Two unauthenticated vulnerabilities in enterprise file transfer platform enable remote code execution and data exfiltration without credentials

Weekly insights on threats, vulnerabilities, and security best practices.

Analysis of attack vectors targeting 48 critical vulnerabilities in Cisco's enterprise networking stack, including exploitation TTPs for ASA, FMC, and FTD devices.

ClawJacked vulnerability enables malicious websites to hijack local OpenClaw AI agents via WebSocket connections, allowing complete takeover of AI operations and data exfiltration.

Apple patched a zero-day vulnerability exploited in targeted attacks. We analyze the attack chain, TTPs, and defensive strategies for security teams.