ShareFile Patch Addresses Path Traversal
Progress confirms a high-severity flaw in Storage Zone Controllers necessitated a temporary service shutdown for customers.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
Progress confirms a high-severity flaw in Storage Zone Controllers necessitated a temporary service shutdown for customers.
A newly identified Rust-based remote access tool uses modular runtime configuration to maintain persistence in compromised environments.
A wide-ranging update from Adobe addresses 88 vulnerabilities across 12 products, focusing on critical ColdFusion and Commerce bugs.
A widely used extension for developers and testers was found harboring spyware that sent user traffic data to remote servers.
A set of seven severe vulnerabilities in the VMware Avi Load Balancer has been addressed following reports from external researchers.
Microsoft is rolling out enhanced security measures in Defender for Cloud Apps to combat the abuse of OAuth tokens by the ShinyHunters group.
The US Department of Defense has paused critical CMMC security assessment requirements to reevaluate the program's impact on innovation.
Critical access control vulnerabilities in RabbitMQ could allow attackers to bypass tenant boundaries and exfiltrate OAuth secrets.
NHS Forth Valley faces an investigation after an employee transferred sensitive maternity patient records to a personal email account.
A new C++ malware strain disguised as an Apple crash reporting tool is targeting local Keychain data and cryptocurrency wallets.
Researchers identify lingering vulnerabilities in the Claude for Chrome extension that could bypass authorization for sensitive account access.
SpaceXAI's CLI tool was caught uploading full repositories, sparking urgent data deletion promises from Elon Musk.
Researchers identify Jalisco and OmegaLord as new threats targeting Microsoft 365 through advanced credential and device exploitation.
A jailbroken AI model enabled a lone operator to execute complex cyber-fraud, automating server migrations in just minutes.
A study of 85 browser-based wallets reveals systemic privacy flaws that allow for cross-site tracking and the de-anonymization of users.
International intelligence agencies warn that Russian state actors are actively exploiting network infrastructure and legacy devices.
CISA mandates action on two high-severity Joomla extension vulnerabilities being actively exploited to gain remote server control.
By integrating validation data into AI agents, organizations can pivot from theoretical risk assessment to verifiable, evidence-based security.
Threat actors are weaponizing OAuth client ID spoofing to validate stolen credentials while remaining invisible to standard telemetry.
New security disclosures address high-stakes vulnerabilities in NetWeaver and Commerce Cloud, demanding immediate enterprise action.