Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and ...
CVE-2026-42533 NGINX vulnerability now has a public config scanner as researcher Stan Shaw warns the critical heap buffer ...
A researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chain ...
Attackers exploit CVE-2026-6875 in ServiceNow AI Platform, a pre-auth sandbox escape that could compromise instances and connected proxy servers.
A newly-disclosed exploit in Claude Code’s ‘auto-mode’ leaves developers facing remote code execution (RCE) vulnerabilities ...
A critical vulnerability in the Erlang/OTP SSH, tracked as CVE-2025-32433, has been disclosed that allows for unauthenticated remote code execution on vulnerable devices. The flaw was discovered by ...
Chrome Firefox security update July 2026 delivered emergency patches across five vendors on July 15: Mozilla confirmed public ...
A chain of Sitecore Experience Platform (XP) vulnerabilities allows attackers to perform remote code execution (RCE) without authentication to breach and hijack servers. Sitecore is a popular ...
Security researchers have disclosed a proof-of-concept exploit capable of obtaining root access on Android 17 by combining ...
Discover how the Rogue Agent vulnerability in Google Dialogflow CX enabled persistent AI agent compromise, data exfiltration, ...
Bonzo Lend, a non-custodial lending and borrowing protocol built on the Hedera [HBAR] network, was recently exploited. The ...