WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS.
Progress disclosed a critical command injection flaw that lets malicious OpenAPI or Swagger documents execute OS commands.
Attackers are exploiting two AhsayCBS flaws to deploy web shells and XMRig miners, and Huntress says version 10.3.4 remains ...
Before a business can trust an agent acting on someone’s behalf, it needs confidence in the identity behind that authority.” — Hartley Thompson, CEO of Microblink BROOKLYN, NY, UNITED STATES, October ...
CISA issued three ICS advisories spanning widely deployed energy and communications technologies, Canada flagged a Johnson Controls camera software command-injection flaw, and a joint U.S. advisory ...
SonicWall fixed four SMA1000 flaws, including a 10.0-rated SSRF reachable before authentication; it says none are known to be ...
Nozomi reports that Cling botnet uses STUN traffic to conceal command-and-control activity and attacks against vulnerable IoT ...
Exploitation of CVE-2026-73570, an unauthenticated OS command injection in Zimbra, started shortly after patches rolled out.
Splunk has disclosed a critical vulnerability in Splunk Enterprise that allows unauthenticated attackers to execute operating ...
Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup ...
NVIDIA patched 14 vulnerabilities in Infrastructure Controller for Linux that enable code execution, data tampering, information disclosure.