Uncategorized

Critical Kibana Vulnerability Enable Heap Corruption and Remote Code Execution

A critical security vulnerability has been identified in Elastic's Kibana platform that enables attackers to execute heap corruption and potentially…

10 months ago

Critical Linux CentOS Web Panel Vulnerability Allows Remote Code Execution – PoC Released

A severe security vulnerability has been discovered in CentOS Web Panel (CWP), a widely-used free web hosting control panel that…

10 months ago

CISA Releases ICS Advisories Addressing Ongoing Vulnerabilities and Exploits

The Cybersecurity and Infrastructure Security Agency (CISA) has released eight Industrial Control Systems (ICS) advisories on June 24, 2025, addressing…

10 months ago

Critical TeamViewer Vulnerability on Windows Allows Attackers to Delete Files with SYSTEM Privileges

A significant security vulnerability has been discovered in TeamViewer's Remote Management software for Windows systems, enabling attackers with local access…

10 months ago

NVIDIA Megatron LM Vulnerabilities Allows Attackers to Inject Malicious Code

NVIDIA has disclosed critical security vulnerabilities in its Megatron LM software that enable attackers to inject malicious code through compromised…

10 months ago

New FileFix Attack Exploits Windows File Explorer to Run Malicious Commands

A new social engineering attack technique called "FileFix" that exploits Windows File Explorer's address bar functionality to execute malicious commands…

10 months ago

America, Netflix, and Microsoft Targeted in Hack to Insert Fake Phone Numbers

A sophisticated scam targeting users of major American companies, where criminals exploit Google's advertising system to inject fake customer service…

10 months ago

OWASP AI Testing Guide: A New Initiative to Identify Vulnerabilities in AI Applications

The Open Web Application Security Project (OWASP) has announced the development of a comprehensive AI Testing Guide, marking a significant…

10 months ago

Threat Actor Promotes EagleSpy v5 RAT, Claiming Stealthy Android Device Access

A prominent cybercriminal known as "xperttechy" has surfaced on a well-known dark web forum, promoting a new iteration of Android…

10 months ago

Zimbra Classic Web Client Vulnerability Allows Attackers to Execute Arbitrary JavaScript

Zimbra has released critical security patches addressing a severe stored cross-site scripting vulnerability in its Classic Web Client that could…

10 months ago