All Articles
78 guides, CVE analyses, and security research articles — page 6 of 7.
-
The Complete Guide to Automated Penetration Testing in 2026
Everything security teams need to know about AI-powered and automated pentesting in 2026: how it works, what it covers, what to look for in a platform, and how to get started.
Read article → -
Why Your Security Scanner Isn't a Penetration Test
Vulnerability scanners find known CVEs. Penetration tests find what attackers actually exploit. Here's the critical difference — and what you're missing if you rely on scans alone.
Read article → -
CVE-2026-22769: Dell RecoverPoint CVSS 10.0 Zero-Day Exploited by China-Nexus Hackers Since 2024
CISA adds CVE-2026-22769 to KEV catalog with 3-day patch deadline. Dell RecoverPoint hardcoded credential zero-day exploited by UNC6201 (Silk Typhoon) since mid-2024 — deploying BRICKSTORM, GRIMBOLT backdoors and Ghost NICs for stealthy VMware pivoting.
Read article → -
RoguePilot: How a Hidden GitHub Copilot Bug Silently Steals Your Entire Repository
Orca Security discloses passive prompt injection in GitHub Copilot that leaks GITHUB_TOKEN from Codespaces — no user interaction required beyond opening a Codespace from a malicious issue.
Read article → -
BeyondTrust Pre-Auth RCE (CVE-2026-1731): WebSocket OS Command Injection Hits 8,500+ Vulnerable Instances
CVSS 9.9 pre-authentication RCE in BeyondTrust Remote Support and Privileged Remote Access enables OS command injection via unauthenticated WebSocket. 8,500+ vulnerable instances globally — patch or restrict now.
Read article → -
Critical VS Code Extension Vulnerabilities: 125 Million Installs At Risk (CVE-2025-65717, CVE-2025-65716, CVE-2025-65715)
Four critical vulnerabilities in popular VS Code extensions — Live Server, Markdown Preview Enhanced, Code Runner, and Microsoft Live Preview — put 125 million developers at risk of file exfiltration and remote code execution. Three remain unpatched.
Read article → -
CVE-2026-21513: Actively Exploited MSHTML Zero-Day Bypasses Windows Security
Critical CVE-2026-21513 MSHTML Framework zero-day vulnerability exploited in the wild. CVSS 8.8 security feature bypass enables attackers to evade Mark-of-the-Web protections.
Read article → -
Security Roundup Feb 10–16 2026: AI Infrastructure Under Fire, Cloud Misconfigs & $4.3M in Bug Bounties
Weekly security roundup covering CVE-2026-22778 vLLM RCE, six n8n CVEs, Azure Functions info disclosure, a real-world AI-assisted AWS cloud breach, HackerOne's $4.3M payout week, and the best tools for bug hunters.
Read article → -
Adobe After Effects CVE-2026-21329: Use-After-Free RCE Vulnerability Threatens Creative Workflows
Critical CVE-2026-21329 use-after-free vulnerability in Adobe After Effects 25.6 and earlier enables arbitrary code execution. Complete technical analysis and bug bounty testing guide.
Read article → -
Microsoft Patch Tuesday February 2026: 6 Zero-Days Exploited in the Wild
Microsoft's February 2026 Patch Tuesday patches 59 CVEs including 6 actively exploited zero-days. Critical Windows Shell, MSHTML, and RDP vulnerabilities demand immediate patching.
Read article → -
CVE-2026-22778: Critical vLLM RCE Vulnerability Threatens AI Infrastructure
Critical CVE-2026-22778 vLLM Remote Code Execution vulnerability discovered by Orca Security. CVSS 9.8 unauthenticated RCE affecting GPU clusters serving large language models.
Read article → -
Critical n8n Vulnerability: Six CVEs Expose Workflow Automation to RCE
Six critical vulnerabilities disclosed in n8n workflow automation platform, including CVE-2026-25049 RCE with CVSS 9.4. Full analysis and mitigation guide.
Read article →