Researchers who found the bug warn that its Moderate rating understates a threat reaching across LLM gateways, MCP servers ...
Novee researchers discovered an account takeover vulnerability in the open source CFP management tool Pretalx.
CVE-2026-5426, a hardcoded ASP.NET machineKey in KnowledgeDeliver, was exploited as a zero-day in ViewState deserialization ...
Ghost CMS flaw CVE-2026-26980 enabled attacks on 700+ sites, injecting ClickFix malware through fake CAPTCHA pages.