You cannot patch everything, so prioritize well Every organization faces more vulnerabilities than it can fix at once. The teams that stay ahead are not the […]
In October 2025, F5 disclosed that a sophisticated, likely nation-state actor had maintained long-term access to its internal systems and stolen portions of BIG-IP source code […]
In late July 2025, active exploitation of on-premises Microsoft SharePoint Server put a large number of organizations into incident-response mode almost overnight. The exploit chain, widely […]
In April 2025, Fortinet warned that attackers who had exploited older FortiOS SSL-VPN vulnerabilities were maintaining read-only access to affected devices through a symbolic link, even […]
January 2025 opened with another edge-device zero-day. Ivanti disclosed CVE-2025-0282, a critical stack-based buffer overflow in Connect Secure, Policy Secure, and related gateways, that was already […]
In late September 2024, a set of vulnerabilities in the CUPS printing system on Linux and Unix-like machines was disclosed, chained together to allow remote code […]
On July 1, 2024, researchers disclosed regreSSHion, tracked as CVE-2024-6387, an unauthenticated remote code execution flaw in OpenSSH on glibc-based Linux systems. OpenSSH is one of […]