Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
ConnectWise ScreenConnect has been compromised by two critical vulnerabilities, CVE-2024-1708 and CVE-2024-1709, which allow attackers to bypass authentication and execute remote code. The vulnerabilities were disclosed on February 19, 2024, with CVE-2024-1709 rated critical (CVSS 10.0) for authenti...
A security researcher, known as Chaotic Eclipse, has publicly released exploit code for a zero-day vulnerability in Windows, dubbed BlueHammer, allowing local privilege escalation to SYSTEM or elevated administrator privileges. The exploit targets a flaw in the Windows Defender update mechanism and...
A newly discovered vulnerability, CVE-2026-6770, allows attackers to fingerprint users of Firefox and Tor browsers, even in Private Browsing mode. The flaw, identified in the IndexedDB API, enables the creation of a database that can be queried to track users across different sessions. This vulnerab...
Researchers have discovered a vulnerability in Notepad's newly added Markdown support that can be exploited for remote code execution (RCE). This flaw, tracked as CVE-2026-20841 with a severity score of 8.8, was addressed in Microsoft's latest Patch Tuesday updates. The exploitation requires social...