Tag: informationsecurity

Week 16 – Trusted Format, Hidden Threat: Exploiting Adobe Reader via PDF

13 -19 Apr 2026 In this week’s CVE of the Week, we’re looking at a critical, actively exploited vulnerability in Adobe Acrobat and Adobe Reader that allows attackers to execute arbitrary code by simply getting a user to open a malicious PDF file. CVE‑2026‑34621 is 

Week 15 – One Text Away: The Samsung Exynos Zero-Click Threat

06 -12 Apr 2026 A newly disclosed Samsung Exynos vulnerability allows attackers to compromise a device with nothing more than a malicious SMS. No clicks. No user interaction. Just one message. Critical vulnerability has been found with the CVSS score of 10 in CVE-2025-543284. An 

Week 14 – Cracked Open: A Critical F5 Flaw Hiding Inside the Easter Egg

30 Mar – 05 Apr 2026 Our CVE of the Week is about BigIP APM which consolidates remote, mobile, network, virtual, and web access. With BIG-IP APM, you can create, enforce, and centralize simple, dynamic, intelligent application access policies for all of your apps, regardless 

Week 13 – When a Video Hacks Your Phone

23 – 29 Mar 2026 In this week’s CVE of the Week we’ll be looking at remote code execution flaw in Android 16 system component. Several locations of the component’s Media Codecs Mainline module exhibit potential out-of-bounds read and write operations caused by a heap 

Week 12 – 10-30 Days to Root

16 – 22 Mar 2026 This week’s CVE of the Week is about a Local Privilege Escalation (LPE) vulnerability in default installations of Ubuntu Desktop 24.04 and later versions. CVE-2026-3888 (CVSS score: 7.8), identified by the Qualys Threat Research Unit, could allow an unprivileged local 

Week 11 – Aruba AOS-CX: Admin Access Without Login

09 – 15 Mar 2026 Hewlett Packard Enterprise has published an urgent security advisory addressing a critical vulnerability (CVE-2026-23813), this our new CVE of the Week. The Aruba Networking AOS-CX operating system used on CX-series campus and data center switches. This flaw is particularly concerning 

Week 10 – A Bitter Cup of Java: CVSS 10 RCE in Cisco FMC

02 – 08 Mar 2026 Our CVE of the Week is about Cisco Secure Firewall Management Center (FMC) Software, which is an administrative nerve center for managing critical Cisco network security solutions. Critical vulnerability has been found with the CVSS score of 10 in CVE-2026-20131. 

Week 9 – Privilege Escalation Flaw in Windows Admin Center

23 Feb – 01 Mar 2026 In this week’s CVE of the Week, we’ll be looking at a high security flaw of improper authentication in Microsoft Windows Admin Center that allows an authorized attacker to elevate privileges over a network. Windows Admin Center is a 

Week 8 – From RecoverPoint to BreakPoint

16 – 22 Feb 2026 CVE-2026-22769 is a critical vulnerability affecting Dell’s RecoverPoint for Virtual Machines. RecoverPoint for Virtual Machines is a solution maintained by Dell to offer hypervisor-level backup and recovery for virtual machines and it is commonly used by enterprises. Exploiting this vulnerability 

Week 7 – Microsoft Patch Tuesday

9 – 15 Feb 2026 In this week’s CVE of the Week, we’ll be looking at one of the vulnerabilities updated during Microsoft’s February 2026 Patch Tuesday. CVE-2026-21510 is a protection mechanism failure that could allow an unauthorized attacker to bypass a security feature affecting