Toggle navigation
SCADA - ICS - IIoT Security Bootcamp
Cyber Range
Contact
Critical Infrastructure
SecList ICS
Threat landscape for industrial automation systems in Q2 2025
Notes of cyber inspector: three clusters of threat in cyberspace
Security Magazine
From Farm to Table: Securing the Future of Agriculture with Innovative Technology
Iran’s Cyber Playbook: What US Critical Infrastructure Needs to Be Doing Right Now
Hacktivism Increasingly Targeting Critical Infrastructure
Physical Security Measures That Respect Constitutional Rights
The importance of security for power utility substations
Chinese threat actor resided in US electric grid for almost one year
Security Leaders Discuss Cyberattack on American Airlines Subsidiary
Cyberattack Disrupts European Airports, Security Leaders Respond
Integrating Mass Notification with Video Surveillance in Airports
Windsor port authority strengthens US-Canada border waterway
Protecting ships from cyber terrorism
Biden administration issues executive order to secure U.S. ports
From Farm to Table: Securing the Future of Agriculture with Innovative Technology
Layered Secure Entrances Strengthen Warehouse and Supply Chain Security
How Air Travel Became Safer Through Cashless Service
No Smoke, Just Signals: Iris Recognition for Cannabis Compliance
Scattered Spider’s Newest Targets: Transportation and Airlines
The Future of Public Transit: Leveraging AI Analytics for Enhanced Operations and Passenger Experience
Case Studies
The 2 am call: Preparing for a government cyberattack
Häfele recovers from ransomware attack with new SASE platform
Ride-hailing company, inDrive, uses new platform to prevent fraud
The Old Spaghetti Factory restaurant chain ups network & physical security
K-8 students learn cybersecurity through gamification
Electric company uses SAP monitoring to bolster cybersecurity
Transforming Higher Ed Safety and Efficiency with Cloud-Based Access Control
Pennsylvania School District Adopts AI-Driven Gun Detection Technology
Protecting 14 Campuses, All With Different Needs
Campus collaboration: a security-focused work management platform
Windsor port authority strengthens US-Canada border waterway
From the stone age to cutting edge: A case study on key management
News
Exploits
[webapps] Flowise 3.0.4 - Remote Code Execution (RCE)
[webapps] Casdoor 2.95.0 - Cross-Site Request Forgery (CSRF)
[remote] Ilevia EVE X1/X5 Server 4.7.18.0.eden - Reverse Rootshell
[local] Microsoft Windows Server 2025 Hyper-V NT Kernel Integration VSP - Elevation of Privilege
[remote] ClipBucket 5.5.0 - Arbitrary File Upload
[remote] ClipBucket 5.5.2 Build #90 - Server-Side Request Forgery (SSRF)
[webapps] Tourism Management System 2.0 - Arbitrary Shell Upload
[webapps] Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)
[webapps] dotCMS 25.07.02-1 - Authenticated Blind SQL Injection
[webapps] ELEX WooCommerce WordPress Plugin 1.4.3 - SQL Injection
[webapps] XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)
[webapps] Concrete CMS 9.4.3 - Stored XSS
[local] Mbed TLS 3.6.4 - Use-After-Free
[remote] HTTP/2 2.0 - Denial Of Service (DOS)
[remote] HTMLDOC 1.9.13 - Stack Buffer Overflow
[remote] GeoVision ASManager Windows Application 6.1.2.0 - Remote Code Execution (RCE)
[local] GeoVision ASManager Windows Application 6.1.2.0 - Credentials Disclosure
[webapps] StoryChief Wordpress Plugin 1.0.42 - Arbitrary File Upload
[remote] Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass
[webapps] Lingdang CRM 8.6.4.7 - SQL Injection
[webapps] Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure
[remote] Tenda AC20 16.03.08.12 - Command Injection
[webapps] Lantronix Provisioning Manager 7.10.3 - XML External Entity Injection (XXE)
[webapps] Soosyze CMS 2.0 - Brute Force Login
[remote] Microsoft Windows 10.0.19045 - NTLMv2 Hash Disclosure
[remote] PHPMyAdmin 3.0 - Bruteforce Login Bypass
[webapps] RiteCMS 3.0.0 - Reflected Cross Site Scripting (XSS)
[webapps] BigAnt Office Messenger 5.6.06 - SQL Injection
[webapps] JetBrains TeamCity 2023.11.4 - Authentication Bypass
[webapps] ServiceNow Multiple Versions - Input Validation & Template Injection
[webapps] Ghost CMS 5.59.1 - Arbitrary File Read
[webapps] Ghost CMS 5.42.1 - Path Traversal
[remote] Belkin F9K1009 F9K1010 2.00.04/2.00.09 - Hard Coded Credentials
[webapps] VMware vSphere Client 8.0.3.0 - Reflected Cross-Site Scripting (XSS)
[remote] Microsoft SharePoint Server 2019 (16.0.10383.20020) - Remote Code Execution (RCE)
[remote] Tigo Energy Cloud Connect Advanced (CCA) 4.0.1 - Command Injection
[webapps] Microsoft Edge Renderer Process (Mojo IPC) 134.0.6998.177 - Sandbox Escape
[webapps] Grav CMS 1.7.48 - Remote Code Execution (RCE)
[remote] Citrix NetScaler ADC/Gateway 14.1 - Memory Disclosure
[webapps] atjiu pybbs 6.0.0 - Cross Site Scripting (XSS)
[local] Microsoft Windows - Storage QoS Filter Driver Checker
[webapps] projectworlds Online Admission System 1.0 - SQL Injection
[remote] Cisco ISE 3.0 - Authorization Bypass
[remote] Cisco ISE 3.0 - Remote Code Execution (RCE)
[local] Microsoft Virtual Hard Disk (VHDX) 11 - Remote Code Execution (RCE)
[webapps] Ultimate Member WordPress Plugin 2.6.6 - Privilege Escalation
Last 20 Website Defacements - Zone-h
Advisories