A SharePoint bug rated 5.3 by Microsoft and 9.8 by NVD is already under active attack. Vendor severity ratings are falling behind AI-accelerated exploits.
News
-
-
A contractor exposing CISA’s credentials on GitHub is the easy story. The nine ignored security alerts that followed reveal the failure worth fixing.
-
Google’s Threat Analysis Group found a critical Zimbra XSS vulnerability in the Classic Web Client that lets a crafted email hijack a live session. Zimbra has patched it in version …
-
An exposed criminal server reveals exactly which plugin flaws powered a mass WordPress webshell attack. Use this checklist to check your own sites now.
-
A local Windows Defender vulnerability, CVE-2026-50656, let any logged-in user reach SYSTEM for nearly 29 days before Microsoft shipped a fix.
-
GhostLock’s real lesson isn’t the bug, it’s the eleven weeks most businesses spent unpatched after the fix shipped. Linux kernel patching needs urgency.
-
BeyondTrust has fixed two pre-authentication bypass flaws in Remote Support and Privileged Remote Access. Here is a practical checklist for IT teams still running self-hosted appliances.
-
A 16-year-old hypervisor escape vulnerability in Linux KVM shows guest isolation is an assumption, not a fact. Here’s why that should change how you scope security testing.
-
What happens during a thick client penetration test, what testers find most often, and how to choose a provider.
-
A US county paid roughly $1 million to a group that never encrypted a single file, exposing how far data-theft extortion has moved beyond classic ransomware.