A Three-Year-Old Proxmox Fix Just Became an Emergency

A passwordless Proxmox VE authentication bypass was fixed in 2023 but disclosed three years later, leaving exposed end-of-life control planes at urgent risk.
Windows, Linux, identity, virtualisation, networks and platforms.

A passwordless Proxmox VE authentication bypass was fixed in 2023 but disclosed three years later, leaving exposed end-of-life control planes at urgent risk.

CISA says attackers are exploiting a Switchvox SQL injection that turns one unauthenticated web request into operating-system command execution.

Three critical WatchGuard Firebox flaws let unauthenticated VPN traffic reach remote code execution. The full bulletin contains eleven Fireware vulnerabilities.

Seven flaws affect every Cisco IOS XR release, two carry a 9.8 score, and operators have no general workaround while planning fixes.

Fire Ant turned a Cisco IOS XR router, TACACS systems and Linux management hosts into a covert collection and access platform.

AWS has fixed a high-severity OpenSearch SQL Plugin flaw that turns a low-privilege search account into a route to arbitrary code execution on the server. The dangerous part is the permission boundary: the account only needs basic read and search…

Cronos halted its entire network after an exploit in Tectonic. The incident turns a DeFi collateral failure into a test of chain-wide emergency governance.
Ten malicious npm releases carried valid provenance because an outsider could drive the project’s trusted GitHub Actions publishing workflow.

Microsoft observed attackers turning exposed LiteLLM gateways into credential-harvesting, database-access and persistence hubs. The public exploit chain makes AI gateways a Tier-0 patching priority.

argocd-mcp 0.8.0 exposed its Argo CD tool surface without caller authentication, letting reachable clients act with the server's stored token. Version 0.9.0 rebuilds the boundary.