CVE-2026-33824 Exploited Against Windows IKE VPNs
CVE-2026-33824 is now in CISA’s exploited-vulnerability catalog. Check whether a Windows IKEv2…
ENDLESSDOORS Backdoor in Zbtlink Routers: 20 Models to Replace
ENDLESSDOORS is embedded in firmware for 20 tested Zbtlink and Wiflyer router…
Rails CVE-2026-66066: Patch Active Storage and Rotate Secrets
Rails patched CVE-2026-66066 in Active Storage. Check whether your app uses vulnerable…
Coldcard Seed Flaw: Update Firmware and Move Funds
Coldcard weak seed generation affects Mk3 and earlier Mk4, Mk5, and Q…
Copilot Word AI Worm Can Spread Hidden Prompts Between Documents
A Copilot for Word test showed a hidden instruction copying itself into…
Cisco FMC CVE-2026-20316 Exploited: Check and Patch
Cisco says attackers are exploiting a static credential in on-premises Secure FMC.…
CVE-2026-16812 Exploited in VeloCloud Orchestrator
Arista confirms active exploitation of CVE-2026-16812 in VeloCloud Orchestrator On-Prem. Check affected…
Fastjson CVE-2026-16723: Enable SafeMode on 1.x Now
Fastjson 1.2.68–1.2.83 can allow unauthenticated RCE in Spring Boot fat JARs. Check…
AWS Kiro Flaw Turned Hidden Web Text Into Code Execution
AWS patched a Kiro IDE flaw that let hidden web text rewrite…
NGINX CVE-2026-42533: Check Regex Maps and Update Now
CVE-2026-42533 affects NGINX map directives with regex captures. Check the exposure pattern…
Cursor git.exe Flaw: Check Windows Repositories Before Opening
A disclosed Cursor flaw can run a repository-local git.exe on Windows when…
Tangem Laser Attack Can Reset Wallet Card Access Codes
Ledger Donjon demonstrated a lab-grade laser attack that resets a Tangem card…
