Content Paint

vulnerabilities

CVSS 10 bug in React, Next.js triggers security klaxons

Pre-auth RCE, trivial exploitation, a massive blast radius...

Oracle exploit: IAM under attack

Ye Olde Fashioned authentication filters in a Groovy codebase to blame.

Fortinet firewalls under "widespread" attack

Auth-bypass to Admin ftw...

The hyperscaler's AI vs the "hobby coders": A security row escalates

The Stack speaks to those at the centre of the community's latest week-long debate on vulnerability disclosure and open source patching.

Microsoft pushes emergency patch for WSUS 0day

"If the WSUS Server Role is enabled on your server, disable it"

Cisco 0day exploitation: Scans suggested it’s coming

CISA: "Permanently disconnect these devices on or before September 30, 2025"

SolarWinds warns over pre-auth RCE help desk bug

Expect this to get exploited - like the bug before it...

Google patches type confusion zero-day in Chrome's V8 engine

The bug was discovered by its government-backed attacks focused research group.

A robotic manufacturing arm at work, a vulnerability Dassault Systèmes' DELMIA Apriso software is being exploited.

Dassault Systèmes software used by major manufacturers including Boeing supplier.

Search the site

Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Great! You've successfully signed up.
Great! You've successfully signed up.
Welcome back! You've successfully signed in.
Success! You now have access to additional content.