
The Unpatched Java Flaw Targeting Your Spring Boot Applications
CVE-2026-16723 hits Fastjson 1.x with a CVSS score of 9.0 — and no patch is coming. Active exploits were detected within 24 hours of Alibaba's advisory.
Practical tips, use cases, and news about AI for SMBs. Explore our latest articles.

CVE-2026-16723 hits Fastjson 1.x with a CVSS score of 9.0 — and no patch is coming. Active exploits were detected within 24 hours of Alibaba's advisory.

A multi-agent system built on Moonshot AI's Kimi K3 autonomously uncovered RCE vulnerabilities in Redis in under half an hour — a turning point for automated offensive security.

Five Joomla extensions. Five unauthenticated file upload flaws. Same result: a webshell on the server. What this systemic pattern reveals for security teams.

ShareFile's emergency server shutdown exposes a critical blind spot: hybrid transfer platforms that sit entirely outside your audit perimeter.

PamStealer reveals how macOS infostealers have reached a new technical maturity—forcing IT and security teams to rethink their endpoint strategy.

CVE-2026-45659 (CVSS 8.8) hits CISA's KEV catalog: standard 'Site Member' privileges are enough to compromise an on-premises SharePoint server.

A single third-party software vulnerability compromised 14.22 million email accounts across six Japanese ISPs all hosted on KDDI's shared platform.

Mozilla 0DIN proves a clean GitHub repo is enough to trick AI coding agents into executing a reverse shell via DNS — no malicious code required.

Squidbleed (CVE-2026-47729), a 29-year-old heap memory leak in Squid Proxy, exposes credentials and tokens in cleartext. The fix lands in Squid 7.6.

Stolen OAuth tokens from a niche SaaS vendor were enough to exfiltrate Salesforce CRM data from nine cybersecurity firms, exposing integration ecosystem risk.

FortiBleed compromised over 30,000 Fortinet devices across 194 countries — no zero-days needed, just credentials left unchanged after a prior breach.

Three critical FortiSandbox vulnerabilities have been actively exploited since June 16, 2026, exposing the patch lag problem plaguing network appliances.

CVE-2026-20253 (CVSS 9.8): an unauthenticated component in Splunk Enterprise exposes AWS deployments to remote code execution — no credentials required.

A former IT tech sabotaged his ex-employer for 21 months via never-revoked credentials. What this conviction reveals about IT offboarding risk.

GreatXML, an unpatched zero-day, bypasses BitLocker through the Windows Recovery Environment. Here's what IT teams need to do right now.

One account compromised via social engineering was enough to expose 73,000 civil servants and 13.5 GB of data from a state-backed encrypted platform.

A critical flaw (CVSS 9.4) in Veeam Backup & Replication v12 allows any domain user to seize control of the backup server — no elevated privileges required.

CVE-2026-23111: a use-after-free flaw in nftables enables root escalation and container escape. Working exploits have been public since June 8.