CVE-2026-25099 in Bludit CMS versions prior to 3.18.4. This exploit, dated 2026-03-28, wa...
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2017-2404 n/a - n/a An issu...
Major Security Vulnerability in Google’s Gemini CLI 🚨 A significant security vulnerability recently threatened Google’s official Gemini-cli repository and its associated GitHub Actions, risking a ...
Dnssec Failure Causes German Internet Blackout 🚨 Millions of German websites went dark, and apps stopped working on Tuesday night as Germany’s top-level domain (TLD) .de became unreachable. For us...
Attackers Adopt JavaScript Runtime Bun to Spread NWHStealer 🚨 In our previous research, we analyzed a Windows infostealer we track as NWHStealer. The attackers behind this stealer are continuously...
Sailor Framework - Chinese Backed Phishing Services Overview: 🚨 The “Sailor Framework” represents a sophisticated phishing service backed by Chinese actors, as reported by the urlscan Threat Rese...
Hacktivists’ DDoS Onslaught Leaves Ubuntu Services Limping Days Later Canonical’s web infrastructure buckled under a massive DDoS barrage last week. The attack, claimed by pro-Iranian hacktivists,...
Google’s Android Apps Get Public Verification to Stop Supply Chain Attacks 🚀 Google has announced expanded Binary Transparency for Android as a way to safeguard the ecosystem from supply chain att...
Before the Breach, There Was a Test Environment Most security conversations begin at the wrong end of the problem. By the time an incident reaches the SOC, the conditions that made it possible hav...
🚨 Trojan Abuses Microsoft Phone Link App to Steal Your Passwords Cisco Talos researchers have revealed the exploits of a Remote Access Trojan (RAT) that can steal your credentials the moment you l...
Kaspersky’s Alarming Discovery 🚨 Security researchers at Kaspersky have identified a malicious backdoor planted in the popular Windows disc imaging software, Daemon Tools. The Russian cybersecurit...
Edge Browser Vulnerability 🚨 A Norwegian researcher has identified a serious issue with Microsoft Edge’s Password Manager that could pose significant risks for businesses. Tom Jøran Sønstebyseter ...
A Rigged Game: ScarCruft Compromises Gaming Platform ESET researchers uncovered a multiplatform supply-chain attack by the North Korea-aligned APT group ScarCruft, targeting the Yanbian region in ...
A Severe Vulnerability Alert 🚨 A severe vulnerability nicknamed ‘Copy Fail’ allows a local user to dig into the guts of the OS and give themselves root privileges merely by writing four bytes of c...
Wiz ZeroDay.Cloud Event Reveals 20-Year-Old PostgreSQL Vulnerabilities 🚀 Cybersecurity researchers participating in Wiz’s ZeroDay.Cloud hacking event in London, England, exploited two critical vul...
The New Ouroboros Technique and How It Fits in dMSA’s Security Model Delegated Managed Service Accounts (dMSAs) were designed to solve a real operational problem: moving services off legacy servic...
Progress Software Addresses Critical MOVEit Automation Bug 🚀 Progress Software has released updates to address two security flaws in MOVEit Automation, including a critical bug that could result i...
DigiCert Hacked with a Malicious Screensaver File 🚨 A threat actor gained access to DigiCert’s backend and stole 27 code signing certificates that were later used to sign malware. The incident too...
Cyber-Secure Philanthropy: Tech Infrastructure for Global Donations Nonprofits move enormous amounts of money across borders. Most of it flows through web forms and third-party processors that wer...
Paying Ransom Won’t Help as VECT 2.0 Ransomware Destroys Data Irreversibly A major coding error in the VECT 2.0 ransomware is permanently destroying victim data, leaving no way for files to be rec...