Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM...
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM...
Ravie LakshmananAug 18, 2026Vulnerability / Artificial Intelligence Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA,...
Swati KhandelwalAug 17, 2026Vulnerability / DevOps GitLab has released security updates to address a critical vulnerability impacting its Community Edition...
Ravie LakshmananAug 17, 2026Vulnerability / Website Security A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin...
A critical Zoom vulnerability chain could have allowed an attacker to take control of another participant’s device simply by joining...
Ravie LakshmananAug 12, 2026Vulnerability / Web Security Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce,...
Ravie LakshmananAug 06, 2026Network Security / Vulnerability Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst...
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files...
Swati KhandelwalJul 29, 2026Vulnerability / DevOps Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A...
JetBrains has patched a critical TeamCity vulnerability that could allow unauthenticated attackers to run operating system commands on exposed, self-hosted...
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws...
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link...
Ravie LakshmananJul 21, 2026Email Security / Vulnerability Zimbra has rolled out fixes to address multiple critical security issues, including a...
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow...
A critical flaw in Zoom’s Windows software could allow an unauthenticated attacker to remotely take over an account, giving organizations...