Critical SQL Injection Hits PROCON-WEB SCADA
A critical vulnerability in the PROCON-WEB SCADA GetGridData endpoint allows unauthenticated attackers to execute arbitrary SQL commands.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
A critical vulnerability in the PROCON-WEB SCADA GetGridData endpoint allows unauthenticated attackers to execute arbitrary SQL commands.
Microsoft introduces automated AI agents for vulnerability management amid rising industry concern over autonomous security threats.
A critical out-of-bounds read vulnerability in Apache Thrift C++ bindings allows for potential data exposure and service disruption.
A critical vulnerability in Apache Thrift c_glib bindings allows for potential memory exposure and system instability, requiring an immediate update.
A severe heap-based buffer overflow in Apache Thrift C++ bindings allows remote attackers to compromise systems; users must update to version 0.24.0 immediately.
A critical OS command injection vulnerability in Arista VeloCloud Orchestrator is now confirmed to be exploited in the wild.
A critical vulnerability in SiYuan desktop allows attackers to achieve remote code execution through a malicious deep link, necessitating an immediate update.
Learn how security researchers and developers use proof of concept demonstrations to validate vulnerabilities and improve software resilience.
Learn how browser-based discovery functions as a reconnaissance technique used to map internal network resources from a web browser.
Learn about the security implications of persistent permissions and why maintaining control over account access is vital for digital safety.
As automated agents become integrated into workflows, security teams struggle to maintain visibility over decentralized, unmanaged AI deployments.
Researchers used AI agents to uncover remote code execution vulnerabilities in Redis, prompting seven urgent security releases.
A malicious Claude Artifact led users to download a remote access trojan, compromising at least 29 organizations in a recent campaign.
A critical vulnerability in Anthropic's Claude Cowork allows AI agents to escape their Linux virtual environment and access host macOS data.
A critical vulnerability in the @better-auth/scim plugin allows authenticated users to hijack accounts via provider ID collisions and bypass security controls.
A critical vulnerability in Bing's image processing reveals the risks of treating image conversion tools as simple infrastructure.
Threat actors are increasingly leveraging vulnerabilities in VPNs and firewalls to gain direct access to corporate networks.
A chain of vulnerabilities in 9router allows unauthenticated attackers to gain full control of the host operating system via default credentials.
A critical vulnerability in Check Point's management software allows attackers to bypass authentication and control network policy.
A path traversal flaw in h2oGPT versions 0.2.1 and earlier allows unauthenticated attackers to read, write, or delete files, potentially leading to RCE.