Citrix NetScaler Root-Level RCE Flaw Goes Public With Working Exploit Code
A publicly released proof-of-concept shows how a pre-authentication heap overflow in Citrix NetScaler ADC and Gateway can be turned into unauthenticated, root-level remote code execution. There is no...
‘Bring Your Own EDR’ Trick Turns SentinelOne Into a Bodyguard for Malware
DEF CON 34 research shows how trusted SentinelOne components could be abused to dump memory from Windows' most protected processes, ultimately shielding malicious payloads behind the endpoint agent's...
Five New TP-Link Flaws Let Attackers Hijack ISP-Managed Routers and Mesh Systems
TP-Link has disclosed five vulnerabilities affecting its carrier-supplied Aginet router, mesh, and modem lineup, the worst of which lets an attacker on the network bypass authentication entirely. Because...
Unpatched GeoServer Zero-Day Under Active Attack as Researchers Warn of RCE Risk
A newly disclosed, unpatched SQL injection flaw in the open-source mapping platform GeoServer is already being probed by attackers just hours after it went public. Under certain database...
Zoom Patches ‘Zoomsday’ Flaw That Let Meeting Guests Hijack Devices Without a Single Click
Zoom has fixed four vulnerabilities in its meeting clients, including a high-severity bug dubbed 'Zoomsday' that let any meeting participant execute code on another attendee's device with zero...
Microsoft’s August 2026 Patch Tuesday Closes 394 Flaws, Including One Zero-Day Already Under Attack
Microsoft's August 2026 security update addresses 394 vulnerabilities spanning Windows, Office, SharePoint, Azure, and developer tools, including three zero-days. One of them, a Windows kernel driver flaw tied...
Lazarus Group Weaponizes Windows Kernel Zero-Day to Deploy Next-Generation FudModule Rootkit
Check Point Research has caught North Korea's Lazarus group exploiting a previously unknown Windows kernel flaw, CVE-2026-68820, to plant an upgraded FudModule rootkit on defense and aerospace targets....
New Outlook Flaw Lets Attackers Run Malicious Code Through a Single Booby-Trapped Email Attachment
Microsoft has patched a high-severity remote code execution flaw in Outlook, tracked as CVE-2026-70329, that can be triggered when a victim opens a specially crafted Office file. The...