Researchers built a Zoom zero-click RCE exploit in under 24 hours using AI, exposing risks to Windows, macOS, iOS, and Android users.
Zoom has patched a vulnerability that could allow attackers to execute code on other meeting participants’ systems.
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution ...
An AI uncovered a $500,000 WordPress exploit in 10 hours for $25, raising bigger concerns about how cheaply serious ...
A critical vulnerability in the Erlang/OTP SSH, tracked as CVE-2025-32433, has been disclosed that allows for unauthenticated remote code execution on vulnerable devices. The flaw was discovered by ...
A team of security researchers chained two vulnerabilities in LiteLLM, the popular open-source proxy that routes enterprise traffic to large language model providers, and walked away with arbitrary ...
The WinSock fix is one of the 398 patches issued today by Microsoft, and SAP’s fix for a vulnerability in Commerce Cloud is one of 29 patches this month.
Broadcom fixes two critical VMware vCenter flaws and a VMXNET3 ESX escape, with no evidence of exploitation in the wild.
Forbes contributors publish independent expert analyses and insights. Davey Winder is a veteran cybersecurity writer, hacker and analyst. This voice experience is generated by AI. Learn more. This ...
A newly published BootROM exploit targeting iPhone 11 and A12/A13 chips has been pulled offline after Magnet Forensics sued the researchers who disclosed it. The vulnerability cannot be patched ...
State-sponsored hackers used compromised South Korean websites to exploit AnySign4PC and install SIGNBT or COPPERHEDGE ...