An exploited zero-day in Check Point SmartConsole turns a management tool into the most sensitive part of the network: the place where security decisions are made.
A new alert on Exim is a reminder that mail software can become a privilege boundary, not just a message router.
SourTrade turns ordinary web delivery into a per-victim build process, a design that weakens hash-based detection and blurs the line between browsing and infection.
An ACN CSIRT Italia alert points to a layered risk in MongoDB Server and MongoDB Compass, where patching now depends on version, deployment, and how much trust an admin workstation is allowed to hold.
A rapid Redis vulnerability hunt tied to Kimi K3 shows how AI-assisted research can compress discovery time and raise the pressure on defenders to harden backend services.
A reported Redis vulnerability hunt by Moonshot AI's Kimi K3 points to a harder question for defenders: how quickly can agentic AI turn software behavior into a reproducible exploit hypothesis?
A high-severity path-handling flaw in Exim shows how a mail queue can become a filesystem boundary issue, with privilege impact depending on how the daemon is deployed.
An updated federal advisory puts PLC security back under the microscope, where exposed industrial controllers and weak access controls can turn a small intrusion into an operational problem.
A high-severity warning on some ASUS drivers shows how a trusted software layer can become a privilege-escalation path when its permissions are too broad and its checks are too thin.
MatheuZSecurity’s newly announced Furtex package puts raw io_uring and eBPF in the spotlight, showing how post-exploitation tooling can lean on legitimate Linux primitives to pursue stealthier process manipulation and data theft.
A long-running campaign tied to weakly managed network gear shows how routers can be turned into stealth relay points, not just broken devices.
Two exploited command-injection flaws put Fortinet’s sandbox appliance in the uncomfortable role of attack surface, not inspection shield.
A security product built to inspect suspicious content is now itself part of the threat surface, and federal agencies have been told to move fast.
OpenAI’s deployment of GPT-Red suggests a growing use of automated adversarial testing in model security, with prompt-injection failures fed back into GPT-5.6 hardening.
A new hardening push shows how routers have become a frontline security problem, where weak management settings can matter as much as software flaws.
An NSA-led advisory puts routine router administration under a hard spotlight, warning that exposed management paths can matter far beyond one network.
A fresh government warning turns attention to an old blind spot: exposed and poorly managed routers can become the easiest way into sensitive networks.
A multinational security alert puts exposed router management at the center of a repeatable access pattern that turns ordinary network gear into high-value footholds.
A joint cybersecurity advisory puts ordinary edge devices back in the spotlight, showing how weak router hygiene can turn into strategic access for sophisticated operators.
U.S. and allied cybersecurity agencies have warned that Russian state hackers are targeting vulnerable and poorly configured routers to reach critical infrastructure networks.