CVE-2026-21875: Critical Unauthenticated Blind SQL Injection Exposes ClipBucket Databases
Product: ClipBucket (v5)Vulnerability Type: Blind SQL InjectionSeverity: CriticalCVSS Score: 9.8Attack Vector: Remote (Network)Authentication Required: No (in default…
continue reading..
CVE-2025-15346: When “Mutual” TLS Isn’t Mutual — Client Authentication Completely Bypassed
CVE ID: CVE-2025-15346Product: wolfSSL Python bindings (wolfssl-py)Vulnerability Type: Authentication Bypass (Mutual TLS)Severity: CriticalCVSS Score: 9.3Attack Vector: NetworkAttack…
continue reading..
ClayRat Android Spyware Turns Trusted Contacts Into Silent Attackers, Hijacking Phones to Spy, Steal, and Self-Propagate Across Russia
Executive Summary ClayRat is an Android spyware campaign uncovered in early January that primarily targets Russian-speaking users.…
continue reading..
Trusted Messages, Compromised Systems: UAC-0184’s Viber-Based Espionage Campaign
What actually happened The attackers initiated contact with victims through Viber messages that appeared legitimate and contextually…
continue reading..
Ghost Tap: The Silent Android Malware Turning Smartphones into Remote Tap-to-Pay Fraud Devices
Incident Discovery Date: January 7, 2026Threat Type: Android malware / NFC relay fraud / Mobile payment abuseImpact…
continue reading..
CVE-2009-0556: CISA Flags Legacy PowerPoint Vulnerability Due to Ongoing Exploitation Risk
Technical Description CVE-2009-0556 affects the way Microsoft PowerPoint handles certain internal references while opening a presentation. The…
continue reading..
CVE-2025-37164: Unauthenticated Remote Code Execution in HPE OneView Puts Core Infrastructure at Risk
What Is the Issue? Hewlett Packard Enterprise OneView is a centralized infrastructure management platform used to manage…
continue reading..
OpenAI has introduced a new feature called ChatGPT Health, no use of users personal data to train model
OpenAI has introduced a feature called ChatGPT Health, a dedicated space within ChatGPT for health-related conversations and…
continue reading..
Microsoft to Enforce MFA for Microsoft 365 Admin Center Sign-Ins
Microsoft has announced that it will begin enforcing multi-factor authentication (MFA) for all users signing in to…
continue reading..
