Version 4.6.7 closes 12 security flaws, underscoring how a trusted network analyzer can become fragile when it ingests hostile traffic or capture files.
Two critical Metabase flaws were patched after security updates, and the risk profile is unsettling: an authenticated user could turn ordinary access into arbitrary code execution on affected systems.
A ransomware claim tied to Vandalia-Rental shows why the most dangerous question is often not what was said, but which exposed entry point could have made it possible.
Version 4.6.7 closes 12 security flaws in the packet analyzer’s decoders, file parsers, and external capture path, a reminder that inspection tools inherit their own attack surface.
Siemens has issued security updates for four product vulnerabilities, a reminder that in industrial environments the real challenge is not just fixing bugs, but doing it without disrupting operations.
Newly disclosed bugs in U-Boot’s FIT signature path could weaken the earliest trust checks in devices that rely on it, with consequences that range from code execution to boot-stage denial of service.
Roundcube 1.7.2 closes high-impact XSS and SSRF issues, a reminder that webmail platforms sit where untrusted email content and server-side network access can become the same attack surface.
Six critical vulnerabilities in U-Boot, reportedly reachable through malicious FIT images, may lead to pre-authentication code execution or early-boot denial of service.
A cluster of weaknesses in PowerChute Serial Shutdown shows how a utility built for orderly power loss can become a high-value target for integrity, availability, and log-trust failures.
A new patch wave for Palo Alto Networks' firewall software highlights how modern security appliances now carry the same mix of memory, logic, and access-control risk as the systems they protect.
High-severity fixes for Junos OS and Junos OS Evolved put router and switch operators back on alert, with the real concern sitting in configuration integrity and service availability.
Two resolved Go vulnerabilities, including one high-severity flaw, show how a small path-handling mistake can turn a safety API into a confidentiality risk.
A wide 2026.1.2 patch cycle for Foxit Reader and Editor shows how parsing bugs, scripts, and rich media can turn routine PDFs into serious endpoint risk.
A security patch notice for GitLab CE and EE is a reminder that self-managed DevSecOps platforms only stay safe if operators keep pace with the supported release line.
Google’s Stable channel update closes 27 security holes across desktop platforms, and the most sensitive fixes point back to memory safety rather than flashy new features.
Several vulnerabilities have been resolved in PAN-OS and Prisma Access, and the technical lesson is clear: exposure depends on the exact branch, deployment model, and fix path, not just the product name.
A maintenance release for GitLab CE and EE closed eight flaws at once, showing how one platform can carry exposure across rendering, credentials, and permission checks.
A national alert about a large-scale CMS exploitation campaign points to a familiar but stubborn problem: internet-facing websites are only as safe as their weakest patch, plugin, or admin control.
An active campaign against content management systems shows how one unpatched plugin can become a foothold for web shells, credential theft, and lingering access.
Reported exploitation of known WordPress plugin vulnerabilities is being used to reach remote code execution and drop webshells for persistent access.