Resources

Application Security
AI-Assisted HTTP Terminator Finds Apache Traffic Server Zero-Day
PortSwigger's AI-assisted HTTP Terminator found roughly 30,000 HTTP desync vectors and a live Apache Traffic Server zero-day affecting roughly 700 targets.
Application Security
CISA Flags Active Exploitation of TeamCity CVE-2026-63077
CISA added JetBrains TeamCity CVE-2026-63077 to its Known Exploited Vulnerabilities catalog, citing unauthenticated remote code execution in the wild.
Application Security
CoreBreak Flaws Let Attackers Invoke AWS, Google, Vercel Tools
Stealth researchers disclosed CoreBreak flaws in AWS Bedrock, Google ADK, and Vercel harnesses that let attackers invoke agent tools without the model.
CVE Vulnerability Alerts
Cisco Patches Critical SD-WAN, IOS XE, and FMC Flaws
Cisco patched two dozen flaws including critical Catalyst SD-WAN and IOS XE command-injection bugs plus an FMC authentication bypass in a new advisory release.
Application Security
CISA Adds Exploited Langflow and Tomcat Flaws to KEV Catalog
CISA added actively exploited Langflow and Apache Tomcat vulnerabilities to the KEV catalog, linking the Tomcat flaw to an AI-enabled Chinese hacking campaign.
Application Security
cPanel Patches Critical Flaw Letting Customers Run SQL as Root
cPanel patched CVE-2026-58048, a CVSS 9.4 privilege-escalation flaw letting an authenticated hosting customer execute SQL in the database root context.
CVE Vulnerability Alerts
TP-Link Omada Provisioning Flaws Enable Full Network Takeover
Forescout disclosed 15 TP-Link Omada zero-touch provisioning vulnerabilities that chain with earlier RCE flaws into full fleet-wide network compromise.
CVE Vulnerability Alerts
Thermo Fisher Patches DNA File Tampering Flaw CVE-2026-17583
Thermo Fisher patched CVE-2026-17583 in Applied Biosystems DNA-testing software, allowing forensic evidence file alterations to pass with little detection.
Application Security
FaceHugger Flaws in Hugging Face Diffusers Bypass trust_remote_code
FaceHugger flaws in Hugging Face Diffusers bypass trust_remote_code and let malicious model repositories execute arbitrary code when models are loaded.
CVE Vulnerability Alerts
N-able Warns Attackers Reached Managed Endpoints via N-central Flaw
N-able warns attackers exploited CVE-2026-18577 to take over N-central servers and reach managed endpoints, planting Cloudflare tunnels for persistent access.

Weekly Newsletter

Weekly Cybersecurity Newsletter: 14th to 18th August
Cybersecurity Newsletter
Weekly Cybersecurity Newsletter: 14th to 18th August
Explore our latest cybersecurity podcast episodes featuring ransomware attacks, phishing campaigns, corporate breaches, legal showdowns, and deep dives into evolving threats and digital defenses.
This Week In Cybersecurity: 23rd June to 27th June
Cybersecurity Newsletter
This Week In Cybersecurity: 23rd June to 27th June
News Stories New ‘FileFix’ Attack Exploits Windows File Explorer to Deliver Stealthy Commands Threat actors use the search-ms URI protocol ...
This Week In Cybersecurity: 26th to 30th May, 2025
Cybersecurity Newsletter
This Week In Cybersecurity: 26th to 30th May, 2025
"Cybersecurity threats escalate as ransomware attacks target major organizations, exposing sensitive data and highlighting vulnerabilities in systems across various industries. Stay informed."
This Week In Cybersecurity: 19th to 23rd May, 2025
Cybersecurity Newsletter
This Week In Cybersecurity: 19th to 23rd May, 2025
This week, significant cybersecurity incidents include ransomware attacks, data breaches affecting major organizations, and ongoing threats from state-sponsored groups, highlighting vulnerabilities across various sectors.
This Week In Cybersecurity: 21st - 25th April, 2025
Cybersecurity Newsletter
This Week In Cybersecurity: 21st – 25th April, 2025
Targeted malware, ransomware, phishing, and ad fraud hit SK Telecom, Baltimore schools, Google, and more this week—exposing critical data and abusing trusted systems.