Latest News

Vulnerabilities

CVE-2026-5194: Critical wolfSSL Flaw Lets Attackers Pass Off Forged Certificates

A critical cryptographic validation bug in the widely deployed wolfSSL library allows improperly weak digests to be accepted during certificate verification, potentially letting attackers impersonate malicious servers. The flaw was patched in wolfSSL 5.9.1 on April 8, 2026.

Analysis

OT Environments Can't Back Up Post-Quantum Cryptography Attestations

Operational technology asset owners are being required to attest to post-quantum cryptographic readiness, but the frameworks, tools, and visibility needed to make those attestations meaningful simply don't exist in most OT environments.

Vulnerabilities

Adobe Issues Emergency Patch for Actively Exploited Acrobat and Reader Zero-Day

Adobe has pushed an out-of-band security update for Acrobat and Reader to address CVE-2026-34621, a zero-day vulnerability exploited in the wild since at least December that allows malicious PDFs to escape sandbox protections and execute arbitrary code.

← Prev 1 8586878889 103 Next →