Apache Struts is a widely used open-source Java-based web application framework that powers many enterprise websites and services.
Apache Struts is a widely used open-source Java-based web application framework that powers many enterprise websites and services. Recent reports describe a vulnerability in Struts that can be exploited to trigger disk exhaustion on affected servers, creating a denial-of-service risk for organizations relying on Struts-based apps.
A China-linked threat actor known as Red Menshen has been conducting a long-term espionage campaign targeting global telecommunications networks using a stealthy Linux kernel backdoor called BPFdoor. This malware…
Atlassian Confluence has faced multiple critical vulnerabilities, including CVE-2022-26134 and CVE-2023-22515. CVE-2022-26134, published on June 3, 2022, is an unauthenticated remote code execution vulnerability that…
A new CVSS 10.0 vulnerability, CVE-2026-29000, was published on March 4, 2026, allowing attackers to bypass authentication in the pac4j-jwt library, enabling impersonation of any user, including administrators. This…
The article discusses the fifth volume of AttackIQ’s Ransom Tales series, which simulates the tactics of ransomware families REvil, DarkSide, and BlackMatter. These emulations are designed to help organizations validate…
A vulnerability in Apache Struts has been identified, allowing attackers to execute disk exhaustion attacks. This flaw poses risks to systems using the affected version of Apache Struts, potentially leading to service…