Vulnerabilities

Critical Flaw In Apache Tika Core Enables Exploitation Through Malicious PDF Files

A critical XML External Entity (XXE) vulnerability in Apache Tika, tracked as CVE-2025-66516, exposes users to attacks through specially crafted…

5 months ago

NCSC Launches Proactive Notification Service To Alert System Owners Of Vulnerabilities

The UK's National Cyber Security Centre (NCSC) has rolled out its Proactive Notification Service, partnering with internet monitoring firm Netcraft…

5 months ago

Security Vulnerability In NVIDIA Triton Could Let Attackers Trigger DoS Using Crafted Payloads

NVIDIA has issued a security bulletin warning about two high-severity vulnerabilities in its Triton Inference Server software. These flaws allow…

5 months ago

Cacti Command Injection Flaw Enables Remote Execution Of Malicious Code

A serious command injection vulnerability in Cacti, a popular open-source network monitoring tool, allows authenticated attackers to execute arbitrary commands…

5 months ago

Prompt Injection Vulnerability In GitHub Actions Affects Multiple Fortune 500 Companies

Security firm Aikido Security uncovered PromptPwnd, a flaw in GitHub Actions and GitLab CI/CD pipelines linked to AI agents. This…

5 months ago

Novel SVG-Based Clickjacking Method Allows Interactive User Manipulation

Security researcher Lyra Rebane has uncovered a powerful new clickjacking technique using SVG filters. This method, dubbed "SVG clickjacking," overlays…

5 months ago

CISA Reports Active Exploitation Of OpenPLC and ScadaBR File Upload Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2021-26828 to its Known Exploited Vulnerabilities (KEV) catalog on December 3,…

5 months ago

Chaining Synology BeeStation Flaws To Gain Root Access via Exploited Task Scheduler

Security researchers chained three vulnerabilities in Synology BeeStation devices to enable unauthenticated attackers to remotely gain root access. Demonstrated initially…

5 months ago

Zero-Day Vulnerabilities In PickleScan Allow Arbitrary Code Execution Through Malicious PyTorch Models

Security researchers at JFrog uncovered three critical zero-day flaws in PickleScan, a key tool for detecting malware in Python pickle-based…

5 months ago

New Tool For Scanning Exposed ReactJS and Next.js RSC Endpoints

Security researchers have released React Server Components Surface Exposure Scanner, a free tool to detect exposed endpoints vulnerable to CVE-2025-55182.…

5 months ago