Vulnerabilities & Exploits
CVEs, zero-days, patching and exploited weaknesses.
Closing the YAML Gap: Securing Automated Repository Workflows Against Cordyceps Attacks
An in-depth security analysis of 'Cordyceps', a class of CI/CD supply chain vulnerabilities exploiting automated pull request workflows at major institutions including Microsoft, Google, Apache, and PSF, exacerbated by AI coding agents.
Unlocking Sex-Specific Vulnerabilities: GABA Pathway Fuels Glioblastoma in Females
A new study reveals that the neurotransmitter GABA selectively reprograms immune cells to fuel glioblastoma growth specifically in females, showing a critical sex-specific mechanism that could lead to targeted therapies.
Critical Privilege Escalation Flaw Discovered in Kirki WordPress Plugin
A critical privilege escalation vulnerability, CVE-2026-8206, in the Kirki WordPress plugin allows unauthenticated attackers to hijack administrator accounts. Users must update to version 6.0.7 immediately.
Git Rebase Command Injection in Gogs Enables Server Takeover
A critical argument injection vulnerability (CVE-2026-52806) in Gogs enabled authenticated users to execute arbitrary commands by exploiting the 'Rebase before merging' function. Explore technical analysis and mitigation strategies to secure your Git infrastructure against RCE.
Active Directory Control Planes at Risk of Remote Takeover via Exposed Netlogon Protocol
An urgent warning from Belgium's national cybersecurity authority reveals that threat actors are actively capitalizing on CVE-2026-41089, a critical stack-based buffer overflow in the Windows Netlogon service allowing unauthenticated remote code execution on Domain Controllers.
Root RCE via Reflected Configuration Commands: A Technical Breakdown of Ivanti Sentry's Dual Flaws
An analytical breakdown of Ivanti Sentry's CVE-2026-10520 and CVE-2026-10523 vulnerabilities, detailing how a pre-authentication endpoint allowed attackers to execute root-level commands via reflective Java configuration parsing.
Critical Exploited Zero-Day Found in Oracle PeopleSoft Applications
Oracle has issued emergency mitigations for CVE-2026-35273, a critical zero-day in PeopleSoft PeopleTools currently being exploited by the ShinyHunters extortion group to facilitate large-scale data theft.
Active Exploitation of Path Traversal in Langflow AI
Exploitation of CVE-2026-5027, a critical path traversal vulnerability in Langflow, is underway, allowing unauthorized file uploads on exposed servers.
Path-Divergence Vulnerability in Starlette Exposes Python-Based AI Agents to Data Breaches
An in-depth look at CVE-2026-48710 (BadHost), a critical path-divergence vulnerability in the Starlette ASGI framework that allows authentication bypasses and security control evasion across the Python AI ecosystem.
Shifting to Risk-Centric Patching: How CISA’s New Mandate Impacts Federal Security
Expanded coverage of CISA’s risk-matrix patching mandate (BOD 26-04), detailing its three-dimensional framework, AI-driven threat context, operational implementation challenges, and strategic implications for federal cyber resilience.
CISA Alerts: Hackers Actively Exploiting SolarWinds Serv-U Flaw (CVE-2026-28318)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are actively exploiting a recently patched high-severity vulnerability in SolarWinds Serv-U to crash file transfer servers. This denial-of-service flaw allows unauthenticated remote attackers to take down Serv-U services using specially crafted POST requests.
Trivial RCE in AMD AutoUpdate Software Due to HTTP Downloads and Missing Signature Verification
A detailed analysis of CVE-2026-40677: How AMD's AutoUpdate software allowed Remote Code Execution through unencrypted HTTP downloads without cryptographic signature verification, and the controversial 124-day embargo period.