Vulnerabilities & Exploits
CVEs, zero-days, patching and exploited weaknesses.
BeyondTrust Warned Customers to Patch Two Critical Security Flaws in Its Remote Support (RS) and Privileged Remote Access
BeyondTrust issued emergency patches for two critical authentication bypass flaws in Remote Support and Privileged Remote Access, with two high-severity DoS flaws. Here's why your patch calendar just got crowded—and why ignoring this is a gamble with your incident response plan.
The Exploitarium Dump: A Solo Researcher's Zero-Day Shotgun Blast
An anonymous security researcher known as bikini published working exploit code for 15 zero-day vulnerabilities across libssh2, Gitea, Splunk, and more — without warning a single vendor. Two are already under active attack.
The Tenda Backdoor Nobody Knew Existed — And Why It Matters
A hidden authentication backdoor in Tenda router firmware (CVE-2026-11405) grants admin access to anyone who knows the secret password. No patch exists. Here's what you need to know before attackers find it first.
New macOS Privilege Escalation Technique Exploits XPC Service Trust
Researchers at XM Cyber have discovered a macOS vulnerability that allows standard-privileged users to disable security tools and perform privileged operations by exploiting faulty XPC service trust validation.
Understanding the 'Sender' Misconfiguration: Why Exchange Spoofing Persists
Recent security analysis reveals a widespread configuration issue in Microsoft Exchange Online enabling bypass of security gateways and authentication protocols, facilitating effective domain spoofing.
Android Security Update: Addressing Critical Vulnerabilities in June 2026 Patch
Google has released its June 2026 Android security patches, addressing 124 vulnerabilities including an actively exploited high-severity zero-day flaw (CVE-2025-48595).
Unpatched, Unforgiven: Microsoft's Zero-Day Standoff with Nightmare Eclipse
How a disgruntled researcher's leaked exploits ignited a firestorm over disclosure norms—and Microsoft's sudden retreat under industry pressure.
Veeam Backup & Replication CVE-2026-44963: Critical RCE Vulnerability Exposes Domain-Joined Servers
Critical vulnerability CVE-2026-44963 in Veeam Backup & Replication allows authenticated low-privilege domain users to achieve remote code execution on backup servers. Patch to version 12.3.2.4854 is required for mitigation.
From Zero-Day to Student Records: Deconstructing the Attack on Nottingham's Database
An analysis of the massive data breach at the University of Nottingham, focusing on how the ShinyHunters extortion crew exploited a critical zero-day vulnerability in Oracle PeopleSoft to access over 450,000 student records.
Campus Networks Unlocked: The PeopleSoft Zero-Day ShinyHunters Exploited to Ransom US Universities
A critical remote code execution vulnerability (CVE-2026-35273) in Oracle PeopleSoft’s Environment Management Hub has been weaponized by the ShinyHunters group, leading to data theft at dozens of institutions, including the University of Nottingham.
How ShinyHunters Turned a PeopleSoft Zero-Day Into the Biggest University Heist of 2026
Oracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunters against 300+ university instances.
Patch Tuesday Just Exposed How Broken Windows Security Really Is
Microsoft patched three zero-days on Tuesday—two that hand attackers SYSTEM access, one that opens BitLocker drives. But the real story is what came after: a researcher named Nightmare Eclipse kept leaking exploits because Microsoft wouldn't listen.