vulnerability 'HTTP Terminator' Hunts for Novel Desync Attacks A new open-source tool, dubbed 'HTTP Terminator,' developed by PortSwigger, utilizes AI to automatically discover novel HTTP request smuggling vulnerabilities. The tool identifies previously unknown attack vectors by analyzing HTTP traffic and simulating attacks, highlighting a significant advancement in automated vuln… Dark Reading · 3d ago Medium httpvulnerabilityweb application
vulnerability Cisco Patches Firewall Zero-Day Exploited for DoS Attacks Cisco has released patches to address a zero-day vulnerability (CVE-2026-20349) in its firewall software, which allows unauthenticated attackers to cause a denial-of-service attack. Cisco detected active exploitation of… SecurityWeek · Aug 12, 2026 High CVE-2026-20349zero-dayvulnerabilityasa
threat-intel AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day An AI-powered research tool, HTTP Terminator, developed by PortSwigger, autonomously discovered several novel HTTP desynchronization techniques, including a zero-day vulnerability in Apache Traffic Server. The tool, usin… The Hacker News · Aug 7, 2026 High CVE-2026-63078UShttpdesyncrqt
vulnerability F5 Patches Multiple NGINX, BIG-IP Vulnerabilities F5 has released out-of-band security patches to address eight critical vulnerabilities affecting NGINX and BIG-IP. These flaws could lead to denial-of-service attacks, memory leaks, and potentially allow remote code exec… SecurityWeek · Jul 16, 2026 High CVE-2026-42533nginxbig-ipvulnerability
vulnerability Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers A remote client can crash HTTP/3 servers running XQUIC, Alibaba's HTTP/3 and QUIC library. The vulnerability, dubbed XRING, stems from an incorrect size calculation during table resizing within the QPACK header compressi… The Hacker News · Jul 10, 2026 High CVE-2026-42530httphttp3quic
threat-intel ISC Stormcast For Thursday, July 9th, 2026 https://isc.sans.edu/podcastdetail/10000, (Thu, Jul 9th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging a newly discovered phishing technique that bypasses traditional email security filters. The c… SANS Internet Storm Center · Jul 9, 2026 Critical USphishingzero-dayransomware
vulnerability Hitachi Energy PROMOD V Hitachi Energy has identified an insecure HTTP transmission vulnerability in its PROMOD V product versions. This vulnerability, stemming from a lack of HTTPS support on the Digipede server, could allow attackers to inter… CISA Advisories · Jul 7, 2026 High CVE-2026-10763WOhttpvulnerabilitycybersecurity
vulnerability 29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests A 29-year-old vulnerability, dubbed Squidbleed (CVE-2026-47729), exists in the Squid web proxy due to a heap over-read. This allows an attacker with proxy access to leak cleartext HTTP requests, including credentials and… The Hacker News · Jun 22, 2026 Medium CVE-2026-47729CVE-2026-50012heap_overflowhttpftp
vulnerability Siemens SENTRON 7KT PAC1261 Data Manager A vulnerability has been identified in the Siemens SENTRON 7KT PAC1261 Data Manager software, specifically within the Go Project’s net/http package. This allows an attacker to potentially gain administrative control over… CISA Advisories · May 14, 2026 High CVE-2025-22871DEhttprequest smugglingindustrial control systems