Blog
GHSA-mqjf-5f49-2fjh (CVSS 9.8): GeoServer PostGIS jsonArrayContains SQL Injection Enables Unauthenticated RCE — Hundreds of Exploitation Attempts Within Hours of Disclosure
An unpatched CVSS 9.8 SQL injection in GeoServer's PostGIS jsonArrayContains OGC filter enables unauthenticated remote code execution. Active exploitation began within hours of public disclosure.
Read More →CVE-2026-42897 (CVSS 8.1): Laundry Bear’s OWAReaper Lives Inside Your Mailbox — Survives Password Reset and Complete Device Rebuild
Laundry Bear’s OWAReaper backdoor exploits CVE-2026-42897 in Microsoft Exchange OWA to steal credentials and persist inside your mailbox, surviving password resets and device rebuilds. Patch and hunt for IOCs now.
Read More →CVE-2026-62878 (CVSS 9.8): Windows DNS Server’s Wormable Stack Overflow Can Detonate Across Your Entire Active Directory Forest — No Password Required
CVE-2026-62878 is a CVSS 9.8 wormable stack overflow in Windows DNS Server requiring no authentication. One crafted packet can lead to full Active Directory domain compromise. Patch immediately.
Read More →CVE-2026-33634: The LiteLLM Supply Chain Attack That Compromised 2,500+ Organisations and 434,000 CI/CD Pipelines
TeamPCP backdoored LiteLLM PyPI packages via a Trivy GitHub Actions exploit, exposing 2,500+ organisations and 434,000 CI/CD pipelines to credential theft and Kubernetes compromise.
Read More →CVE-2026-48362 (CVSS 10.0): Adobe ColdFusion’s Unauthenticated OS Command Injection — 72-Hour Patch Window Closes Today
Adobe APSB26-90 patches CVE-2026-48362, a CVSS 10.0 unauthenticated OS command injection in ColdFusion giving attackers full server control with no credentials required.
Read More →DeadLock Ransomware Stores C2 on Polygon Blockchain — 96 Victims Across Four Continents, No Takedown Path
DeadLock ransomware embeds command-and-control inside Polygon smart contracts that law enforcement cannot seize — 96 victims across IT, manufacturing, and logistics sectors across four continents.
Read More →CVE-2026-20349 (CVSS 8.6): Cisco ASA and FTD VPN Flaw Under Active Attack — CISA Deadline Is Tomorrow
Unauthenticated attackers are crashing Cisco ASA and FTD firewalls via CVE-2026-20349. CISA’s patch deadline is August 14. No workarounds exist — patch now.
Read More →CVE-2026-62815 (CVSS 9.8): Microsoft QUIC’s Use-After-Free Flaw Opens Every Windows Server to Remote Code Execution — No Password Required
A CVSS 9.8 use-after-free flaw in Microsoft QUIC lets unauthenticated attackers execute code remotely on Windows 11 and Windows Server 2022/2025 with no user interaction. Patch immediately or block UDP/443…
Read More →CVE-2026-68820 (CVSS 7.0): Lazarus Group Weaponises Windows WinSock Kernel Zero-Day to Deploy FudModule Rootkit — August 2026 Patch Tuesday
North Korea's Lazarus Group exploited CVE-2026-68820, a Windows WinSock kernel zero-day, in Operation Dream Job targeting Indian defence firms. Here is what IT leaders must do now.
Read More →CVE-2025-24472 (CVSS 8.1): Gunra RaaS Chains Your FortiOS VPN Into a Ransomware On-Ramp — FBI, CISA, NSA and Seoul Issue Red Alert
FBI, CISA & South Korea warn Gunra ransomware exploits CVE-2025-24472 (CVSS 8.1) in FortiOS to breach governments and critical infrastructure. Patch to FortiOS 7.0.17 now.
Read More →