OpenSSL Bug Silently Devours Memory
A newly identified memory-fragmentation flaw in OpenSSL allows attackers to exhaust server resources without triggering standard defenses.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
A newly identified memory-fragmentation flaw in OpenSSL allows attackers to exhaust server resources without triggering standard defenses.
A new campaign targeting Vite developers uses a four-tier blockchain infrastructure to bypass traditional security takedown efforts.
A newly identified Go-based botnet is pivoting from simple compute-hijacking to harvesting cloud credentials from exposed AI services.
New York startup Beacon Security raises $13 million to develop an agentic platform for security data and threat visibility.
A critical authentication bypass in Android allows unauthorized users to send messages via Gemini without requiring a device PIN.
A critical vulnerability identified in Zoom's Windows desktop software exposes users to potential unauthorized account access.
A critical business logic vulnerability in HCL Aftermarket EPC allows unauthorized users to intercept passwords via email redirection.
Corporate security ranks see high turnover as organizations across diverse sectors bring on new chief information security officers.
Military forces are racing to deploy autonomous systems, but true dominance depends on building a secure, trusted information grid.
A severe vulnerability in YAML::Syck versions before 1.47 allows memory reads via malformed binary data.
Sandworm, Russia's notorious military intelligence unit, is now deploying the deceptive Clickfix CAPTCHA method to compromise targets.
A new integration between 1Password and Claude shifts the model of AI credential management, but challenges remain for user trust.
A critical privilege escalation flaw in the Bricksforge plugin allows unauthenticated attackers to create new administrator accounts.
A critical vulnerability in the Grav login plugin allows attackers to bypass two-factor authentication protections.
Modern security programs are failing to see deep inside SaaS platforms, leaving sensitive data exposed through quiet misconfigurations.
A hard-coded JWT secret in self-hosted clawvet API servers allows remote attackers to bypass authentication and harvest sensitive data.
A major cyberattack on Japanese food giant Nichirei exposes the fragility of global cold storage and automated shipping networks.
Microsoft prepares for the transition of Windows Server 2022 to extended support, marking a key milestone for enterprise infrastructure.
ACR Stealer exploits user-executed commands to siphon session tokens and files, bypassing traditional software vulnerabilities.
Senior leadership is actively bypassing security protocols for AI, creating a dangerous precedent that undermines enterprise governance.