
Citrix found two more holes in NetScaler — one skips the login screen completely
Three weeks after the last NetScaler patch-now story, Citrix is back with a critical bug that needs no password and no user interaction at all.
Kernel · Aug 26 · 6 min
5 articles · newest first

Three weeks after the last NetScaler patch-now story, Citrix is back with a critical bug that needs no password and no user interaction at all.
Kernel · Aug 26 · 6 min

Microsoft patched this JWT flaw back in July. A public proof-of-concept turned it into real attacks in under 48 hours — here's exactly what's broken and how to check if you're exposed.
Kernel · Aug 20 · 6 min

CVE-2026-62911 only scores an 8.0, but it came with working exploit code demonstrated at Pwn2Own Berlin — and it doesn't stop at one mailbox.
Kernel · Aug 17 · 7 min

A broken identity check let attackers skip the login screen entirely — and Check Point found out because someone was already inside.
Kernel · Aug 1 · 6 min

While everyone patched the wp2shell core flaw, a 9.8-rated hole in a popular login plugin quietly went public with no fix available. If you run miniOrange's OAuth SSO, updating WordPress didn't save you.
Kernel · Jul 22 · 7 min