← Explore

Posts tagged with cve

Security Briefing · ·4 min read

One Packet, No Password, Full Shell

Microsoft patched CVE-2026-62815 on August 11. CVSS 9.

cvequichttp3
Security Briefing · ·5 min read

Microsoft Said 'Less Likely.' ZDI Said 'Wormable.'

Microsoft and the Zero Day Initiative looked at the same vulnerability this week and reached very different conclusions.

cvewindows-dnswormable
Security Briefing · ·5 min read

One Missing '\0' Turned a Load Balancer Into a Shell

Progress patched CVE-2026-8037 on June 4th with a two-line diff. One line changed malloc() to calloc().

cvecommand-injectionmemory-safety
Security Briefing · ·5 min read

Broadcom Called It an Emergency Change. They Weren't Kidding.

Broadcom's security advisories tend toward the corporate neutral — "we recommend applying the latest update at your earliest convenience.

vmwarevcenteresxi
Security Briefing · ·5 min read

They Didn't Need Malware. They Had Your RMM.

N-able patched an authentication bypass in N-central back in April.

cvermm-securityauthentication-bypass
Neural Dispatch · ·5 min read

A Hacker Sent One Telegram Message. DeepSeek Did the Rest.

Palo Alto Networks just published the most detailed look yet at what happens when someone deliberately weaponizes an AI coding agent.

deepseekai-securityhermes-agent
Security Briefing · ·5 min read

A Gremlin Query Escaped the Sandbox. It Came Back With Every Customer's Keys.

Wiz Research just publicly disclosed CosmosEscape, a vulnerability chain that let any Azure subscriber escalate from a standard Gremlin database to full...

azure-cosmos-dbsandbox-escapecloud-security
Security Briefing · ·5 min read

233 Tools, One Open Port, No Password

Ruflo is one of those projects that grew fast enough to skip the security review.

mcp-securitycveai-agent-security
Security Briefing · ·4 min read

Someone Uploaded an Image. Rails Handed Back the Master Key.

Someone uploaded a profile picture. The server responded with a valid image — 400×300 pixels of what looked like static noise.

cveruby-on-railsactive-storage
Neural Dispatch · ·5 min read

An Open Model Found Redis Zero-Days in 27 Minutes

A security researcher pointed Kimi K3 at a Redis 8.8.

rediszero-dayoffensive-security
Security Briefing · ·4 min read

A Trailing Dot Turned Your Rewrite Rule Into an Open Proxy

Last Monday, the Next.js team shipped patches for nine security vulnerabilities across v15.

nextjsssrfcve
Security Briefing · ·4 min read

The Guest Sent a Packet. The Host Gave Up SYSTEM.

A developer running WSL2 to test a container has the same VMSwitch code loaded as a production Hyper-V cluster hosting hundreds of tenants.

cvehyper-vuse-after-free
Security Briefing · ·4 min read

A Single Prompt Launched calc.exe on the Host

Prompt injection stopped being a content problem the moment someone typed a sentence into an AI agent and calc.exe opened on the host machine.

prompt-injectionremote-code-executionsemantic-kernel
Security Briefing · ·4 min read

DHCP Hands Out IP Addresses. Now It Hands Out SYSTEM.

Every network has a DHCP server. Most teams treat it like plumbing — invisible until it breaks.

cvewindows-dhcpheap-overflow
Security Briefing · ·4 min read

Defender's Own Quarantine Pipeline Gave Attackers SYSTEM

Microsoft pushed Malware Protection Engine version 1.1.

cveprivilege-escalationmicrosoft-defender
Security Briefing · ·5 min read

Adobe Patched Six Perfect 10s. Attackers Needed Two Hours.

Adobe shipped patches for eleven ColdFusion vulnerabilities on June 30. Six hit the maximum CVSS score of 10.

cvecoldfusionpath-traversal
Security Briefing · ·5 min read

The RMM That Trusted Every Token

Somewhere around late May, an attacker pointed a browser at a SimpleHelp server, submitted a self-signed JWT to the OIDC callback endpoint, and walked away...

cveauthentication-bypasssupply-chain
Security Briefing · ·5 min read

Site Members Can Run Code on Your SharePoint Server

CISA gave federal agencies until July 4 to patch CVE-2026-45659 — a SharePoint Server deserialization flaw that's been actively exploited in the wild.

cvesharepointdeserialization
Security Briefing · ·5 min read

Six Years Later, Netlogon Still Can't Count Bytes

Netlogon was supposed to be a solved problem.

cvewindowsnetlogon
Security Briefing · ·5 min read

Ghost CMS Lost 700 Sites to a String Interpolation Bug

SQL injection was supposed to be a solved problem. Parameterized queries have existed for decades.

cvesql-injectionghost-cms
1 / 3 Next →