Vulnerabilities & Exploits
CVEs, zero-days, patching and exploited weaknesses.
INC Ransomware: How Operational Discipline Beat Flashy Exploits
INC ransomware emerges as a top-tier RaaS operation by mastering fundamentals—targeting pressured sectors, leveraging timing from competitor shutdowns, and rewriting its malware in Rust—claiming 800+ victims since 2023.
AI Cybersecurity in Action: How a Vulnerability Vending Machine Turns Code Slices Into Zero-Days
Intruder’s AI pipeline automates zero-day discovery in WordPress plugins using code slicing and LLMs — not theory, but a working system that found a critical SQL injection with no human input.
Microsoft Links Upcoming Patch Tuesday Surge to AI-Powered Discovery
As Microsoft adopts AI-based vulnerability scanning tools like MDASH, the company warns that customers should prepare for more frequent and voluminous security update releases.
AI Cybersecurity Threats: CISA Warns of Actively Exploited SharePoint Flaws Enabling RCE and Persistence
CISA has issued an urgent alert: attackers are weaponizing three SharePoint Server vulnerabilities to bypass authentication, execute remote code, and steal IIS machine keys for persistent access. Federal agencies have just days to patch.
Windows 10’s Last Stand: The 570-Flaw Patch That Bought Us Until 2027
Microsoft's final extended security update for Windows 10 patches 300+ vulnerabilities, enforces TDI transport registration, and quietly shifts Secure Boot certificate deployment — a last gasp before the OS exits stage left.
The "Delusion" Gap: How False Premises Overpower AI Safety Mechanisms
An exploration of how inducing a hallucinated or false premise in LLMs disrupts safety filters and allows for forbidden instruction execution.
U-Boot Bootloader Under Fire: Six Critical Vulnerabilities Could Let Attackers In Through Your Firmware
Six newly disclosed vulnerabilities in the U-Boot bootloader could let attackers execute code before your operating system even starts — opening the door to persistent firmware attacks on embedded devices, BMCs, industrial systems, and more.
Critical XSS Flaw Prompts Urgent Zimbra Classic Web Client Update
Zimbra has released a critical security update for its Classic Web Client to address a stored XSS vulnerability that could lead to account compromise.
Threat Actors Weaponized CVE-2026-10520 Within 24 Hours of Ivanti Sentry Disclosure
Threat actors exploited a maximum-severity OS command injection flaw (CVE-2026-10520) in Ivanti Sentry within 24 hours of disclosure, using a public proof-of-concept to achieve root-level RCE. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog with a three-day patch deadline.
SAP’s June 2026 Patch: Four Critical Flaws That Could Break Your Enterprise
SAP's June 2026 Security Patch resolves 15 vulnerabilities, including four critical-severity flaws in NetWeaver and Commerce Cloud—most dangerously, an unauthenticated SAML bypass and memory corruption flaw that require immediate action.
AI Cybersecurity in Action: How IBM’s $5 Billion Patching Bet Rewrites the Rules
IBM and Red Hat have launched Project Lightwell, a $5 billion initiative to accelerate the patching of open-source vulnerabilities faster than AI systems can discover them. The program combines AI-driven vulnerability detection with automated remediation pipelines and a global coalition of developers, security researchers, and enterprise partners.
One Critical Flaw in India's UPSC Portal Allowed Full System Takeover — And It Wasn't the Only One
An independent researcher exposed 14 vulnerabilities across Indian government systems in 2026, including a critical flaw in the UPSC civil-service portal that let any attacker seize full administrative control — revealing systemic failures in public-sector access control.