vulnerability MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw that grants attacker… The Hacker News · May 18, 2026 Critical CVE-2020-17103CVE-2025-62221
vulnerability Siemens Siemens ROS# This advisory details a critical vulnerability in Siemens ROS# (version 2.2.2 and earlier) due to a path traversal flaw. An attacker could potentially access and modify arbitrary files on a system hosting the ROS# file_s… CISA Advisories · May 14, 2026 Critical CVE-2026-41551DEpath traversalindustrial control systemscwe-23
vulnerability Siemens Ruggedcom Rox A vulnerability has been identified in Siemens Ruggedcom Rox devices, specifically within the feature key installation process. This flaw allows authenticated remote attackers to execute arbitrary commands with root priv… CISA Advisories · May 14, 2026 Critical CVE-2025-40947DEinput validationremote code executionroot privilege
vulnerability Siemens SIPROTEC 5 This CISA advisory details a critical vulnerability in Siemens SIPROTEC 5 devices due to the use of insufficiently random session identifiers. An unauthenticated remote attacker could potentially exploit this weakness to… CISA Advisories · May 14, 2026 Critical CVE-2024-54017session_hijackingauthenticationrandomness
vulnerability Siemens Ruggedcom Rox A vulnerability has been identified in Siemens Ruggedcom Rox devices, specifically within the Scheduler functionality, allowing authenticated remote attackers to execute arbitrary commands with root privileges. This is d… CISA Advisories · May 14, 2026 Critical CVE-2025-40949DEinput validationroot privilegescheduler
vulnerability Universal Robots Polyscope 5 A critical vulnerability has been identified in Universal Robots Polyscope 5 software versions prior to 5.25.1, allowing for unauthenticated code execution via OS command injection. This poses a significant risk to criti… CISA Advisories · May 14, 2026 Critical CVE-2026-8153WOcommand injectionroboticscve-2026-8153
vulnerability Siemens Opcenter RDnL This advisory details a critical vulnerability in Siemens Opcenter RDnL software, specifically related to missing authentication in the ActiveMQ Artemis component. An attacker within an adjacent network could exploit thi… CISA Advisories · May 14, 2026 Critical CVE-2026-27446DEauthenticationcore protocolactivemq artemis
threat-intel A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens Google Project Zero researchers discovered a critical 0-click vulnerability in the Google Pixel 10's VPU driver, allowing for arbitrary kernel code execution. The vulnerability stems from a flaw in the `vpu_mmap` functio… Google Project Zero · May 13, 2026 Critical CVE-2025-54957zero-clickkernel-exploitationdriver-vulnerability
threat-intel Patch Tuesday, May 2026 Edition This article reports on Patch Tuesday, May 2026, highlighting a significant increase in security vulnerabilities addressed by major software vendors like Microsoft, Apple, Google, Mozilla, and Oracle. The updates, spurre… Krebs on Security · May 12, 2026 Critical CVE-2026-41089CVE-2026-41096CVE-2026-41103USpatch tuesdayaivulnerability
vulnerability CVE-2025-68670: discovering an RCE vulnerability in xrdp This report details a remote code execution (RCE) vulnerability, CVE-2025-68670, discovered in the Kaspersky xrdp server. The vulnerability exists within the xrdp_wm_parse_domain_information function due to a buffer over… Securelist · May 8, 2026 Critical CVE-2025-68670buffer_overflowrcexrdp
vulnerability Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution Unit 42 details CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. Read now for details. The post Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated… Palo Alto Unit 42 · May 7, 2026 Critical CVE-2026-0300
vulnerability Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years A critical Linux kernel vulnerability, dubbed 'Copy Fail' (CVE-2026-31431), has been discovered allowing unprivileged local attackers to escalate their access to root across numerous Linux distributions since 2017. The f… Palo Alto Unit 42 · May 5, 2026 Critical CVE-2026-31431CVE-2026-314331USlinuxkernellpe
apt Alleged Silk Typhoon hacker extradited to the United States to face charges A Chinese national, Xu Zewei, has been extradited to the United States to face charges related to his alleged involvement with the Hafnium hacking group, also known as Silk Typhoon. He is accused of attempting to steal c… Graham Cluley · Apr 29, 2026 Critical CHUSstate-sponsoredcyber espionageexchange server
ransomware Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab German authorities have identified ‘UNKN,’ the elusive figure behind the notorious GandCrab and REvil ransomware gangs, as 31-year-old Russian national Daniil Maksimovich Shchukin. Shchukin, alongside Anatoly Sergeevitsc… Krebs on Security · Apr 6, 2026 Critical DERUransomwareextortioncybercrime
vulnerability Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529 Researchers at Google Project Zero discovered and exploited a type confusion vulnerability (CVE-2024-54529) within the coreaudiod system daemon in macOS. The vulnerability, stemming from a double-free, allowed for heap m… Google Project Zero · Jan 30, 2026 Critical CVE-2024-54529CVE-2025-31235macosvulnerabilityheap
supply-chain A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave A Google Project Zero researcher discovered a 0-click exploit chain targeting the Pixel 9, leveraging a BigWave hardware accelerator and a vulnerability in the mediacodec SELinux context. The exploit bypasses sandboxing… Google Project Zero · Jan 14, 2026 Critical kernelsupply-chainarbitrary-read-write