OverviewOn September 14, 2026, Cisco published a security advisory for CVE-2026-76461, a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The…
TLDR: Exploit. This is a deterministic local privilege escalation affecting the default install of the latest Arch, Fedora, Debian, Amazon Linux and RHEL distributions, having unprivileged user…
How Brutus grew into an engine that finds your identities, tests them everywhere they’re accepted, and remembers what it confirms. An attacker rarely needs a novel exploit when a valid username and…
La simulation de services Active Directory légitimes sur un réseau interne est une capacité puissante et polyvalente qui peut être exploitée dans le contexte de divers vecteurs d'attaque. De nombreux…
Lors du Pwn2Own Berlin 2025, nous avons exploité VMware Workstation en abusant d'un Heap-Overflow dans l'implémentation de son contrôleur PVSCSI. L'allocation vulnérable atterrissait dans…
1Password’s FLAWED report, published on August 6, 2026, gives defenders a misleading picture of AI patching. Its headline says models produced clean fixes only 26% of the time. That figure includes…
CVE-2026-76460: Cisco ISE Flaw Actively Exploited CVE-2026-76460 represents a critical security flaw in Cisco’s Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Because…
CVE-2026-76461: Cisco Email Gateway Flaw Exploited Cisco has confirmed active exploitation of CVE-2026-76461, a critical SQL injection vulnerability in Cisco Secure Email Gateway that can lead to…
CVE-2026-27540 WooCommerce Flaw Exploited Attackers are actively exploiting CVE-2026-27540, a critical arbitrary file-upload vulnerability in the WooCommerce Wholesale Lead Capture plugin for…
Agentic Ransomware: From Human-Operated to AI-Operated Attacks Ransomware has always needed a human involved somewhere: an affiliate navigating a network by hand, or at minimum, a person who wrote…
GitLab CVE-2026-85706 Added to CISA KEV CVE-2026-85706 represents a severe path traversal flaw in GitLab CE and EE, permitting unauthenticated remote actors to retrieve arbitrary files from affected…
On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with an estimated 6,000…
On August 21 and August 22, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, identified two independent critical vulnerability chains in The Events Calendar, a WordPress…
A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD)…
A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall…
Multiple vulnerabilities in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat…
A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an…
A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated…