Vulnerability

New 0-Click NTLM Credential Leak Vulnerability Evades Microsoft’s CVE-2025-24054 Patch

A critical zero-click vulnerability that circumvents Microsoft's security patch for CVE-2025-24054, enabling attackers to extract NTLM credentials without any user…

9 months ago

Microsoft Teams RCE Vulnerability Lets Hackers Steal, Alter, and Erase Messages

Microsoft has disclosed a significant remote code execution vulnerability in Teams that could enable attackers to compromise enterprise communications and…

9 months ago

Apache bRPC Vulnerability Enables Remote Service Crash

A critical vulnerability in Apache bRPC's Redis protocol parser has been identified that allows remote attackers to execute denial-of-service attacks…

9 months ago

7-Zip Vulnerability Enables Arbitrary File Write and Remote Code Execution

A critical security vulnerability has been discovered in 7-Zip, the popular file compression utility, that allows attackers to perform arbitrary…

9 months ago

Retbleed Vulnerability Enables Arbitrary Memory Reads on Modern CPUs

A sophisticated exploitation of the Retbleed vulnerability, showcasing how attackers can read arbitrary physical memory from sandboxed processes and virtual…

9 months ago

CISA Issues Urgent Warning on Critical Microsoft Exchange Security Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive 25-02 on August 7, 2025, ordering federal agencies to immediately…

9 months ago

Akamai Ghost Platform Vulnerability Allows HTTP Request Smuggling via Request Body

Akamai Technologies has patched a critical HTTP request smuggling vulnerability affecting its Ghost platform, after a coordinated disclosure with security…

9 months ago

Critical HTTP/1.1 Vulnerability Puts Millions of Websites at Risk of Takeover

A critical vulnerability in HTTP/1.1 protocol that exposes tens of millions of websites to hostile takeover through sophisticated desynchronization attacks.…

9 months ago

New Microsoft Exchange Vulnerability Grants Attackers Admin Access

Microsoft and CISA have issued urgent security alerts regarding a newly discovered high-severity vulnerability in Exchange Server hybrid deployments that…

9 months ago

Cursor IDE Vulnerability in MCP Validation Enables MCPoison Command Execution Attack

A critical vulnerability in Cursor, the rapidly growing AI-powered code editor, that enables persistent remote code execution through manipulation of…

9 months ago