Content Paint

vulnerabilities

December's Patch Tuesday brings an 0day - and prompt injection warnings

Microsoft patched 1,139 vulnerabilities in 2025. This month, look out for...

React2Shell: FUD, loathing and mass exploitation

"A clean ‘this was a successful exploit’ signal isn’t really possible here. The only reliable detection is post-exploitation activity on the box..."

CVSS 10 bug in React, Next.js triggers security klaxons

Pre-auth RCE, trivial exploitation, a massive blast radius...

Oracle exploit: IAM under attack

Ye Olde Fashioned authentication filters in a Groovy codebase to blame.

Fortinet firewalls under "widespread" attack

Auth-bypass to Admin ftw...

The hyperscaler's AI vs the "hobby coders": A security row escalates

The Stack speaks to those at the centre of the community's latest week-long debate on vulnerability disclosure and open source patching.

Microsoft pushes emergency patch for WSUS 0day

"If the WSUS Server Role is enabled on your server, disable it"

Cisco 0day exploitation: Scans suggested it’s coming

CISA: "Permanently disconnect these devices on or before September 30, 2025"

SolarWinds warns over pre-auth RCE help desk bug

Expect this to get exploited - like the bug before it...

Search the site

Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Great! You've successfully signed up.
Great! You've successfully signed up.
Welcome back! You've successfully signed in.
Success! You now have access to additional content.