Critical RCE in OpenSSH Affects 14M Internet-Facing Servers
Researchers at Qualys disclosed a remotely exploitable vulnerability in OpenSSH 8.5p1–9.7p1.
Apple Issues Emergency Update for Actively Exploited WebKit 0-day
Out-of-band fix for CVE-2024-23222, observed in targeted exploitation against journalists.
Patch Tuesday Fixes 51 CVEs — 3 Zero-Days Actively Exploited
This month's update addresses 51 vulnerabilities including three actively-exploited zero-days.
CISA Adds Apache HTTP Server Vulnerability to Known Exploited List
Federal agencies must patch CVE-2024-38476 by July 23.
UNC5174 Campaign Exploits CVE-2024-1709 Against Federal Targets
China-nexus actor leverages ConnectWise ScreenConnect auth bypass in widespread campaign.
Operation Triangulation Toolchain Analyzed in Full Technical Detail
Kaspersky publishes complete chain analysis of the iOS implant first disclosed in 2023.