Microsoft began rolling out fixes for two Microsoft Defender flaws after they were reportedly exploited before a public patch was broadly available.
Exploited flaws in two Defender-related components could let an attacker climb to SYSTEM or knock protection offline, underscoring how endpoint security software can become part of the attack surface.
A cluster of vulnerabilities in the file-sync staple shows why exposure is shaped less by product name than by the way the service is deployed.
A max-severity issue in the Python FastAPI build of ChromaDB shows how one exposed AI service can become a takeover path when authentication and request handling fail in the wrong order.
Microsoft has warned that a critical XSS issue in Exchange Server’s OWA interface is being exploited while defenders wait for a permanent fix.
Fragnesia is a reminder that the most dangerous Linux flaws are often not remote fireworks, but local kernel breaks that can hand an ordinary account the keys to the host.
A reported stored XSS issue in Open WebUI’s upload path shows how a routine profile-image workflow can become a persistent browser-side attack surface, with a claimed route to account hijacking and even deeper compromise in chained scenarios.
A May 8 disclosure tied to cPanel, WHM, and WP Squared shows how small mistakes in hosting-control logic can create outsized risk when the vulnerable code sits close to server administration.
Microsoft Edge’s design flaw leaves user passwords vulnerable in process memory, posing a significant risk for organizations relying on the browser.
A critical oversight in Cursor’s extension architecture allows malicious add-ons to silently steal API keys and session tokens—no hacking skills required.
A critical flaw in the popular LeRobot ML framework lets hackers seize control—no password required.
Security flaw in Notion exposes names, emails, and profile pictures of editors on public pages—no password required.
An overlooked vulnerability in the Model Context Protocol exposes millions to cascading AI-powered cyberattacks.
A critical flaw in Marimo’s open-source Python notebook platform was weaponized less than 10 hours after disclosure, exposing sensitive credentials worldwide.
A newly uncovered bug in Docker’s authorization system left critical systems open to stealthy attacks—here’s what went wrong and what you need to know.
A critical vulnerability in Anthropic’s AI coding assistant quietly disabled security rules, putting sensitive data and systems at risk.
A subtle software bug let bad actors slip malicious VS Code extensions past Open VSX’s security checks—no hacking required.
A newly detected vulnerability in Oracle’s software ecosystem sends shockwaves through the business world, raising urgent questions about data safety and corporate risk.
A critical flaw in AdGuard Home let hackers waltz past logins, triggering a global scramble to lock down networks.