Vulnerabilities & Exploits
CVEs, zero-days, patching and exploited weaknesses.
The "Delusion" Gap: How False Premises Overpower AI Safety Mechanisms
An exploration of how inducing a hallucinated or false premise in LLMs disrupts safety filters and allows for forbidden instruction execution.
U-Boot Bootloader Under Fire: Six Critical Vulnerabilities Could Let Attackers In Through Your Firmware
Six newly disclosed vulnerabilities in the U-Boot bootloader could let attackers execute code before your operating system even starts — opening the door to persistent firmware attacks on embedded devices, BMCs, industrial systems, and more.
Critical XSS Flaw Prompts Urgent Zimbra Classic Web Client Update
Zimbra has released a critical security update for its Classic Web Client to address a stored XSS vulnerability that could lead to account compromise.
Threat Actors Weaponized CVE-2026-10520 Within 24 Hours of Ivanti Sentry Disclosure
Threat actors exploited a maximum-severity OS command injection flaw (CVE-2026-10520) in Ivanti Sentry within 24 hours of disclosure, using a public proof-of-concept to achieve root-level RCE. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog with a three-day patch deadline.
How Google Catches AI Spam Clusters Before They Flood Your Search
Google’s Scalable Cluster Termination System uses infrastructure signals and generative artifacts to detect coordinated AI spam campaigns — shifting from content-level filters to cluster-level termination.
CISA Orders Federal Agencies to Patch Actively Exploited LangFlow Auth Bypass by Friday
The U.S. Cybersecurity and Infrastructure Security Agency has added a newly exploited IDOR flaw in the popular LangFlow AI-agent builder to its KEV catalog, giving FCEB agencies until Friday to remediate under BOD 26-04.
How a Silent Software Vulnerability Exposed 12 Million Users at Japan's KDDI and Partner ISPs
Logan Bastion breaks down the architecture failure behind the KDDI zero-day exploit, which exposed the email addresses and passwords of over 12 million users across five partner ISPs.
The Shadow in the Prompt: Understanding the Escalation of AI Vulnerabilities
As AI becomes integral to business operations, prompt injection has emerged as a primary security threat. This article explores how vulnerabilities in large language models are being exploited to facilitate large-scale malicious operations, including botnet assembly, and how security frameworks are evolving to counter these risks.
Zero-Day ColdFusion Flaw Hit by Attackers Hours After Adobe Disclosure
Attackers are exploiting a CVSS 10.0 path-traversal vulnerability in Adobe ColdFusion (CVE-2026-48282) within hours of patch release, prompting CISA to add it to its KEV catalog and issue a federal mandate under BOD 26-04.
Brands Exploited to Lure Job Seekers in Wide-Scale Phishing Operation
A persistent phishing campaign is impersonating more than 30 major global brands, exploiting legitimate CRM and marketing cloud services to execute nested redirect chains and steal Google account credentials via a convincing browser-based authentication mimicry technique.
SAP’s June 2026 Patch: Four Critical Flaws That Could Break Your Enterprise
SAP's June 2026 Security Patch resolves 15 vulnerabilities, including four critical-severity flaws in NetWeaver and Commerce Cloud—most dangerously, an unauthenticated SAML bypass and memory corruption flaw that require immediate action.
One Critical Flaw in India's UPSC Portal Allowed Full System Takeover — And It Wasn't the Only One
An independent researcher exposed 14 vulnerabilities across Indian government systems in 2026, including a critical flaw in the UPSC civil-service portal that let any attacker seize full administrative control — revealing systemic failures in public-sector access control.