Content Paint

vulnerabilities

Langflow instances are getting exploited – again

"“These deployments rarely got the hardening a production web app would. They run with default authentication settings and sit on public IPs because someone needed to demo a flow to a stakeholder..."

Defender under attack, "HTTP/2 Bomb" - and other record Patch Tuesday notes

Plus a fresh exploit from Nightmare Eclypse.

Microsoft looks to turn down  temperature amid ongoing "Nightmare Eclipse" spat

"To be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research."

Microsoft stirs a hornets nest over “criminal” zero day disclosure threats

A BitLocker "backdoor" remains unpatched, whilst "RedSun", "UnDefend, "BlueHammer" get exploited in the wild.

Over 10 threat groups are now feasting on your Cisco SD-WAN

The latest open door? A CVSS 10 authentication bypass, for network on a plate

Pwn a CEO with a single email? Patch Tuesday brings nasty zero-click Outlook bug

Redmond "lists this as a Microsoft Word bug, which may or may not be entirely accurate... it is a genuine Outlook 0-click RCE"

Copy Fail exploitation has begun, and Brian Pak is sorry for the chaos

"The current coordination model really needs to be improved..."

Linux bug “Copy Fail”: Short Python script gives root on… everything?

“A very stable and straightforward exploit” across distros, developed after Xint Code pointed an LLM at the Linux kernel for “about an hour”

The internet's control plane, cPanel is under attack

Pre-auth RCE to root with a few HTTP requests. First IOCs start landing...

Search the site

Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Great! You've successfully signed up.
Great! You've successfully signed up.
Welcome back! You've successfully signed in.
Success! You now have access to additional content.