A known vulnerability in DD-WRT firmware is now actively exploited, risking remote code execution via a stack-based buffer overflow in UPnP.
Browsing Category
Cybersecurity Threats and Defense
387 posts
Why Credential Stuffing Works Even Against Smart Organizations
Credential stuffing works against even smart organizations because hackers exploit password reuse,…
TP-Link Kasa Cameras Leaked Home GPS Via Unauthenticated UDP For 6 Years
Security flaw in TP-Link Kasa cameras exposed home GPS locations through unauthenticated UDP packets for six years, raising privacy concerns.
CVE-2026-25089: FortiSandbox Unauthenticated Command Injection Added To CISA KEV
A critical unauthenticated command injection vulnerability in FortiSandbox has been added to CISA’s Known Exploited Vulnerabilities list, raising security concerns.
CVE-2026-25089: Fortinet FortiSandbox OS Command Injection Vulnerability Actively Exploited (CISA KEV)
Fortinet FortiSandbox OS command injection vulnerability CVE-2026-25089 is actively being exploited, allowing unauthorized remote code execution.
CVE-2026-39808: Fortinet FortiSandbox OS Command Injection Vulnerability Actively Exploited (CISA KEV)
A critical OS command injection flaw in Fortinet FortiSandbox is actively exploited, allowing unauthenticated attackers to execute remote commands.
Cursor 0day: When Full Disclosure Becomes the Only Protection Left
Exploring the rise of full disclosure in cybersecurity following Cursor 0day, and its implications for security practices and threat mitigation.
Cursor 0Day: When Full Disclosure Becomes The Only Protection Left
A newly discovered Cursor 0day vulnerability prompts full disclosure, raising questions about cybersecurity strategies and the future of vulnerability management.
CVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability Actively Exploited (CISA KEV)
A server-side request forgery vulnerability in SonicWall SMA1000 appliances is actively exploited, allowing remote attackers to cause unintended requests.
CVE-2026-15410: SonicWall SMA1000 Appliances Code Injection Vulnerability Actively Exploited (CISA KEV)
SonicWall SMA1000 appliances are actively targeted due to a code injection vulnerability that could allow remote attackers to execute arbitrary code.