Vulnerabilities

Exposed VPN Keys and Over-Permissioned Roles in Azure API Vulnerabilities

Azure, Microsoft’s flagship cloud platform, faces new scrutiny after security researchers from Token Security uncovered critical misconfigurations in multiple built-in…

10 months ago

Comodo Internet Security 2025 Vulnerabilities Allows Remote Code Execution System Privileges

A series of critical vulnerabilities have been discovered in Comodo Internet Security Premium (CISP) version 12.3.4.8162, potentially allowing remote attackers…

10 months ago

Active Exploitation of Vulnerabilities in Apache Tomcat and Camel

In March 2025, the Apache Software Foundation disclosed several high-severity vulnerabilities impacting two of its most widely deployed platforms: Apache…

10 months ago

Critical ScriptCase Vulnerabilities Allow Remote Code Execution and Server Takeover

A critical vulnerabilities in ScriptCase, a popular low-code platform used for generating PHP web applications, that allow attackers to execute…

10 months ago

FileFix – Leveraging Windows Browser Vulnerabilities to Circumvent Mark-of-the-Web Defense

A new blog post by a security researcher has introduced a troubling variant of the notorious FileFix attack, posing fresh…

10 months ago

Cybercriminals Targeting Windows and Linux Server Vulnerabilities to Install Web Shells

A recent wave of cyberattacks targeting South Korean web servers has raised alarms among cybersecurity professionals. Security analysts have identified…

10 months ago

Critical PHP Vulnerabilities Enable SQL Injection and DoS Attacks – Update Immediately

Critical security vulnerabilities have been discovered in PHP's PostgreSQL and SOAP extensions that could enable SQL injection attacks and denial…

10 months ago

Exploiting Vulnerabilities in Multiple Brother Devices – Attackers Gain Ability to Execute Arbitrary HTTP Requests

Security researchers at Rapid7 have uncovered a series of eight significant vulnerabilities affecting a staggering 748 multifunction printer (MFP) models…

10 months ago

Anthropic MCP Server Vulnerabilities Lets Attackers Escape Sandbox, Execute Code

A two high-severity vulnerabilities in Anthropic's Model Context Protocol (MCP) Filesystem Server that allow attackers to escape security sandboxes and…

10 months ago

CISA Warns of TeleMessage TM SGNL Vulnerabilities Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities affecting TeleMessage TM SGNL to its Known Exploited…

10 months ago