Three proof-of-concept exploits are being used in active attacks against Microsoft’s built-in security platform; two are unpatched.
Latest
The critical remote code execution flaw (CVE-2026-1731) in the remote monitoring and management tool can be exploited...
The prompt-injection vulnerability in the agentic AI product for filesystem operations was a sanitization issue that allowed...
A newly discovered malware called Lotus Wiper has been used in a targeted destructive attack against the...
A new Kyber ransomware operation is targeting Windows systems and VMware ESXi endpoints in recent attacks, with...
Cybersecurity researchers have flagged a fresh set of packages that have been compromised by bad actors to...
A North Korea-linked threat group is quietly getting hired by real companies. Jasper Sleet, a threat actor...
Project: Drupal core Date: 2026-April-15 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Cross-site scripting Affected versions: >=...
Project: Drupal core Date: 2026-April-15 Security risk: Moderately critical 14 ∕ 25 AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:Uncommon Vulnerability: Gadget Chain Affected versions: >=...
Critical Severity Description A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed...
