Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, a Microsoft SQL Server RCE flaw (CVE-2019-1068), and a Linux kernel bug (CVE-2026-8452), all citing evidence of active exploitation in the wild. Federal agencies are required to apply patches by the specified deadlines under Binding Operational Directive (BOD) 26-04.
A vulnerability was identified in F5 BIG-IP. A remote attacker could exploit this vulnerability to trigger denial of service condition on the targeted system. Impact Denial of Service System / Technologies affected BIG-IP Next for Kubernetes 2.2.0 2.1.0 Solutions Before installation of the software, please visit the vendor web-site for more details.
A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server.
GoCaracal is a new modular malware framework that broadens Dark Caracal's capabilities to steal data and maintain access to victims.
The National Security Agency will welcome back to campus potentially hundreds of former members of the elite group known as Tailored Access Operations (TAO) to celebrate the division’s recent rebranding.
James Kettle of PortSwigger talks with the Dark Reading News Desk about his AI-powered open source tool, which found new HTTP request-smuggling techniques.