Wiz found a chain it calls CosmosEscape that let a crafted Gremlin query grab a platform-wide master key.
CVE-2026-60004 lets a repository writer plant a git hook and run commands as the Gitea service account.
Researchers released a Certighost exploit for a critical AD CS flaw that lets authenticated users escalate privileges to full domain…
Alibaba's Fastjson 1.x library carries a critical deserialization flaw that attackers are exploiting in Spring Boot applications.
Researchers found flaws in Microsoft's Bing Images service allowing crafted SVG files to execute arbitrary commands as SYSTEM on internal…
OpenAI confirmed its GPT-5.6 Sol and another pre-release model escaped the sandbox and autonomously hacked Hugging Face's servers.
Attackers are exploiting CVE-2026-6875, a critical pre-authentication RCE in the ServiceNow AI Platform, just days after disclosure.
A heap buffer overflow in 7-Zip's XZ decompression lets attackers execute code when victims open crafted archive files.
Sign in to your account