Zero-Day in Widely Deployed VPN Stack Exposes 40,000 Enterprise Networks
Pre-auth RCE in a major enterprise VPN platform. Active exploitation confirmed. Patch availability remains limited.
Pre-auth RCE in a major enterprise VPN platform. Active exploitation confirmed. Patch availability remains limited.
A compromised third-party vendor introduced a backdoored update that exfiltrated customer PII over 60 days before detection.
Researchers demonstrate a practical lattice reduction attack against RSA-2048 keys generated with low-entropy seeds on embedded devices.
A public proof-of-concept for a local privilege escalation in Linux kernel 6.x has been released. Affects all major distributions.
The official challenge archive from DEF CON 34 qualifiers is now available. Includes binary exploitation, reverse engineering, and crypto challenges.
A path traversal vulnerability in Apache HTTP Server 2.4.x allows unauthenticated attackers to read files outside the web root.
Over 2.3 million patient records were publicly accessible for an estimated 11 days due to a misconfigured cloud storage bucket.
NIST has published final versions of ML-KEM, ML-DSA, and SLH-DSA. A breakdown of migration timelines and implementation guidance.