Toggle navigation
SCADA - ICS - IIoT Security Bootcamp
Cyber Range
Contact
Critical Infrastructure
SecList ICS
Threat landscape for industrial automation systems in Q2 2025
Notes of cyber inspector: three clusters of threat in cyberspace
Security Magazine
High Water Mark: CISA Shares Foundations for Effective Cybersecurity and Risk Management
From Farm to Table: Securing the Future of Agriculture with Innovative Technology
Iran’s Cyber Playbook: What US Critical Infrastructure Needs to Be Doing Right Now
Hacktivism Increasingly Targeting Critical Infrastructure
Physical Security Measures That Respect Constitutional Rights
The importance of security for power utility substations
Security Leaders Discuss Cyberattack on American Airlines Subsidiary
Cyberattack Disrupts European Airports, Security Leaders Respond
Integrating Mass Notification with Video Surveillance in Airports
Windsor port authority strengthens US-Canada border waterway
Protecting ships from cyber terrorism
Biden administration issues executive order to secure U.S. ports
From Farm to Table: Securing the Future of Agriculture with Innovative Technology
Layered Secure Entrances Strengthen Warehouse and Supply Chain Security
How Air Travel Became Safer Through Cashless Service
No Smoke, Just Signals: Iris Recognition for Cannabis Compliance
Scattered Spider’s Newest Targets: Transportation and Airlines
The Future of Public Transit: Leveraging AI Analytics for Enhanced Operations and Passenger Experience
Case Studies
The 2 am call: Preparing for a government cyberattack
Häfele recovers from ransomware attack with new SASE platform
Ride-hailing company, inDrive, uses new platform to prevent fraud
The Old Spaghetti Factory restaurant chain ups network & physical security
K-8 students learn cybersecurity through gamification
Electric company uses SAP monitoring to bolster cybersecurity
Transforming Higher Ed Safety and Efficiency with Cloud-Based Access Control
Pennsylvania School District Adopts AI-Driven Gun Detection Technology
Protecting 14 Campuses, All With Different Needs
Campus collaboration: a security-focused work management platform
Windsor port authority strengthens US-Canada border waterway
From the stone age to cutting edge: A case study on key management
News
Exploits
[webapps] phpMyFAQ 2.9.8 - Cross-Site Request Forgery(CSRF)
[webapps] phpMyFAQ 2.9.8 - Cross-Site Request Forgery (CSRF)
[webapps] MaNGOSWebV4 4.0.6 - Reflected XSS
[webapps] Django 5.1.13 - SQL Injection
[webapps] phpMyFaq 2.9.8 - Cross Site Request Forgery (CSRF)
[webapps] MobileDetect 2.8.31 - Cross-Site Scripting (XSS)
[webapps] phpIPAM 1.4 - SQL-Injection
[webapps] OpenRepeater 2.1 - OS Command Injection
[webapps] phpMyAdmin 5.0.0 - SQL Injection
[webapps] RosarioSIS 6.7.2 - Cross Site Scripting (XSS)
[webapps] RosarioSIS 6.7.2 - Cross-Site Scripting (XSS)
[webapps] PluckCMS 4.7.10 - Unrestricted File Upload
[webapps] openSIS Community Edition 8.0 - SQL Injection
[webapps] YOURLS 1.8.2 - Cross-Site Request Forgery (CSRF)
[webapps] phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)
[webapps] phpIPAM 1.5.1 - SQL Injection
[webapps] Piwigo 13.6.0 - SQL Injection
[webapps] phpIPAM 1.6 - Reflected-Cross-Site Scripting (XSS)
[webapps] phpIPAM 1.6 - Reflected Cross-Site Scripting (XSS)
[webapps] Flowise 3.0.4 - Remote Code Execution (RCE)
[webapps] Casdoor 2.95.0 - Cross-Site Request Forgery (CSRF)
[remote] Ilevia EVE X1/X5 Server 4.7.18.0.eden - Reverse Rootshell
[local] Microsoft Windows Server 2025 Hyper-V NT Kernel Integration VSP - Elevation of Privilege
[remote] ClipBucket 5.5.0 - Arbitrary File Upload
[remote] ClipBucket 5.5.2 Build #90 - Server-Side Request Forgery (SSRF)
[webapps] Tourism Management System 2.0 - Arbitrary Shell Upload
[webapps] Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)
[webapps] dotCMS 25.07.02-1 - Authenticated Blind SQL Injection
[webapps] ELEX WooCommerce WordPress Plugin 1.4.3 - SQL Injection
[webapps] XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)
[webapps] Concrete CMS 9.4.3 - Stored XSS
[local] Mbed TLS 3.6.4 - Use-After-Free
[remote] HTTP/2 2.0 - Denial Of Service (DOS)
[remote] HTMLDOC 1.9.13 - Stack Buffer Overflow
[remote] GeoVision ASManager Windows Application 6.1.2.0 - Remote Code Execution (RCE)
[local] GeoVision ASManager Windows Application 6.1.2.0 - Credentials Disclosure
[webapps] StoryChief Wordpress Plugin 1.0.42 - Arbitrary File Upload
[remote] Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass
[webapps] Lingdang CRM 8.6.4.7 - SQL Injection
[webapps] Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure
[remote] Tenda AC20 16.03.08.12 - Command Injection
[webapps] Lantronix Provisioning Manager 7.10.3 - XML External Entity Injection (XXE)
[webapps] Soosyze CMS 2.0 - Brute Force Login
[remote] Microsoft Windows 10.0.19045 - NTLMv2 Hash Disclosure
[remote] PHPMyAdmin 3.0 - Bruteforce Login Bypass
[webapps] RiteCMS 3.0.0 - Reflected Cross Site Scripting (XSS)
Last 20 Website Defacements - Zone-h
Advisories