Security news, decoded.
74 stories in the last 7 days, naming 204 CVEs; 60 of those CVEs are in CISA KEV.
The wire
Wednesday, Mar 182 stories
- watchTowr Labs
- MandiantThe Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat ActorsReported exploitediOS
Monday, Mar 161 story
- Mandiant
Tuesday, Mar 101 story
- ESET WeLiveSecuritySednit reloaded: Back in the trenchesReported exploitedBeardShell
Monday, Mar 91 story
- Bishop FoxPre-Authentication SQL Injection in FortiClient EMS 7.4.4 - CVE-2026-21643Reported exploitedFortiClient EMS
Friday, Mar 61 story
- GitHub Security LabHow to scan for vulnerabilities with GitHub Security Lab’s open source AI-powered frameworkResearchGitHub Security Lab Taskflow Agent
Thursday, Mar 51 story
- MandiantLook What You Made Us Patch: 2025 Zero-Days in ReviewReported exploitedGTIG zero-day tracking
Tuesday, Mar 32 stories
- watchTowr LabsSometimes, You Can Just Feel The Security In The Design (Juniper Junos Evolved CVE-2026-21902 Pre-Auth RCE)PatchJunos OS Evolved (PTX Series)
- MandiantCoruna: The Mysterious Journey of a Powerful iOS Exploit KitReported exploitediOS exploit kit Coruna
Thursday, Feb 261 story
- Google Project ZeroA Deep Dive into the GetProcessHandleFromHwnd APIPoC publicWindows
Wednesday, Feb 251 story
- watchTowr LabsBuy A Help Desk, Bundle A Remote Access Solution? (SolarWinds Web Help Desk Pre-Auth RCE Chain(s))PoC publicSolarWinds Web Help Desk
Tuesday, Feb 171 story
- MandiantUNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-DayReported exploitedDell RecoverPoint for Virtual Machines
Friday, Jan 302 stories
- watchTowr LabsSomeone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340)Reported exploitedIvanti Endpoint Manager Mobile (EPMM)
- ESET WeLiveSecurityThis month in security with Tony Anscombe – January 2026 editionRoundupServiceNow
Thursday, Jan 291 story
- PatchstackSQL Injection Vulnerability in Quiz and Survey Master (QSM) Plugin Affecting 40k+ SitesPatchQuiz and Survey Master (QSM) WordPress plugin
Thursday, Jan 222 stories
- PatchstackCritical Arbitrary File Upload Vulnerability in RealHomes CRM Plugin Affecting 30k+ SitesPatchRealHomes CRM plugin
- watchTowr LabsAttackers With Decompilers Strike Again (SmarterTools SmarterMail WT-2026-0001 Auth Bypass)Reported exploitedSmarterMail
Wednesday, Jan 143 stories
- Google Project Zero
- Google Project ZeroA 0-click exploit chain for the Pixel 9 Part 1: Decoding DolbyPoC publicPixel 9
- PatchstackCritical Privilege Escalation Vulnerability in Modular DS plugin affecting 40k+ Sites exploited in the wildReported exploitedModular DS plugin
Thursday, Jan 81 story
- watchTowr Labs
Monday, Dec 221 story
- ESET WeLiveSecurityRevisiting CVE‑2025‑50165: A critical flaw in Windows Imaging ComponentResearchWindows Imaging Component (WindowsCodecs.dll)
Wednesday, Dec 171 story
- Patchstack
Wednesday, Dec 101 story
- watchTowr LabsSOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies And WSDLPoC public.NET Framework
Thursday, Dec 41 story
- Bishop FoxArista Firewall XSS to RCE ChainResearchNext Generation Firewall (NGFW)
Friday, Nov 141 story
- watchTowr Labs
Wednesday, Nov 121 story
- watchTowr Labs
Thursday, Oct 231 story
- ESET WeLiveSecurityGotta fly: Lazarus targets the UAV sectorReported exploitedESET
Thursday, Jun 261 story
- Bishop FoxSitecore Experience Platform Vulnerabilities: Critical Update Needed for Versions 10.1 to 10.3AdvisorySitecore Experience Platform
Wednesday, Jun 251 story
- Bishop Fox
Friday, Mar 211 story
- Bishop FoxSonicWall-CVE2024-53704: Exploit Details BlogReported exploitedSSL VPN component
Tuesday, Mar 181 story
- Bishop FoxTomcat CVE-2025-24813: What You Need to Know BlogPoC publicApache Tomcat
Monday, Feb 101 story
- Bishop FoxSonicWall CVE-2024-53704: SSL VPN Session HijackingPoC publicSonicOS
Friday, Dec 131 story
- Bishop Fox
Friday, Nov 11 story
- Bishop FoxA Deeper Look at FortiJump (FortiManager CVE-2024-47575)Reported exploitedFortiManager