Cisco VPN flaw weaponized in active DoS attacks
A high-severity ASA and FTD vulnerability is being exploited to crash devices remotely; hot fixes are available.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
A high-severity ASA and FTD vulnerability is being exploited to crash devices remotely; hot fixes are available.
August's Patch Tuesday addresses 398 vulnerabilities, including an actively exploited zero-day, as AI-driven discovery swells update volumes.
Device-bound session credentials could curb account takeovers, but rollout is limited for now.
A flaw in Zoom's annotation tool could let any participant take over a sharer's client — with zero clicks.
Microsoft's August Patch Tuesday fixes 421 CVEs, including one exploited zero-day and two publicly disclosed flaws.
Researchers chain AI-found flaws to gain admin on SharePoint servers, bypassing authentication entirely.
Adobe's latest security update addresses over 50 vulnerabilities, with critical fixes for ColdFusion and Campaign Classic rated as top priority.
Sonatype finds six npm packages reading C2 addresses from an Ethereum wallet transaction linked to DPRK.
A Cursor bug let repositories run commands pre-trust, even with the sandbox enabled.
SAP's August 2026 patch batch addresses 28 flaws, including a 10/10 severity bug in Commerce Cloud that could allow attackers to bypass authentication and execute code.
Mozilla replaced the GPG key for Firefox and Thunderbird after an unencrypted copy leaked to a private GitHub repo.
Cloudflare mitigated over 800 network-layer DDoS attacks above 1 Tbps in Q2, a fivefold rise from Q1.
CISA adds CVE-2026-45659 to KEV catalog, confirming ransomware abuse of a Microsoft SharePoint RCE flaw.
Suisan City declared a state of emergency after a malicious software infection disrupted emergency services, highlighting a pattern of local government attacks.
Malicious SIM cards can force phones to leak files, drop to 2G, or crash—by abusing standard SIM commands.
Marcus Hutchins, who halted WannaCry, recounts his path from malware author to security researcher.
New Make UK report finds half of UK manufacturers lack a formal cyber incident response plan despite rising incidents.
Most security leaders are confident they can detect rogue AI agents — but few can act fast enough.
As AI accelerates account takeover attacks, experts argue credentials alone can no longer secure access.
Recent research shows passkey protections can be bypassed without breaking the underlying cryptography.