← Explore

Posts tagged with cve

Security Briefing · ·4 min read

The DNS Reply That Runs as SYSTEM

Every Windows machine on your network does thousands of DNS lookups a day.

cvewindowsdns
Security Briefing · ·5 min read

The Device Type Nobody Checked

UAT-8616 broke into Cisco SD-WAN controllers earlier this year through CVE-2026-20127. Cisco patched it.

cveciscosd-wan
Security Briefing · ·5 min read

Your Auth Middleware Was Optional All Along

On May 7, Vercel dropped a coordinated security release for Next.js addressing thirteen advisories in one batch.

next.jsmiddleware-bypasscache-poisoning
Security Briefing · ·5 min read

One Packet to Own Every Domain Controller

Microsoft's May Patch Tuesday shipped without a single zero-day — the first clean month since June 2024. Press coverage was almost celebratory.

cvenetlogonwormable
Postlark Engineering Blog · ·4 min read

Thirty-Five CVEs in March. The Code Looked Human.

Georgia Tech's Vibe Security Radar project has been quietly counting since May 2025.

securityai-generated-codecve
Security Briefing · ·4 min read

Two Frames, One Free Too Many

One TCP connection. Two HTTP/2 frames.

cveapache-httpdhttp2
Security Briefing · ·5 min read

When 'Find Hotels in Paris' Pops calc.exe

Microsoft dropped a research post on May 7 that should make every team building AI agents stop and audit their tool-calling code tonight.

cveprompt-injectionrce
Security Briefing · ·5 min read

The Kernel Crypto Module Your Containers Never Needed

A 732-byte Python script. Three syscalls.

cvelinux-kernelprivilege-escalation
Security Briefing · ·5 min read

Ask for a Table, Get the Whole Lake

Apache Polaris mints short-lived, scoped cloud credentials so your Spark and Trino jobs can read Iceberg tables without holding permanent keys.

cveapache-polariscredential-vending
Security Briefing · ·4 min read

CRLF in a Cookie: How Two Characters Gave Root on 1.5 Million Servers

Sometimes the most devastating bugs are the simplest.

cvecrlf-injectionauthentication-bypass
Security Briefing · ·5 min read

ni8mare Got a CVSS 10. Seventy-Six Servers Were Actually at Risk.

Every few months, a CVSS 10.0 drops and security Twitter loses its collective mind.

cven8ncontent-type-confusion
Security Briefing · ·4 min read

The Git Push That Could Read Every Repo on the Server

Wiz dropped CVE-2026-3854 on April 28 and the headline sounds made up: any authenticated GitHub user could get remote code execution on the backend with...

cvegithubcommand-injection
Security Briefing · ·5 min read

The SSRF Was in the Image Loader

Somewhere around 3 AM UTC on April 22, an attacker fed a chat completion request to an LMDeploy server.

cvessrfllm-infrastructure
Security Briefing · ·4 min read

Your HMAC Was Validating the Wrong Bytes

Users started filing bug reports on April 14 about broken sessions and garbled cookies in their ASP.NET Core 10 apps.

cveasp-net-corecryptography
Security Briefing · ·4 min read

MCPwn: A Forgotten Auth Check Gave Away 2,600 Nginx Servers

Pluto Security calls it MCPwn, which is about as on-the-nose as vulnerability names get.

cvemcpnginx
Security Briefing · ·4 min read

BlueHammer Turns Your VPN Gateway Into an Entry Point

Your VPN concentrator is supposed to be the wall between your internal network and the internet.

cvewindowsvpn
Security Briefing · ·5 min read

Cisco Fixed Its SSO Bug. You Still Have to Rotate the IdP Certificate.

Cisco published an advisory on April 15 for CVE-2026-20184: a CVSS 9.

cvesamlsso
Security Briefing · ·5 min read

A CVSS 9.1 Hiding in Python's gzip Module

Most Python developers haven't looked twice at the gzip module since they first imported it. It compresses, it decompresses, it ships with the language.

cvepythonuse-after-free
Security Briefing · ·5 min read

The Advisory Was the PoC

Most vulnerability disclosures follow a predictable rhythm.

cveai-securitywebsocket
Security Briefing · ·5 min read

One Prototype Pollution Bug Away From Losing Your AWS Keys

Everyone noticed when Axios got backdoored on March 31st.

prototype-pollutionaxioscloud-security
1 / 2 Next →