91. Grafana CVE-2025-6023 Bypass: A Technical Deep Dive vulnerability | High | 2025-11-27 00:00 | CVE-2025-6023 | ethiack.com | original ↗ | #vulnerability-research | #attack-chains | #xss
92. Anatomy of an Automated Patch: Fixing a File Upload RCE CVE-2025-59304 vulnerability | Critical | 2025-11-06 00:00 | CVE-2025-59304 | depthfirst.com | original ↗ | #rce | #path-traversal | #automated-patching
93. Casting a Net(ty) for Bugs, and Catching a Big One (CVE-2025-59419) vulnerability | Medium | 2025-10-20 00:00 | CVE-2025-59419 | depthfirst.com | original ↗ | #vulnerability-research | #java | #command-injection
94. CVE-2025-6515 Prompt Hijacking Attack – How Session Hijacking Affects MCP Ecosystems vulnerability | 2025-10-21 13:15 | CVE-2025-6515 | jfrog.com | original ↗ | #ai-security | #mcp | #jfrog
95. RediShell: Critical Remote Code Execution Vulnerability (CVE-2025-49844) in Redis, 10 CVSS score vulnerability | 2025-10-06 21:00 | CVE-2025-49844 | wiz.io | original ↗ | #rce | #cloud-security | #vulnerability
96. Cooking an SQL Injection Vulnerability in Chef Automate vulnerability | High | 2025-09-30 12:00 | CVE-2025-8868 | xbow.com | original ↗ | #vulnerability-research | #devops | #sql-injection
97. How An Authorization Flaw Reveals A Common Security Blind Spot: CVE-2025-59305 Case Study vulnerability | High | 2025-09-30 00:00 | CVE-2025-59305 | depthfirst.com | original ↗ | #ai-security | #vulnerability-research | #access-control
98. BYOVD to the next level (part 1) — exploiting a vulnerable driver (CVE-2025-8061) vulnerability | High | 2025-09-22 22:00 | CVE-2025-8061 | blog.quarkslab.com | original ↗ | #privilege-escalation | #windows | #driver
99. CVE-2025-27888: Server-Side Request Forgery via URL Parsing Confusion in Apache Druid Proxy Endpoint vulnerability | Medium | 2025-09-23 14:42 | CVE-2025-27888 | xbow.com | original ↗ | #zero-day | #vulnerability-research | #ssrf
100. Reverse engineering of Apple's iOS 0-click CVE-2025-43300: 2 bytes that make size matter vulnerability | Critical | Actively exploited | 2025-09-03 22:00 | CVE-2025-43300 | blog.quarkslab.com | original ↗ | #reverse-engineering | #ios | #apple
101. NT OS Kernel Information Disclosure Vulnerability – CVE-2025-53136 vulnerability | Medium | 2025-09-11 12:00 | CVE-2025-53136 | crowdfense.com | original ↗ | #information-disclosure | #race-condition | #kaslr
102. Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver – CVE-2025-53149 vulnerability | High | 2025-09-04 10:03 | CVE-2025-53149 | crowdfense.com | original ↗ | #windows-kernel | #patch-analysis | #cve-2025-53149
103. Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel vulnerability | High | 2025-09-02 14:43 | CVE-2024-50264 | swarm.ptsecurity.com | original ↗ | #privilege-escalation | #use-after-free | #linux-kernel
104. Breaking NVIDIA Triton: CVE-2025-23319 - A Vulnerability Chain Leading to AI Server Takeover vulnerability | 2025-08-04 12:55 | CVE-2025-23319 | wiz.io | original ↗ | #ai-security | #rce | #vulnerability
105. What is CVE-2025-53770? A Critical Microsoft SharePoint Vulnerability and How to Respond vulnerability | Critical | Actively exploited | 2025-07-23 19:49 | CVE-2025-53770 | hackerone.com | original ↗ | #active-exploitation | #rce | #microsoft
106. Another Byte Bites the Dust - How XBOW Turned a Blind SSRF into a File Reading Oracle vulnerability | Critical | 2025-07-28 12:00 | xbow.com | original ↗ | #vulnerability-research | #ssrf | #exfiltration
107. Beyond the Bands: Exploiting TiTiler’s Expression Parser for Remote Code Execution vulnerability | Critical | 2025-07-25 12:00 | CVE-2023-39631 | xbow.com | original ↗ | #rce | #vulnerability-research | #python
108. SharePoint ToolShell – One Request PreAuth RCE Chain vulnerability | 2025-07-24 10:39 | blog.viettelcybersecurity.com | original ↗ | #rce | #deserialization | #pre-auth
109. SharePoint Vulnerabilities (CVE-2025-53770 & CVE-2025-53771): Everything You Need to Know vulnerability | 2025-07-21 17:42 | wiz.io | original ↗ | #rce | #microsoft | #sharepoint
110. Agents Built From Alloys vulnerability | 2025-07-17 12:00 | xbow.com | original ↗ | #ai-security | #agentic-ai | #benchmark
111. ControlPlane Local Privilege Escalation Vulnerability on macOS vulnerability | 2025-07-14 22:00 | blog.quarkslab.com | original ↗ | #privilege-escalation | #macos | #vulnerability
112. SharePoint Unknown CVE Unveiled: RCE via WebPart Properties Deserialization vulnerability | 2025-07-16 09:42 | CVE-2024-38018 | blog.viettelcybersecurity.com | original ↗ | #rce | #deserialization | #sharepoint
113. Dùng AI để tìm bug - Phần 1: Tìm SQL Injection trong PHP vulnerability | 2025-07-16 09:41 | blog.viettelcybersecurity.com | original ↗ | #ai-security | #bug-bounty | #php
114. Golden dMSA: What Is dMSA Authentication Bypass? vulnerability | 2025-07-16 09:30 | semperis.com | original ↗ | #active-directory | #authentication-bypass | #privilege-escalation
115. When the Heat Gets to Your Database: A Refreshing SQL Injection Discovery in Z-Push vulnerability | 2025-07-10 12:00 | xbow.com | original ↗ | #vulnerability-research | #sql-injection | #web-security
116. Buried in the Log. Exploiting a 20 years old NTFS Vulnerability vulnerability | 2025-07-09 14:05 | CVE-2025-49689 | swarm.ptsecurity.com | original ↗ | #privilege-escalation | #windows | #ntfs
117. How to Block BadSuccessor: The Good, Bad, and Ugly of dMSA Migration vulnerability | 2025-07-10 19:59 | semperis.com | original ↗ | #active-directory | #privilege-escalation | #powershell
118. Finding XSS in Salesforce Aura Components: How XBOW Got Creative vulnerability | 2025-07-07 12:00 | xbow.com | original ↗ | #ai-security | #vulnerability-research | #web-security
119. ‘Feeling close to a critical vulnerability is incredibly addictive’ – YouTuber gregxsunday on the joys of Bug Bounty vulnerability | 2025-07-04 05:51 | yeswehack.com | original ↗ | #bug-bounty | #authentication | #interview
120. CVE-2025-49493: XML External Entity (XXE) Injection in Akamai CloudTest vulnerability | 2025-06-30 12:00 | CVE-2025-49493 | xbow.com | original ↗ | #cloud | #cloud-security | #vulnerability-research