CISA adds critical Gitea RCE CVE-2026-60004 to its KEV catalog. Discover how default registration settings enable Git hook exploitation and host takeover.
Latest news
Latest cybersecurity dispatches
Fresh reporting on active vulnerabilities, security patches, incident response, and threat research for defenders.
Threat actors chain Starlette and LiteLLM flaws to achieve unauthenticated RCE and steal enterprise AI keys. Discover key forensic details and patch steps.
Prompt injection resists a model-layer fix. Inside the agent control plane: workload identity, brokered credentials and blast-radius caps at the tool call.
Commercial spyware exploits Linux kernel flaw CVE-2024-36971 to hijack Android devices. Learn the technical mechanics, exploit chain, and how to patch now.
Critical Apache OFBiz vulnerabilities CVE-2024-38856 & CVE-2024-45195 allow unauthenticated RCE. Discover how attackers exploit them and how to mitigate now.
Explore CVE-2024-38213 (Copy2Pwn), the Windows SmartScreen zero-day bypass exploited by DarkGate via WebDAV UNC shares, plus detection and mitigation rules.
A critical SAML flaw (CVE-2024-6800, CVSS 9.5) lets attackers gain admin access on GitHub Enterprise Server. Learn the exploitation mechanism and patch steps.
Alibaba’s Qwen3.8-Flash-Next beats DeepSeek-V4-Flash on SWE-bench Pro with 6B active parameters. Explore full benchmarks, architecture, and enterprise TCO.