CVE-2026-3502: TrueConf Client Zero-Day Exploited in the Wild
CVE-2026-3502 is a high-severity security flaw in the TrueConf client that was exploited as a zero-day in campaigns targeting government entities in…
CVE-2026-3502 is a high-severity security flaw in the TrueConf client that was exploited as a zero-day in campaigns targeting government entities in…
TrueConf Client is the client application for TrueConf videoconferencing. It has been targeted by attackers through poisoned installers and a zero-day vulnerability…
OpenAI has announced it is pausing certain internal activities involving its upcoming artificial intelligence model, Astra, after an internal evaluation indicated significant…
N-able has issued Hotfix 2 for its N-central Remote Monitoring and Management (RMM) product, responding to ongoing exploitation of a recently disclosed…
Metabase is a business intelligence and data visualization platform. A critical zero-day vulnerability (CVSS 10.0) allows unauthenticated attackers to inject SQL and…
Metabase has disclosed a maximum-severity zero-day vulnerability in its business intelligence and data visualization software that is being actively exploited in the…
Metabase, a provider of business intelligence and data visualization software, disclosed a maximum-severity zero-day vulnerability (CVSS 10.0) that is being exploited in…
Framework, a PC manufacturer, was affected by the Metabase zero-day exploitation. The company alerted customers that personal information including names, login IPs,…
A desynchronization zero-day in Apache Traffic Server was exposed during human-guided research by PortSwigger. The issue has been patched, but public records…
Apache Traffic Server was found to have a desynchronization zero-day vulnerability (CVE-2026-63078) during research by PortSwigger. The issue has been patched, but…