N-able’s patch for its N-central platform didn’t fully close the door attackers used. Here is the step-by-step check for anyone running it, beyond just installing the update.
News
-
-
Veeam, HashiCorp’s Terraform MCP Server and Django all patched critical flaws within 48 hours, including a CVSS 10.0 bug. Here’s what happened and what to check.
-
A critical TeamCity flaw is being actively exploited. Here is a practical, step-by-step checklist for UK businesses to confirm exposure, patch and check for compromise.
-
A WordPress XSS vulnerability patched in version 7.0.3 needed no login to start. Here’s a plain-English explainer and five checks for your own sites.
-
A step-by-step look at how the Atomic macOS Stealer infects Mac users through fake fix-it websites, and a practical checklist for businesses to reduce the risk.
-
Cl0p-linked attackers are exploiting an unauthenticated flaw in PTC Windchill and FlexPLM. Here’s a practical checklist for finding out if you’re exposed.
-
The Cisco FMC vulnerability CVE-2026-20316 scores a modest 5.3 but is under active attack with no workaround. It’s a case study in why CVSS alone can’t drive your triage.
-
Broadcom has patched two 9.8-rated vCenter flaws and a VM escape bug in ESX. Here is what the VMware vCenter vulnerabilities mean for businesses running vSphere.
-
A step-by-step check for teams running Adobe Campaign Classic on-premise: confirm your build, check exposure, and patch a flaw that needs no login and no clicks.
-
The OWASP Top 10 was rebuilt for 2025. Here is what moved, what is new, and the questions worth asking before your next web application penetration test.