Section
Security
Exploitation, supply chain, and the incident response nobody publishes.
19 stories · 0 editors
Topics
Sort: Newest ▾
News
4 min
Citrix published fixes for eight NetScaler ADC and Gateway flaws on September 27 and said two were already being exploited. CISA gave federal agencies until September 30.
News
4 min
WordPress shipped 7.1.2 and backports to every branch since 4.7 on September 22 for an unauthenticated file inclusion in page-template resolution. CISA listed it as exploited on September 25.
23 Sep · Prelo · 5 min
Plugin4Shell: pinned-commit bypass in four coding agents' plugin installers.
22 Sep · Prelo · 6 min
Oracle's September CSPU: 673 patches, six CVSS 10.0, and not cumulative.
15 Sep · Prelo · 4 min
Critical SSMS 22 Copilot flaw: crafted prompts could bypass read-only limits. Fixed in 22.8.2, disclosed 42 days later.
15 Sep · Prelo · 6 min
Anthropic's Sept 2026 threat report: stolen AI API keys are loot, attack compute and cover, and eval sandboxes leak them.
Older in Security →