A newly patched issue in Cisco Secure Workload shows how a single unauthenticated flaw in a security control plane can carry outsize operational risk.
Microsoft is changing how Edge handles saved credentials at startup, after a researcher found passwords could sit in cleartext inside process memory during launch.
A critical authentication-bypass flaw in Four-Faith F3x36 routers shows how exposed management interfaces can turn industrial networking hardware into botnet infrastructure.
A set of critical SEPPmail gateway vulnerabilities shows how the systems built to protect sensitive mail can become the first place attackers look for code execution and message interception paths.
A new wave of attacks around “Nginx Rift” shows how a web server can become dangerous not only because of its version, but because of the way it is configured.
Multiple severe Linux-kernel bugs have revived dramatic talk of an emergency off-switch, but the real security story is the kernel’s patch pipeline, not a mythical panic button.
A recent round of April testing points to weaknesses in Apple’s desktop platform and shows how AI can sharpen vulnerability research without implying a live breach.
A controlled exploit contest in Berlin turned into a stress test for modern security layers, with researchers demonstrating 24 unique zero-days across Microsoft Edge, Windows 11, LiteLLM, and NVIDIA-related targets.
A financially motivated threat group is being linked to attacks on build-and-release workflows, a reminder that the most dangerous target in cloud security may be the system trusted to ship the code.
A Siemens HMI weakness shows how a small local access gap can become a serious industrial security problem when browser access and device controls are not tightly locked down.
A recent industrial-security disclosure points to a harder problem than a new exploit: post-detection escalation through already-compromised operational technology environments.
A critical flaw in a specialized MongoDB storage path shows how a narrow feature bug can still turn into server-side code execution when access controls are too loose.
Repeated exploitation of Microsoft Exchange against an Azerbaijani energy company shows how an exposed mail server can become a durable attack surface, even when defenders are already on alert.
A named extortion crew has tied Bestat Pharmaservices Corp. to an alleged attack, underscoring how modern ransomware now lives as much in stolen-data threats as in encryption.