Resources

Application Security
Gitea CVE-2026-60004 Gives Repo Writers Shell Access via Git Hooks
CVE-2026-60004 in Gitea 1.17–1.27.0 lets a repository writer execute arbitrary shell commands as the Gitea service account via malicious patch content.
CVE Vulnerability Alerts
OpenWrt CVE-2026-53921 Lets Attackers Root Routers via DHCPv6 Overflow
CVE-2026-53921, a CVSS 9.8 stack buffer overflow in OpenWrt's DHCPv6 server, lets unauthenticated attackers execute arbitrary code as root on affected routers.
Application Security
VMware ESXi VM Escape CVE-2026-47876 Patched Alongside Four More Flaws
Broadcom patched CVE-2026-47876, a critical ESXi VM escape via VMXNET3, plus two critical vCenter Server flaws, with no confirmed in-the-wild exploitation.
Application Security
Fastjson 1.x Zero-Day CVE-2026-16723 Under Active Exploit, No Patch
CVE-2026-16723, a CVSS 9.0 zero-day in Fastjson 1.x with no available patch, is actively exploited targeting financial services and healthcare backends.
Application Security
CISA Orders Patch for Langflow and WordPress wp2shell RCEs
CISA added Langflow CVE-2026-0770 and WordPress wp2shell CVE-2026-63030 to its KEV catalog, setting a July 24 Langflow deadline and August 4 WordPress deadline as mass ...
CVE Vulnerability Alerts
Qilin Affiliates Exploit PAN-OS CVE-2026-0257 GlobalProtect Bypass
Arctic Wolf documented Qilin affiliates exploiting CVE-2026-0257, a PAN-OS GlobalProtect auth bypass, to gain trusted VPN access for double-extortion attacks.
Application Security
JetBrains Patches TeamCity CVE-2026-63077 CVSS 9.8 RCE Flaw
JetBrains patched CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in TeamCity CI/CD servers exploitable via the agent polling protocol without any credentials.
CVE Vulnerability Alerts
AI-Assisted Linux Kernel CVE-2026-53264 Root Exploit Released
Lee Jia Jie used AI assistance to discover CVE-2026-53264, a Linux kernel use-after-free enabling local root escalation. A public exploit is now available.
CVE Vulnerability Alerts
Arista VeloCloud CVE-2026-16812 Exploited, CISA Orders Patch
Arista confirmed CVE-2026-16812, a CVSS 10.0 OS command injection in VeloCloud Orchestrator, is actively exploited. CISA ordered federal patches by July 30.
Application Security
Public Exploit Released for vBulletin CVE-2026-61511 RCE
SSD Secure Disclosure released a weaponized unauthenticated RCE exploit for CVE-2026-61511 in vBulletin 6.x, exposing forum sites not yet on version 6.2.2.

Weekly Newsletter

Weekly Cybersecurity Newsletter: 14th to 18th August
Cybersecurity Newsletter
Weekly Cybersecurity Newsletter: 14th to 18th August
Explore our latest cybersecurity podcast episodes featuring ransomware attacks, phishing campaigns, corporate breaches, legal showdowns, and deep dives into evolving threats and digital defenses.
This Week In Cybersecurity: 23rd June to 27th June
Cybersecurity Newsletter
This Week In Cybersecurity: 23rd June to 27th June
News Stories New ‘FileFix’ Attack Exploits Windows File Explorer to Deliver Stealthy Commands Threat actors use the search-ms URI protocol ...
This Week In Cybersecurity: 26th to 30th May, 2025
Cybersecurity Newsletter
This Week In Cybersecurity: 26th to 30th May, 2025
"Cybersecurity threats escalate as ransomware attacks target major organizations, exposing sensitive data and highlighting vulnerabilities in systems across various industries. Stay informed."
This Week In Cybersecurity: 19th to 23rd May, 2025
Cybersecurity Newsletter
This Week In Cybersecurity: 19th to 23rd May, 2025
This week, significant cybersecurity incidents include ransomware attacks, data breaches affecting major organizations, and ongoing threats from state-sponsored groups, highlighting vulnerabilities across various sectors.
This Week In Cybersecurity: 21st - 25th April, 2025
Cybersecurity Newsletter
This Week In Cybersecurity: 21st – 25th April, 2025
Targeted malware, ransomware, phishing, and ad fraud hit SK Telecom, Baltimore schools, Google, and more this week—exposing critical data and abusing trusted systems.