Vulnerabilities

Critical Unauthenticated DoS Bug Can Take Down Next.js Servers Using Just One HTTP Request

A serious denial-of-service (DoS) flaw in Next.js lets attackers crash self-hosted servers with a single HTTP request, using almost no…

5 months ago

Apache Syncope Flaw Lets Attackers Dump Internal Database Contents

Security teams using Apache Syncope face a new risk. A flaw in this open-source identity management tool allows attackers to…

5 months ago

HashiCorp Vault Flaw Enables Credential-Free Authentication Bypass

HashiCorp has disclosed a security flaw in its Vault Terraform Provider that allows attackers to bypass valid credentials and log…

5 months ago

NVIDIA Isaac-GROOT Robotics Platform Flaw Allows Malicious Code Injection

NVIDIA has patched serious security flaws in its Isaac-GR00T platform, a key tool for building AI-powered humanoid robots. Released on…

5 months ago

Remote Code Execution Enabled By Malicious Payloads Through vLLM Vulnerability

A serious flaw in the popular vLLM library could let attackers crash servers or even run malicious code remotely. Security…

5 months ago

Wireshark 4.6.1 Addresses Multiple Vulnerabilities That Could Cause Application Crashes

Wireshark, the leading open-source network protocol analyzer, released version 4.6.1 on November 19, 2025, to fix two security flaws in…

5 months ago

Critical Vulnerabilities Identified In DeepSeek-R1’s Code Generation

CrowdStrike researchers discovered that DeepSeek-R1, a 671-billion-parameter large language model from a Chinese AI firm released in January 2025, produces…

5 months ago

Hackers Launch 2.3 Million Attacks On Palo Alto Networks’ GlobalProtect VPN Portals

Cybersecurity firm GreyNoise reported a dramatic spike in attacks targeting Palo Alto Networks' GlobalProtect VPN portals. Starting November 14, 2025,…

5 months ago

Active Exploitation Of Chrome Type Confusion Zero-Day Vulnerability In The Wild

Google has urgently patched a critical zero-day vulnerability in its Chrome browser after confirming active exploitation by threat actors. The…

5 months ago

Critical Security Bug In Zoho Analytics Plus Lets Attackers Execute Arbitrary SQL Commands

Zoho Corporation, known for its suite of business software, has disclosed a serious security flaw in its Analytics Plus tool.…

5 months ago