Toggle navigation
SCADA - ICS - IIoT Security Bootcamp
Cyber Range
Contact
Critical Infrastructure
SecList ICS
Threat landscape for industrial automation systems. Q2 2026
Threat landscape for industrial automation systems. Q1 2026
Security Magazine
Critical Infrastructure Cyberattack Encrypts Central IT Structures
Compromising 5.4% of Texas’ Battery Fleet Could Black Out the Grid
100+ Internet-Exposed Water Systems Faced Cyberattacks Last Month
Red Team Discoveries Support Organizations in Assessing Risk
Iranian Cyberattack Shuts Down UK Power Generator
Protecting America’s Critical Infrastructure: A Shared Responsibility in an Era of Escalating Cyber Threats
Manchester Airports Breach Impacts 8.7M
LAX Security Guard Found With 24 Pounds of Fentanyl, Facing Charges
Majority of Organizations Lack Drone Mitigation Due to Legal Restrictions
You Can’t Secure a Ship Like a Laptop
Julia Stuyt — Women in Security 2026
No More Failures of Imagination: Future Proofing Airport Employee Screening
Uber Freight Investigates Data Security Concern
You Can’t Secure a Ship Like a Laptop
Critical Crossings: Securing Bridges and Tunnels
Inside the Modern Warehouse: Securing the World’s New Front Door
Pro-Iranian Actor Claims L.A. Metro Cyberattack
Airport Security Challenges in the Midst of the DHS Shutdown
Case Studies
The 2 am call: Preparing for a government cyberattack
Häfele recovers from ransomware attack with new SASE platform
Ride-hailing company, inDrive, uses new platform to prevent fraud
The Old Spaghetti Factory restaurant chain ups network & physical security
K-8 students learn cybersecurity through gamification
Electric company uses SAP monitoring to bolster cybersecurity
Buzzfeed Deploys AI-Powered GSOC Operating System
Fifth Third Bank Strengthens Security With Security Operations Center
Thornton Township High School District Implements ZeroEyes
Transforming Higher Ed Safety and Efficiency with Cloud-Based Access Control
Pennsylvania School District Adopts AI-Driven Gun Detection Technology
Protecting 14 Campuses, All With Different Needs
News
Exploits
[remote] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE
[webapps] FreePBX 17.0.2 - Remote Code Execution (RCE)
[webapps] Metabase 0.61.0 - Authenticated Remote Code Execution
[dos] EVerest 2025.9.0 - DoS
[webapps] Bludit CMS 3.20.0 - Reflected Cross-Site Scripting
[webapps] PodcastGenerator 3.2.9 - Stored XSS
[webapps] Ghost_CMS 6.19.0 - Remote Code Execution
[webapps] Langflow 1.10.0 - RCE
[hardware] Fullhan FH8626V100 - Multiple Vulnerabilities
[webapps] Marimo 0.20.4 - RCE
[webapps] Wolf CMS 0.8.3.1 - RCE v
[webapps] Payload CMS 3.72.0 - Blind SQL Injection
[webapps] Bludit CMS - Stored XSS
[webapps] Grav CMS 2.0.7 - RCE
[webapps] miniOrange 5.4.3 - Unauthenticated Auth Bypass
[webapps] EasyAppointments 1.5.1 - Blind SQL Injection
[webapps] C-MOR 6.0104 - Directory Traversal
[webapps] C-MOR 6.0104 - Cross-Site Scripting (XSS)
[webapps] CubeCart 6.7.4 - SQL injection
[webapps] CubeCart 6.7.4 - SQL
[webapps] CubeCart 6.7.4 - Stored XSS
[webapps] CubeCart 6.7.4 - Cross-Site Scripting
[webapps] Linksys E1200_2.0.04 - Unauthenticated OS Command Injection
[webapps] Langflow 1.8.4 - Path Traversal to Remote Code Execution
[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE
[remote] PCMan 2.0.7 - Buffer Overflow
[dos] NanaZip 6.5 - DoS
[webapps] flyto-core 2.26.7 - Arbitrary File Write
[webapps] Nodemailer 9.0.0 - File Read/ SSRF
[webapps] Linuxfabrik monitoring_plugins_6.0.0 - SSRF
[dos] NanaZip 6.5 - DoS
[webapps] flyto_core 2.26.7 - Server-Side Request Forgery
[webapps] Probo 0.222.2 - IDOR
[webapps] webpack_devserver 5.2.5 - CSRF
[remote] phpSysInfo 3.4.5 - IP Allowlist Bypass
[dos] Nmap 7.99 - Extension Header Integer Underflow
[webapps] Duplicati 2.2.0.3 - JWT Signing Key Leak
[webapps] Joomla JCE_2.9.15 - Remote Code Execution
[remote] ipTIME A3004T - Remote Code Execution
[remote] D-Link DNS_340L - OS Command Injection
[webapps] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
[webapps] Apache Gravitino 1.2.1 - SSRF
[webapps] Blocksy Companion 2.1.46 - RCE
[remote] PraisonAI praisonaiagents 1.6.77 - Remote Code Execution
[remote] mcp-server-kubernetes 3.8.x - Argument Injection
[dos] LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting
Last 20 Website Defacements - Zone-h
Advisories