Our news

  • Vulnerability Summary for the Week of June 22, 2026

    High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info abhisheksaha11–URL Preview The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0 via the ‘url’ parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web…

    READ MORE

  • Hacker in a hoodie typing on a laptop as red cyberattack lines strike a server rack, depicting a cyberattack scenario and defense ultimate goal.

    Why Firewalls and Edge Gateways are the New Primary Target

    For a long time, the unwritten rule of initial access was simple- trick a human. Phishing and social engineering were the easiest ways into a network because people are notoriously easy to manipulate. While those vectors haven’t gone anywhere, the threat landscape has shifted drastically over the past year. Sophisticated threat actors are completely bypassing…

    READ MORE

  • Vulnerability Summary for the Week of June 15, 2026

    High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info 10Web–Form Maker by 10Web Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions. 2026-06-15 9.3 CVE-2026-39502 404-redirection-manager–404 Redirection Manager The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL…

    READ MORE

  • CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure

    CISA is aware of global reports that malicious cyber actors have targeted internet-accessible Fortinet devices across government and private sector organizations using compromised credentials. This activity, referred to as FortiBleed, involves the exposure of leaked credentials associated with approximately 74,000 Fortinet devices, including firewalls and virtual private network (VPN) gateways.   To defend against this…

    READ MORE

  • Vulnerability Summary for the Week of June 8, 2026

    High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info AdguardTeam–AdGuardHome AdGuard Home, when started with the –glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full admin access by supplying a path traversal sequence in the Admin-Token cookie, exploiting unsanitized string concatenation in the token file path construction within…

    READ MORE

  • Vulnerability Summary for the Week of June 1, 2026

    High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info 10Web–Photo Gallery by 10Web Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection. This issue affects Photo Gallery by 10Web: from n/a through 1.8.41. 2026-06-04 7.6 CVE-2026-49771 AAM Plugin–Advanced Access…

    READ MORE

  • Hacker in a hoodie using a laptop surrounded by cybersecurity and cloud icons, illustrating a cyberattack scene

    How Threat Actors Are Abusing Microsoft Entra ID Self-Service Password Reset (SSPR) to Compromise Cloud Environments

    Threat actors are increasingly leveraging Microsoft Entra ID’s Self-Service Password Reset (SSPR) feature to conduct highly targeted, identity-driven attacks. Advanced threat groups, such as Storm-2949, have demonstrated how legitimate account recovery functionality can be manipulated to gain access to high-value executive and IT accounts. Once access is obtained, attackers move beyond traditional account compromise, targeting…

    READ MORE

  • Vulnerability Summary for the Week of May 25, 2026

    High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info 1Panel-dev–MaxKB MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB’s webhook trigger endpoint (/api/trigger/v1/webhook/{trigger_id}) is accessible without authentication. The WebhookAuth class unconditionally returns (None, {}), which Django REST Framework interprets as successful authentication. Combined with optional per-trigger token verification and no…

    READ MORE

  • Supply Chain Compromises Impact Nx Console and GitHub Repositories

    CISA is prioritizing the response to multiple emerging software supply chain intrusion campaigns targeting developer ecosystems Continuous Integration/Continuous Development (CI/CD) pipelines. These recent incidents, including the GitHub compromise via a malicious Nx Console Visual Studio Code (VS Code) extension and the “Megalodon” supply chain intrusion campaign, demonstrate how cyber threat actors are abusing tools and…

    READ MORE

  • Vulnerability Summary for the Week of May 18, 2026

    High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info 10-Strike–Network Inventory Explorer 10-Strike Network Inventory Explorer 8.54 contains a stack-based buffer overflow vulnerability in the registration key input field that allows local attackers to execute arbitrary code by triggering a structured exception handler overwrite. Attackers can craft a malicious registration key string with…

    READ MORE