CVE-2026-24306 : Critical Azure Front Door Flaw Opens Door to Silent Cloud Privilege Escalation
Azure Front Door – Privilege Escalation via Control-Plane Abuse CVE ID: CVE-2026-24306Affected Service: Azure Front DoorVulnerability Type:…
continue reading..
CVE-2025-54816: Critical WebSocket Authentication Flaw Exposes EV Charging Control Systems to Remote Takeover
CVE-2025-54816 — Missing Authentication on WebSocket Endpoint CVE ID: CVE-2025-54816Vulnerability Name: WebSocket Endpoint Missing AuthenticationCategory: Authentication Bypass…
continue reading..
CVE-2026-21264: Critical Flaw in Microsoft Account Login Pages Enables Spoofed Sign-In Attacks and Account Takeover Risk
CVE-2026-21264 — Microsoft Account XSS / Spoofing Vulnerability CVE Identifier: CVE-2026-21264CVSS v3.1 Score: 9.3 (Critical)Affected Component: Microsoft…
continue reading..
CVE-2026-24304: Critical Azure Resource Manager Flaw Opens Door to Cloud Tenant Takeover
CVE-2026-24304 – Azure Resource Manager Privilege Escalation CVE ID: CVE-2026-24304Component: Azure Resource Manager (ARM)Vulnerability Type: Improper Access…
continue reading..
CVE-2026-0775: npm CLI Bug Turns Developer Machines Into Privilege Escalation Targets
CVE-2026-0775 — npm CLI Local Privilege Escalation CVE ID: CVE-2026-0775Affected component: npm CLIVulnerability class: Local Privilege Escalation…
continue reading..
Gitea Under Threat: Critical Authorization Flaws Lead to Destructive and Org-Wide Attacks
Product Overview Product: GiteaCategory: Self-hosted Git repository management platformTypical Users: Enterprises, DevOps teams, open-source maintainersCore Risk Area:…
continue reading..
Hackers Exploit ‘rn’ Typo Trick to Impersonate Microsoft and Marriott in Sophisticated Phishing Campaign
Cybercriminals are exploiting a visual typo trick known in cybersecurity as typosquatting or a homoglyph attack —…
continue reading..
North Korea–Linked KONNI Group Targets Developers With AI-Generated Malware, Researchers Warn
In a significant escalation of cybercrime tactics, the North Korea–linked threat actor KONNI has shifted its sights…
continue reading..
CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog, Urges Immediate Patching
CVE-2024-37079, a critical vulnerability affecting VMware vCenter Server, has been added to the Known Exploited Vulnerabilities (KEV)…
continue reading..
