A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. The
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks.