Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM...
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM...
SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers,...
Ravie LakshmananAug 17, 2026Vulnerability / Website Security A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin...
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus...
A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency...
A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers...
Ravie LakshmananAug 08, 2026Zero-Day / Vulnerability Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data...
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the...
Ravie LakshmananAug 06, 2026Vulnerability / Enterprise Security A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come...
A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on...
Swati KhandelwalAug 04, 2026Vulnerability / Database Security cPanel has patched a flaw that let an authenticated hosting customer execute SQL...
Swati KhandelwalAug 03, 2026Data Security / Vulnerability Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification...
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI...
Ravie LakshmananJul 28, 2026Vulnerability / Threat Intelligence A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has...