CVE-2026-55553: urllib Redirects Can Leak Credentials
A high-severity Node.js urllib flaw can forward authentication headers on cross-origin redirects.…
Grok Cryptographic Context Injection Could Leak Chat History
Adversa AI showed how encrypted webpage instructions could make Grok expose current-chat…
CVE-2026-73570 Exploited Against Zimbra Servers
CVE-2026-73570 is exploited against Zimbra servers with SNMP notifications enabled. Check exposure,…
CVE-2026-72529 and CVE-2026-72530 Exploited in TrueConf Server
CISA says two TrueConf Server flaws are actively exploited. Check fixed versions,…
CVE-2026-33824 Exploited Against Windows IKE VPNs
CVE-2026-33824 is now in CISA’s exploited-vulnerability catalog. Check whether a Windows IKEv2…
ENDLESSDOORS Backdoor in Zbtlink Routers: 20 Models to Replace
ENDLESSDOORS is embedded in firmware for 20 tested Zbtlink and Wiflyer router…
Rails CVE-2026-66066: Patch Active Storage and Rotate Secrets
Rails patched CVE-2026-66066 in Active Storage. Check whether your app uses vulnerable…
Coldcard Seed Flaw: Update Firmware and Move Funds
Coldcard weak seed generation affects Mk3 and earlier Mk4, Mk5, and Q…
Copilot Word AI Worm Can Spread Hidden Prompts Between Documents
A Copilot for Word test showed a hidden instruction copying itself into…
Cisco FMC CVE-2026-20316 Exploited: Check and Patch
Cisco says attackers are exploiting a static credential in on-premises Secure FMC.…
CVE-2026-16812 Exploited in VeloCloud Orchestrator
Arista confirms active exploitation of CVE-2026-16812 in VeloCloud Orchestrator On-Prem. Check affected…
Fastjson CVE-2026-16723: Enable SafeMode on 1.x Now
Fastjson 1.2.68–1.2.83 can allow unauthenticated RCE in Spring Boot fat JARs. Check…
