Fastjson 1.x RCE Vulnerability Under Active Attack With No Patch Available
Security firms ThreatBook and Imperva report active exploitation of a critical remote code execution vulnerability in Alibaba's Fastjson 1.x JSON library for…
Security firms ThreatBook and Imperva report active exploitation of a critical remote code execution vulnerability in Alibaba's Fastjson 1.x JSON library for…
A Russian state-sponsored espionage group exploited a zero-day vulnerability in Zimbra's webmail client to steal emails, passwords, and two-factor authentication recovery codes…
Group-IB has uncovered a China-nexus cyber operation tracked as JadeProx, which has been targeting government, healthcare, and education organizations across Asia and…
Check Point has released security updates to address multiple vulnerabilities in its Security Management and Multi-Domain Management (MDSM) products, including a critical…
A high-severity path traversal vulnerability in the open-source developer platform Windmill, tracked as CVE-2026-29059 (CVSS 7.5), is under active exploitation. The flaw…
A critical remote code execution vulnerability in Microsoft SharePoint Server, CVE-2026-50522 (CVSS 9.8), is being actively exploited in the wild following the…
The cybersecurity industry initially focused on the volume of new CVEs introduced by Anthropic's Mythos AI model, but the real threat lies…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability in Microsoft SharePoint Server, tracked as…
A critical vulnerability in n8n's Enterprise token exchange feature, tracked as CVE-2026-59208, allows attackers to log in as any user by exploiting…
A SharePoint Server vulnerability exploited by threat actors to gain unauthorized access to on-premises instances, as warned by CISA.