Session Hijacking 2.0 — The Latest Way That Attackers are Bypassing MFAThe Hacker News·Sep 30, 12:50 UTC · Sep 30, 2024Vulnerability30
in(Secure) messaging apps — How side-channel attacks can compromise privacy in WhatsApp, Telegram, and SignalCisco Talos·Dec 10, 16:51 UTC · Dec 10, 2018Vulnerability42
OWASP Top 10 for .NET developers part 9: Insufficient Transport Layer ProtectionTroy Hunt·Nov 28, 00:00 UTC · Nov 28, 2011Vulnerability30
Flaw in WordPress Live Chat Plugin allows to steal and hijack sessionsSecurity Affairs·Jun 11, 19:53 UTC · Jun 11, 2019VulnerabilityCVE-2019-1249860
AWS Patches Critical 'FlowFixation' Bug in Airflow Service to Prevent Session HijackingThe Hacker News·Mar 22, 13:45 UTC · Mar 22, 2024Vulnerability55
Citrix warns admins to patch NetScaler CVE-2023Security Affairs·Oct 25, 09:56 UTC · Oct 25, 2023Vulnerability in the wildCVE-2023-496660
The latest high-severity Citrix vulnerability under attack isn’t easy to fixArs Technica · Security·Oct 19, 21:56 UTC · Oct 19, 2023Vulnerability in the wildCVE-2023-496660
Threat actors have been exploiting CVE-2023-4966 in Citrix NetScaler ADC/Gateway devices since AugustSecurity Affairs·Oct 18, 13:56 UTC · Oct 18, 2023Vulnerability in the wildCVE-2023-4966CVE-2023-351960
VMware pushes admins to uninstall vulnerable, deprecated vSphere plugin (CVE-2024-22245, CVE-2024-22250)Help Net Security·Feb 25, 16:34 UTC · Feb 25, 2024VulnerabilityCVE-2024-22245CVE-2024-22250135
Magento fixed security flaws that allow complete site takeoverSecurity Affairs·Jul 4, 13:50 UTC · Jul 4, 2019Vulnerability42
Fortinet warns about Critical flaw in Wireless LAN Manager FortiWLMSecurity Affairs·Dec 19, 13:53 UTC · Dec 19, 2024VulnerabilityCVE-2023-34990CVE-2023-4878260
VMware fixes several flaws in its ESXi, Workstation, Fusion and NSX-TSecurity Affairs·Oct 22, 07:26 UTC · Oct 22, 2020VulnerabilityCVE-2020-3992CVE-2020-3993CVE-2020-399460
Critical n8n Flaw CVE-2026-25049 Enables System Command Execution via Malicious WorkflowsThe Hacker News·Feb 6, 09:39 UTC · Feb 6, 2026VulnerabilityCVE-2026-25049CVE-2025-68613CVE-2026-21893+10 CVEs160
How A Bug Hunter Forced Apple to Completely Remove A Newly Launched FeatureThe Hacker News·Jan 20, 18:36 UTC · Jan 20, 2017Vulnerability30
The browser is eating your security stackHelp Net Security·Nov 13, 00:00 UTC · Nov 13, 2025Vulnerability42
CitrixBleed 2 Vulnerability ExploitedInfosecurity Magazine·Jun 27, 10:15 UTC · Jun 27, 2025Vulnerability in the wildCVE-2025-5777CVE-2025-5349CVE-2023-4966+1 CVEs60
Bugs in Avast AntiTrack expose users to cyber attacksSecurity Affairs·Aug 23, 22:53 UTC · Aug 23, 2022VulnerabilityCVE-2020-898735
‘Citrix Bleed’ vulnerability targeted by nationThe Record·Nov 21, 19:18 UTC · Nov 21, 2023Vulnerability in the wildCVE-2023-4966CVE-2023-491160
Unpatched ScreenConnect servers open to attack (CVE-2026-3564)Help Net Security·Mar 20, 00:00 UTC · Mar 20, 2026Vulnerability in the wildCVE-2026-356460
CitrixBleed 2 might be actively exploited (CVE-2025-5777)Help Net Security·Jun 30, 00:00 UTC · Jun 30, 2025Vulnerability in the wildCVE-2025-5777CVE-2025-6543CVE-2025-5349+1 CVEs60
Citrix Releases Emergency Patches for Actively Exploited CVE-2025The Hacker News·Jul 1, 13:29 UTC · Jul 1, 2025Vulnerability in the wildCVE-2025-6543CVE-2025-5777CVE-2023-496660
OpenSSH bugs allows Man-in-theSecurity Affairs·Feb 19, 12:10 UTC · Feb 19, 2025VulnerabilityCVE-2025-26465CVE-2025-26466CVE-2024-6409+1 CVEs60
Top 5 Web App Vulnerabilities and How to Find ThemThe Hacker News·Dec 19, 10:43 UTC · Dec 19, 2022Vulnerability55
ThreatsDay Bulletin: AI Prompt RCE, Claude 0-Click, RenEngine Loader, Auto 0The Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026VulnerabilityCVE-2026-2084147
Fortinet Warns of Severe SQLi Vulnerability in FortiClientEMS SoftwareThe Hacker News·Mar 22, 03:02 UTC · Mar 22, 2024Vulnerability in the wildCVE-2023-48788CVE-2023-42789CVE-2023-42790160
How the SolarWinds Hackers Bypassed Duo's Multi-Factor AuthenticationSchneier on Security·Dec 15, 00:00 UTC · Dec 15, 2020Vulnerability30
VMware Alert: Uninstall EAP Now - Critical Flaw Puts Active Directory at RiskThe Hacker News·Feb 22, 02:28 UTC · Feb 22, 2024VulnerabilityCVE-2024-22245CVE-2024-22250CVE-2024-2172660
Patch your Asus RT wireless routers now to avoid ugly surprisesSecurity Affairs·May 11, 15:09 UTC · May 11, 2017VulnerabilityCVE-2017-5891CVE-2017-6547CVE-2017-6549+1 CVEs47
NVIDIA shader out-of-bounds and eleven LevelOne router vulnerabilitiesCisco Talos·Oct 31, 15:29 UTC · Oct 31, 2024VulnerabilityCVE-2024-0121CVE-2024-0117CVE-2024-0118+14 CVEs47
Cymatic announces first year customer milestonesHelp Net Security·Jan 23, 13:45 UTC · Jan 23, 2024Vulnerability30
CymaticONE + VADR's new features allow customers to protect their web properties from persistent attacksHelp Net Security·Oct 22, 00:00 UTC · Oct 22, 2020Vulnerability30
Why workforce identity is still a vulnerability, and what to do about itHelp Net Security·Mar 4, 00:00 UTC · Mar 4, 2026Vulnerability30
High-Severity Flaw in Open WebUI Affects AI ConnectionsInfosecurity Magazine·Jan 6, 15:30 UTC · Jan 6, 2026VulnerabilityCVE-2025-6449647
5 Threats That Reshaped Web Security This Year [2025]The Hacker News·Dec 4, 11:30 UTC · Dec 4, 2025VulnerabilityCVE-2025-54135CVE-2025-53109CVE-2025-5528460
Chinese DeepSeek-R1 AI Generates Insecure Code When Prompts Mention Tibet or UyghursThe Hacker News·Nov 24, 11:08 UTC · Nov 24, 2025Vulnerability55
New AI-Targeted Cloaking Attack Tricks AI Crawlers Into Citing Fake Info as Verified FactsThe Hacker News·Oct 29, 14:57 UTC · Oct 29, 2025Vulnerability42