Install
Vulnerabilities & Patching
CVEs, exploits, SBOMs, and patch prioritization and virtual patching guides.
- 4 Tracked terms
- Last 30 days Feed window
What this topic collects on
An article joins this feed when it matches these terms. Each one is also a search of its own.
Related topics
Latest in Vulnerabilities & Patching
What if the latest iPhone, which I bought for nearly 2 million won, suddenly turned off and turned o.. - MK
1+ day, 14+ hour ago (531+ words) What if the latest iPhone, which I bought for nearly 2 million won, suddenly turned off and turned on again a day after I bought it. Users are reporting that Apple's iPhone 18 Pro and Pro Max products released in Korea on…...
CVE-2026-87886: Insecure File Permissions in Acronis Backup Plugins for cPanel, WHM and Plesk
23+ hour, 33+ min ago (1202+ words) Vulnerability overview CVE-2026-87886 is a privilege escalation vulnerability in the Acronis Backup plugin for cPanel & WHM (Linux) and the Acronis Backup extension for Plesk (Linux). CERT-In published the note as CIVN-2026-0466 with a HIGH severity rating on 18 September 2026, and Acronis…...
ISC Patches 14 Vulnerabilities in BIND 9 Security Update
4+ day, 9+ hour ago (404+ words) Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process. Internet Systems Consortium (ISC) has released fresh security updates for BIND, the widely used open source DNS server software, resolving 14 vulnerabilities…...
CVE-2026-48710 (BadHost): How a Malformed Host Header Bypasses Starlette Path Authorization
5+ day, 13+ hour ago (1523+ words) Vulnerability overview CVE-2026-48710, tracked publicly as BadHost and catalogued by X41 D-Sec as X41-2026-002, is an authentication bypass in the Starlette ASGI framework. The flaw is CWE-444, inconsistent interpretation of HTTP requests. Starlette maintainers published a GitHub security advisory with a CVSS…...
Korra (@korraflow) on X
6+ day, 6+ hour ago (392+ words) ‼️ BREAKING: Our investigations team at Duel is in contact with the Revolut hacker, and we've found out a lot more about how he did what he did. - The hacker got access to government employee accounts using an infostealer. After gaining…...
Solana Mobile Brevo Breach Exposes Users to Potential Phishing Threats
1+ week, 1+ day ago (200+ words) Solana Mobile said attackers gained unauthorized access to its Brevo marketing account, potentially exposing customer information in a security incident at the email provider. The company disabled its Brevo account after discovering the breach and is working with the provider…...
Solana Mobile Suspends Brevo Account Following Unauthorized Access
1+ week, 2+ day ago (79+ words) Solana Mobile disclosed that a security incident occurred at third-party marketing email service provider Brevo, affecting some customer accounts, including Solana Mobile's own account. The team immediately suspended the account after discovering unauthorized access and is verifying the scope of…...
Trezor, BitBox Warn of Phishing Emails After Email Provider Breach
1+ week, 4+ day ago (965+ words) Hardware wallet makers Trezor and BitBox have warned users about a coordinated phishing campaign in which fraudulent security alerts were sent through legitimate looking email infrastructure. The campaign emerged on September 9, with attackers impersonating Trezor and BitBox and using claims…...
A Critical WHMCS RCE Just Got Patched. Did You Update?
1+ week, 5+ day ago (642+ words) Lillian Castro, Senior Editor Lillian Castro brings more than 30 years of editing and journalism experience to our team. She has written and edited for major news organizations, including The Atlanta Journal-Constitution and the New York Times, and she previously served…...
Hundreds of old, vulnerable Exchange servers remain in Australia
1+ week, 6+ day ago (370+ words) Unpatched and ancient Microsoft Exchange servers that are vulnerable to a critical authentication bypass vulnerability are rife on Australian and New Zealand networks, putting organisations' mailboxes in risk of full compromise. Worse, there is now working exploit code publicly available…...