Resources

Application Security
SAP Patches Zero-Day in Commerce Cloud Data Hub Adapter
CVE-2026-58231 allows unauthenticated remote code execution across SAP Commerce Cloud. The flaw affects the Data Hub Adapter and carries CVSS 10.0 globally.
Application Security
CISA Adds Metabase SQL Injection Zero-Day to KEV With Aug 14 Deadline
CISA adds CVE-2026-72898 Metabase SQL injection flaw to KEV, setting an August 14 patch deadline for federal agencies and urging enterprises to update.
Application Security
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit
CISA confirms ransomware operators exploit a CVSS 9.1 SharePoint Server RCE requiring no authentication and granting administrator access worldwide today.
CVE Vulnerability Alerts
Metabase Zero-Day SQL Injection Exploited Against Framework, Tally
Metabase confirmed an exploited CVSS 10.0 zero-day SQL injection vulnerability that let attackers access customer data at Framework, Tally, and LexisNexis.
CVE Vulnerability Alerts
CISA Adds Exploited Kemp LoadMaster Command Injection to KEV
CISA added exploited Progress Kemp LoadMaster command injection CVE-2026-8037 to its KEV catalog after 792 in-the-wild exploitation attempts were documented.
CVE Vulnerability Alerts
Zapscape KVM Flaw Lets Privileged L1 Guest Escape to Host
Researcher Hyunwoo Kim documented Zapscape, CVE-2026-64561, a KVM/x86 shadow memory flaw allowing privileged L1 guest code to escape to the Linux host.
CVE Vulnerability Alerts
NatJack Attacks Hijack TCP Sessions and Spoof DNS via NAT
Researcher Malcolm Stagg's NatJack technique hijacks TCP sessions and spoofs DNS through NAT table manipulation, affecting Windows Hyper-V and Linux Netfilter.
Application Security
Claude Code and Gemini CLI Flaws Expose CI Workflow Secrets
Novee Security found flaws in Claude Code and Google Gemini CLI that let an attacker-controlled GitHub issue reach CI workflow secrets via an AI agent.
Application Security
AI-Assisted HTTP Terminator Finds Apache Traffic Server Zero-Day
PortSwigger's AI-assisted HTTP Terminator found roughly 30,000 HTTP desync vectors and a live Apache Traffic Server zero-day affecting roughly 700 targets.
Application Security
CISA Flags Active Exploitation of TeamCity CVE-2026-63077
CISA added JetBrains TeamCity CVE-2026-63077 to its Known Exploited Vulnerabilities catalog, citing unauthenticated remote code execution in the wild.

Weekly Newsletter

Weekly Cybersecurity Newsletter: 14th to 18th August
Cybersecurity Newsletter
Weekly Cybersecurity Newsletter: 14th to 18th August
Explore our latest cybersecurity podcast episodes featuring ransomware attacks, phishing campaigns, corporate breaches, legal showdowns, and deep dives into evolving threats and digital defenses.
This Week In Cybersecurity: 23rd June to 27th June
Cybersecurity Newsletter
This Week In Cybersecurity: 23rd June to 27th June
News Stories New ‘FileFix’ Attack Exploits Windows File Explorer to Deliver Stealthy Commands Threat actors use the search-ms URI protocol ...
This Week In Cybersecurity: 26th to 30th May, 2025
Cybersecurity Newsletter
This Week In Cybersecurity: 26th to 30th May, 2025
"Cybersecurity threats escalate as ransomware attacks target major organizations, exposing sensitive data and highlighting vulnerabilities in systems across various industries. Stay informed."
This Week In Cybersecurity: 19th to 23rd May, 2025
Cybersecurity Newsletter
This Week In Cybersecurity: 19th to 23rd May, 2025
This week, significant cybersecurity incidents include ransomware attacks, data breaches affecting major organizations, and ongoing threats from state-sponsored groups, highlighting vulnerabilities across various sectors.
This Week In Cybersecurity: 21st - 25th April, 2025
Cybersecurity Newsletter
This Week In Cybersecurity: 21st – 25th April, 2025
Targeted malware, ransomware, phishing, and ad fraud hit SK Telecom, Baltimore schools, Google, and more this week—exposing critical data and abusing trusted systems.