CISA set a July 17 remediation deadline, but patching alone leaves an already-compromised appliance in place — credential rotation and hunting are mandatory.
Latest news
Latest cybersecurity dispatches
Fresh reporting on active vulnerabilities, security patches, incident response, and threat research for defenders.
A critical stack-based buffer overflow in Ivanti Connect Secure has been exploited since mid-March 2025, turning perimeter VPN gateways into footholds.
A practical systems-level explanation of Claude Code as a local agent runtime, covering startup, authentication, tools, permissions, sessions, MCP, plugins, and the Agent SDK.
CVE-2026-33017 exposes Langflow AI workflow builders to unauthenticated remote code execution through the public flow build endpoint.
CVE-2026-33634 turned trusted Trivy releases and GitHub Actions into credential-stealing malware inside CI/CD pipelines and developer environments.
SimpleHelp CVE-2024-57727, CVE-2024-57726, and CVE-2024-57728 form an attack chain abused by ransomware actors against MSPs and downstream customers.
CVE-2026-41940 is a critical cPanel and WHM authentication bypass tied to mass exploitation, Sorry ransomware deployment, and an accelerated CISA remediation deadline.
A critical unauthenticated PAN-OS User-ID Authentication Portal zero-day, CVE-2026-0300, was exploited for 26 days before public disclosure, giving likely state-backed attackers root-level firewall access.