Discover actionable security strategies, real-world threat analysis, and expert insights to strengthen your defenses against evolving cyber threats.
U-Boot FIT signature flaws expose a fragile pre-OS trust boundary Firmware security company Binarly has disclosed six vulnerabilities in U-Boot's FIT signature...
Lucas Oliveira
Research
Gitea Docker flaw turns a trusted proxy header into account takeover Gitea has fixed a critical authentication bypass in its official Docker images that could l...
Lucas Oliveira
Research
BeyondTrust auth bypass flaws put remote support appliances on the urgent patch list BeyondTrust has disclosed four vulnerabilities in its Remote Support and Pr...
Lucas Oliveira
Research
LeakyLooker: 9 Google Looker Studio Flaws Enabled Cross-Tenant SQL and Data Theft | 2026 Executive Summary LeakyLooker is the name Tenable gave to a set of nine...
Lucas Oliveira
Research
Check Point SmartConsole CVE-2026-16232 turns exposed management into firewall takeover risk Check Point has released an urgent July 2026 security update for an...
Lucas Oliveira
Research
Iran-linked PLC attacks show why internet-exposed OT is now an incident-response priority U.S. agencies have updated their warning on Iran-affiliated cyber acti...
Lucas Oliveira
Research
Check Point CVE-2026-16232 puts firewall management in the blast radius Check Point has patched an actively exploited SmartConsole authentication bypass that ca...
Lucas Oliveira
Research
Windmill CVE-2026-29059 turns log access into a secrets problem Attackers are now exploiting CVE-2026-29059, a Windmill path traversal flaw that lets unauthenti...
Lucas Oliveira
Research
SharePoint CVE-2026-50522 makes patching only the first step Microsoft SharePoint Server is back in the emergency lane. CVE-2026-50522, a critical deserializati...
Lucas Oliveira
Research
ServiceNow CVE-2026-6875 turns AI workflow platforms into urgent patch targets ServiceNow's July security advisory for CVE-2026-6875 has moved quickly from "cri...
Lucas Oliveira
Research
7-Zip CVE-2026-14266 turns archive handling into an endpoint patch priority The latest 7-Zip security disclosure is not the kind of vulnerability that lets an a...
Lucas Oliveira
Research
NGINX CVE-2026-42533 turns a narrow map regex bug into an urgent patch window F5 has released fixes for CVE-2026-42533, a critical NGINX Plus and NGINX Open Sou...
Lucas Oliveira
Research
SharePoint RCE zero-day forces a July 19 incident-response deadline Microsoft SharePoint Server administrators have another urgent on-premises exposure to handl...
Lucas Oliveira
Research
wp2shell puts WordPress core in emergency patch mode WordPress administrators have a rare core-level emergency on their hands. On July 17, 2026, WordPress relea...
Lucas Oliveira
Research
Oracle E-Business Suite flaw hits CISA KEV as payment systems face takeover risk CISA has added CVE-2026-46817, a critical Oracle E-Business Suite vulnerability...
Lucas Oliveira
Research
FortiSandbox command injection flaws move from patch queue to exploited risk CISA has added two Fortinet FortiSandbox vulnerabilities to its Known Exploited Vul...
Lucas Oliveira
Research