Cybersecurity Vulnerabilities

Login required for search functionality | Get a free-level account with Google/Microsoft single-sign-on.

59 reports

Update Now: Google Patches Zero-Day Flaw Exploited in the Wild (CVSS 8.8)

Google disclosed a high-severity "use after free" vulnerability in the Chrome CSS engine. The flaw allows remote code execution via malicious webpages. With active exploitation confirmed, immediate updates are required for all Chromium-based browsers.

Two RCE Vulnerabilities in Automation Platform n8n Disclosed (CVSS 9.9 and 8.5)

The workflow automation platform n8n disclosed two critical RCE vulnerabilities. These flaws allow authenticated users to escape sandboxes and execute commands on the host server, risking credential theft and infrastructure-level control across connected services.

Sandbox Escape Vulnerability Found in vm2 NodeJS Library (CVSS 9.8)

A critical sandbox escape vulnerability was disclosed in the vm2 NodeJS library, carrying a CVSS of 9.8. The flaw allows attackers to bypass restricted environments to execute commands, install malware, and steal credentials, impacting software supply chain security.

Russian APT28 Exploiting Recently Patched Microsoft Office Flaw

Russian state-sponsored group APT28 is exploiting a Microsoft Office vulnerability to target government and defense sectors. This "Operation Neusploit" uses compromised documents to bypass security checks, deploying malware for long-term intelligence gathering and data theft.

Critical Takeover Attack Vulnerability in n8n Platform Disclosed (CVSS 10.0)

A critical authentication bypass vulnerability in n8n, dubbed "Ni8mare," allows unauthenticated attackers to achieve full remote code execution. With a maximum CVSS score of 10.0, the flaw enables attackers to weaponize workflows, steal credentials, and compromise connected services.

Critical Cisco Zero-Day Patched After Active Espionage Campaign

Cisco released urgent patches for a maximum-severity zero-day vulnerability in its Secure Email Gateway. Actively exploited by China-linked threat actors, the CVSS 10.0 flaw allows unauthenticated root-level command execution, enabling full device takeover and persistent network access.

China‑Linked Hackers Target North American Critical Infrastructure via Sitecore Zero‑Day

Cisco Talos reports that China-linked group UAT-8837 is exploiting a critical zero-day vulnerability in Sitecore CMS to breach North American critical infrastructure. The group uses insecure configurations to bypass controls, establish long-term persistence, and monitor operational plans.

Latest Microsoft Patch Released – January 2026 -114 Vulnerabilities, 3 Zero-days, and Operational Disruptions Reported

Microsoft's January 2026 update addresses 114 vulnerabilities, including three zero-days, most notably a memory leak in Desktop Windows Manager. Despite critical fixes, the rollout has caused operational disruptions, including Outlook freezes and Windows 11 shutdown failures.

KimWolf Botnet Reportedly Compromised 2 Million Android-based Streaming Devices

The "Kimwolf" campaign has compromised over two million Android streaming devices, primarily off-brand TV boxes, to build a global botnet. These infected devices facilitate DDoS attacks, credential stuffing, and bandwidth theft, often arriving pre-infected or compromised minutes after setup.