Vendors
Windows, Exchange, Outlook, Azure, and the patch cycle.
Vulnerabilities and patches across Windows, Exchange Server, Outlook, Active Directory, and Azure — including Patch Tuesday triage and zero-days under active exploitation.
IOS XE, ASA, and edge-device exploitation.
Vulnerabilities in Cisco IOS XE, ASA, and other network infrastructure — the gear that, when compromised, hands attackers the keys to entire networks.
Connect Secure, Policy Secure, and VPN appliance flaws.
Coverage of Ivanti Connect Secure, Policy Secure, and related edge VPN appliance vulnerabilities — a recurring target for nation-state and ransomware actors alike.
NetScaler ADC, Gateway, and session-hijack flaws.
Citrix NetScaler ADC and Gateway vulnerabilities, including session-hijacking flaws like Citrix Bleed that bypass MFA entirely.
Confluence, Jira, and collaboration-suite exploitation.
Vulnerabilities in Atlassian Confluence, Jira, and Bitbucket — frequent ransomware-precursor targets due to the sensitive internal documentation they host.
PAN-OS, GlobalProtect, and firewall zero-days.
PAN-OS and GlobalProtect vulnerabilities affecting Palo Alto Networks firewalls — perimeter devices where a single command-injection flaw can mean full network compromise.
FortiOS, FortiGate, and FortiProxy perimeter flaws.
Vulnerabilities in FortiOS, FortiGate, and FortiProxy — the firewall and SSL-VPN appliances that sit at the network edge, making a single auth-bypass or overflow bug a direct path to full network compromise.
BIG-IP and iControl REST management-plane flaws.
Vulnerabilities in F5 BIG-IP's iControl REST and TMUI management interfaces — application-delivery controllers whose compromise typically hands attackers control of the load-balanced traffic behind them.
NetWeaver, S/4HANA, AppRouter, and Commerce Cloud advisories.
Vulnerabilities and patches across SAP's enterprise stack — NetWeaver Application Server (Java and ABAP), S/4HANA, Business Technology Platform, AppRouter, and Commerce Cloud — including the monthly SAP Security Patch Day cycle.
vCenter, ESXi, and Spring Framework RCE flaws.
Vulnerabilities in VMware vCenter Server, ESXi, and the Spring Framework VMware stewards — virtualization and application infrastructure whose compromise can mean full control of an organization's entire virtual estate.
7-Zip archive-parsing flaws and RCE bugs in the open-source Windows archiver.
Vulnerabilities in Igor Pavlov's 7-Zip, the open-source archive utility bundled or installed on tens of millions of Windows endpoints. 7-Zip ships without an auto-update mechanism, so parser bugs — heap overflows in Zstd, XZ, or LZMA decompression, path-traversal in extraction — tend to sit on user machines long after the fix is out.
WinRAR archive-handling and path-traversal flaws.
Vulnerabilities in RARLAB's WinRAR, the ubiquitous Windows archive utility — bugs here are attractive to attackers because a single malicious archive can compromise any of WinRAR's hundreds of millions of installs.
Email Security Gateway appliance flaws.
Vulnerabilities in Barracuda Networks' Email Security Gateway appliances — internet-facing mail-scanning devices that, once compromised, gave attackers a foothold that in one case survived even after patching.
GitLab CE/EE RCE and access-control flaws.
Vulnerabilities in GitLab Community and Enterprise Edition — the DevOps platform that, when compromised, can expose an organization's entire source code history and CI/CD pipeline secrets.
Log4j and other Apache Software Foundation project flaws.
Vulnerabilities in Apache Software Foundation projects — most notably Log4j, the ubiquitous Java logging library whose Log4Shell flaw became one of the most widely exploited vulnerabilities in internet history.
Kemp LoadMaster, MOVEit, and the file-transfer/appliance patch cadence.
Vulnerabilities and patches across Progress Software's edge and file-transfer product line — Kemp LoadMaster application delivery controllers, MOVEit Transfer, and other appliances whose compromise typically hands attackers a foothold at the network perimeter.
ColdFusion, Commerce, Reader, and Acrobat exploitation.
Vulnerabilities in Adobe ColdFusion, Commerce (Magento), Reader, and Acrobat — a product line whose enterprise footprint keeps it in the KEV catalog and in attacker toolkits well past its perceived relevance.
ServiceNow Platform and Now Assist / AI Platform vulnerabilities.
Vulnerabilities and exploitation targeting ServiceNow's platform and its AI Platform / Now Assist surfaces — a high-value enterprise SaaS foothold that frequently holds sensitive IT, HR, and workflow data across large organizations.
macOS, iOS, and Safari flaws — and the malware ecosystem targeting them.
Vulnerabilities and malware affecting Apple's platforms — macOS, iOS, iPadOS, and Safari — including PAM-abusing stealers, cross-platform RATs, and the Mac-native malware families that have moved from novelty to fixture in enterprise threat models.
Chrome, Android, Chrome Web Store, and Workspace exposure.
Vulnerabilities, supply-chain compromises, and abuse of Google's platforms — Chrome and V8, Android, the Chrome Web Store as a malware distribution channel, and Workspace as an attacker pivot point in identity-driven intrusions.
Kernel LPEs, use-after-frees, and Android downstream fallout.
Vulnerabilities in the upstream Linux kernel — local privilege escalations, use-after-frees, race conditions, and the subsystems (epoll, netfilter, io_uring, eBPF) that keep producing them — plus the downstream impact on Android devices and long-lived LTS deployments.
Core, plugin, and theme CVEs across the largest CMS attack surface on the web.
Vulnerabilities across WordPress core and its plugin and theme ecosystem — the sprawling third-party attack surface that runs a large share of the public web, where a single popular plugin flaw can cascade into hundreds of thousands of compromised sites within days of disclosure.
Extortion operators, payouts, and the tooling behind the campaigns.
Ransomware campaigns, extortion economics, and the tradecraft that drives them — from LOLBin-heavy intrusions to bespoke encryptors. Coverage of individual crews (Anubis, BlueHammer, Kairos, Lynx, Avalon/CrownX, JadePuffer, Inc/Lynx) sits alongside the class-level tactics that outlive any one brand.
npm, PyPI, and dependency-chain compromises.
Attacks that use the software supply chain as the delivery vector — malicious npm, PyPI, and RubyGems packages, poisoned transitive dependencies, typo-squats, and compromised build pipelines. Includes DPRK's ongoing Contagious Interview package operations and the rollup-polyfill class of "one dependency, many downstreams" incidents.
Self-hosted Git service CVEs and advisories.
Vulnerabilities and advisories affecting Gitea, the self-hosted Git service, including its official Docker images.
Industrial control, operational tech, and air-gap threats.
Vulnerabilities and intrusions affecting industrial control systems, SCADA, PLCs, and the operational-technology stack — plus the wider "physical-layer" surface of firmware in embedded devices and covert channels against air-gapped machines. Where a bug can mean a plant trip, not just a data breach.
Chrome, Firefox, Safari, and extension-ecosystem exploitation.
Vulnerabilities and exploitation across Chrome, Firefox, Safari, Edge, and their smaller relatives — plus the browser-extension ecosystem, where a signed add-on can silently exfiltrate anything the browser can see.
iOS, Android, and mobile spyware.
Mobile-platform vulnerabilities and the spyware ecosystem that exploits them — from Pegasus-class commercial surveillance tooling to opportunistic Android malware. Covers OS-level flaws in iOS and Android and the mobile-specific attack surface: baseband, MDM, and sideload channels.
M365, Google Workspace, and cloud-identity attacks.
Attacks against cloud identity and productivity platforms — Microsoft 365, Google Workspace, Azure, AWS — including OAuth consent phishing, device-code abuse, token theft, and the "identity-first" intrusion patterns that treat the tenant, not the endpoint, as the ground floor.
Firefox and Thunderbird zero-days, sandbox escapes, and MFSA advisories.
Vulnerabilities across Mozilla Firefox, Thunderbird, and the shared Gecko/SpiderMonkey stack — the Mozilla Foundation Security Advisories (MFSA) cadence, browser-sandbox escapes, and the JavaScript-engine bugs that Pwn2Own and in-the-wild attackers keep finding.
Firewall, SMA, and SSL-VPN flaws — CISA KEV regulars.
Vulnerabilities in SonicWall firewalls, Secure Mobile Access (SMA) appliances, and SSL-VPN gateways — perimeter gear that lands on CISA's Known Exploited Vulnerabilities catalog with unusual regularity and gets targeted by ransomware crews within days of disclosure.
Junos OS, SRX, and edge-network vulnerabilities.
Vulnerabilities in Juniper Networks Junos OS, SRX Series firewalls, and other carrier- and enterprise-grade network hardware — the routing and firewall gear that sits at the edge of large networks, where a bug on the management plane often means full device compromise.
ManageEngine ADSelfService Plus, ADAudit Plus, and the APT-magnet product line.
Vulnerabilities in Zoho's ManageEngine suite — ADSelfService Plus, ADAudit Plus, ServiceDesk Plus, and adjacent identity and IT-management tools — where authentication bypasses and unauthenticated RCEs draw APT groups and ransomware operators as quickly as CVEs are published.
Remote Support, Privileged Remote Access, and PAM appliance disclosures.
Vulnerabilities and patches across BeyondTrust's remote-access and privileged-access product line — Remote Support (RS), Privileged Remote Access (PRA), and adjacent PAM appliances whose compromise typically hands attackers a foothold in the vendor-and-third-party access path into an enterprise.
Malware families, threat-actor campaigns, takedowns, and research that doesn't hang on one CVE.
Coverage that doesn't reduce to a single vendor advisory: infostealer and RAT write-ups, threat-actor campaigns and infrastructure takedowns, tooling roundups, and industry analysis on where security practice is falling behind.
UniFi OS, UniFi Network, and edge gear on the LAN.
Vulnerabilities in Ubiquiti's UniFi product line — the switches, gateways, and access points that make up the physical layer of a lot of small businesses, campuses, and prosumer networks, often deployed once and rarely touched again.
SimpleHelp remote-support server disclosures, patches, and KEV entries.
Vulnerabilities and patches in SimpleHelp's remote-support server — an on-prem RMM/support tool whose compromise typically hands attackers pre-authenticated technician access to every endpoint enrolled behind it. Covered here because remote-support servers are a repeat target for ransomware crews and CISA has added multiple SimpleHelp flaws to its Known Exploited Vulnerabilities catalog.
Zimbra Collaboration Suite advisories and patches.
Vulnerabilities, patches, and vendor advisories affecting Zimbra Collaboration Suite — the Classic Web Client, Modern UI, and mailboxd server components — plus the operational impact of Zimbra patch cycles on the organizations still self-hosting webmail.
Windchill PDMLink, FlexPLM, and the PLM/PDM software that sits between engineering and the shop floor.
Coverage of PTC's Product Lifecycle Management and Product Data Management platforms — Windchill PDMLink and FlexPLM — the enterprise engineering software that owns CAD, BOMs, and manufacturing releases at large industrial and defense firms. Not ICS itself, but the pipeline into it.
Firewall, ATP, USG, and edge-appliance vulnerabilities.
Vulnerabilities in Zyxel ZyWALL/USG, USG FLEX, ATP, and VPN-series firewalls and other SMB/branch-office edge networking gear — perimeter appliances that recur on the CISA KEV catalog and remain a durable target for botnet operators years after patch availability.
Zoom Workplace, VDI Client, Meeting SDK — PSIRT advisories and desktop-client bugs.
Vulnerabilities across the Zoom stack: Workplace (formerly Zoom Client), Windows and macOS VDI Clients, Meeting SDK, Rooms, and the browser plug-ins. Zoom Product Security (PSIRT) advisories, in-the-wild reports, and the desktop-client bugs that turn every enterprise's collaboration surface into an attack surface.
E-Business Suite, Fusion Middleware, WebLogic, Database, and the quarterly Critical Patch Update cycle.
Vulnerabilities and patches across Oracle's enterprise stack — E-Business Suite (including Payments), Fusion Middleware, WebLogic Server, Database, and Java — driven by the January, April, July, and October Critical Patch Update cycle.
Open-source workflow automation with Enterprise SSO and OEM deployments.
Vulnerabilities in n8n, the open-source workflow automation platform — including Enterprise-only auth, token-exchange, and OEM-integration flaws that surface as CVEs against multi-issuer SSO deployments.