Toggle navigation
SCADA - ICS - IIoT Security Bootcamp
Cyber Range
Contact
Critical Infrastructure
SecList ICS
Threat landscape for industrial automation systems. Q1 2026
Threat landscape for industrial automation systems in Q4 2025
Security Magazine
Protecting America’s Critical Infrastructure: A Shared Responsibility in an Era of Escalating Cyber Threats
CISA, FBI Issue Warning of Ongoing Cyber Exploitation from Iran
Eye on the Sky: SkySafe Named 2026 Golden Eagle Award Winner
Protecting the Cloud Starts at the Perimeter
Security Experts Discuss Validity of Handala’s Cal Water Hacking Claim
Why Are People Entering NYC’s Sewers at Night?
Majority of Organizations Lack Drone Mitigation Due to Legal Restrictions
You Can’t Secure a Ship Like a Laptop
Julia Stuyt — Women in Security 2026
No More Failures of Imagination: Future Proofing Airport Employee Screening
Security Leaders Discuss Cyberattack on American Airlines Subsidiary
Cyberattack Disrupts European Airports, Security Leaders Respond
Uber Freight Investigates Data Security Concern
You Can’t Secure a Ship Like a Laptop
Critical Crossings: Securing Bridges and Tunnels
Inside the Modern Warehouse: Securing the World’s New Front Door
Pro-Iranian Actor Claims L.A. Metro Cyberattack
Airport Security Challenges in the Midst of the DHS Shutdown
Case Studies
The 2 am call: Preparing for a government cyberattack
Häfele recovers from ransomware attack with new SASE platform
Ride-hailing company, inDrive, uses new platform to prevent fraud
The Old Spaghetti Factory restaurant chain ups network & physical security
K-8 students learn cybersecurity through gamification
Electric company uses SAP monitoring to bolster cybersecurity
Thornton Township High School District Implements ZeroEyes
Transforming Higher Ed Safety and Efficiency with Cloud-Based Access Control
Pennsylvania School District Adopts AI-Driven Gun Detection Technology
Protecting 14 Campuses, All With Different Needs
Campus collaboration: a security-focused work management platform
Windsor port authority strengthens US-Canada border waterway
News
Exploits
[remote] PCMan 2.0.7 - Buffer Overflow
[dos] NanaZip 6.5 - DoS
[webapps] flyto-core 2.26.7 - Arbitrary File Write
[webapps] Nodemailer 9.0.0 - File Read/ SSRF
[webapps] Linuxfabrik monitoring_plugins_6.0.0 - SSRF
[dos] NanaZip 6.5 - DoS
[webapps] flyto_core 2.26.7 - Server-Side Request Forgery
[webapps] Probo 0.222.2 - IDOR
[webapps] webpack_devserver 5.2.5 - CSRF
[remote] phpSysInfo 3.4.5 - IP Allowlist Bypass
[dos] Nmap 7.99 - Extension Header Integer Underflow
[webapps] Duplicati 2.2.0.3 - JWT Signing Key Leak
[webapps] Joomla JCE_2.9.15 - Remote Code Execution
[remote] ipTIME A3004T - Remote Code Execution
[remote] D-Link DNS_340L - OS Command Injection
[webapps] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
[webapps] Apache Gravitino 1.2.1 - SSRF
[webapps] Blocksy Companion 2.1.46 - RCE
[remote] PraisonAI praisonaiagents 1.6.77 - Remote Code Execution
[remote] mcp-server-kubernetes 3.8.x - Argument Injection
[dos] LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting
[webapps] Planyo_Online_Reservation_System 3.0 - Arbitrary File Read via SSRF
[webapps] Ray 2.56.0 - Directory Traversal & Local File Inclusion
[webapps] OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution
[local] Microsoft Edge 150.0.4078.48 - RCE
[webapps] CorgetGpsDget 2_3.2 - OS Command Injection
[webapps] Joomla 2.9.99.4 - Unauthenticated Remote Code Execution
[webapps] Krayin CRM v2.2.x - Authenticated Remote Code Execution
[webapps] Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure
[webapps] Langflow 1.9.0 - RCE
[webapps] Joomla Page Builder CK 3.5.10 - Arbitrary File Upload
[webapps] MCPJam Inspector - Remote Code Execution
[local] ProtonVPN v4.4.1 - Unquoted Service Path
[webapps] Flowise 3.1.3 - arbitrary code execution
[remote] Hydra - Stack Buffer Overflow
[webapps] Discuz! X5.0 - Authentication Bypass
[webapps] Tenable Nessus 10.12.1 - SQL Injection
[webapps] WordPress Bricks Builder Theme - RCE
[remote] iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter
[webapps] Joomla Extension 4.1.4 - PHP Object injection
[webapps] Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass
[local] MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation
[webapps] KeepInMind 0.8.4.2 - Stored XSS
[webapps] KNX visualisering - Broken Access Control
[local] Windows Defender (MsMpEng.exe) - Race Condition
[webapps] WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)
Last 20 Website Defacements - Zone-h
Advisories