A flaw in the binary-parser npm package before version 2.3.0 lets attackers execute arbitrary JavaScript via unsanitized parser input.
A critical-severity vulnerability in the vm2 Node.js sandbox library, tracked as CVE-2026-22709, allows escaping the sandbox and executing arbitrary code on the underlying host system.
A critical Grist-Core flaw (CVE-2026-24002, CVSS 9.1) allows remote code execution through malicious formulas when Pyodide ...
Exploit code has been published for CVE-2025-64155, a critical command injection vulnerability affecting Fortinet FortiSIEM ...
To exploit the vulnerability, an attacker would need either system access or be able to convince a user to open a malicious ...
Windows 11 includes multiple built-in security layers designed to protect your system from modern cyber threats. One such ...
Popular AI interface was plagued by an 8/10 bug, but a fix is now available.
Technical details and a public exploit have been published for a critical vulnerability affecting Fortinet's Security ...
Indian authorities have issued a critical warning to Android users regarding a Dolby audio vulnerability (CIVN–2026-0016).
Just yesterday, we noted the growing threat of ransomware. Now, Jamf Threat Labs is warning that North Korean threat actors ...
Vulnerabilities in Anthropic MCP server could be exploited via prompt injections to execute arbitrary code and read/delete arbitrary files.
January 2026 was a wake-up month for enterprise security teams. In a single week, CERT-In released three high-severity ...