When Business Email Compromise Starts Rewriting RealityDouglas McKee, Director, Vulnerability Intelligence
CVE-2026-0826: How an Old Bug Can Feed AI-Powered ImpersonationDouglas McKee, Director, Vulnerability Intelligence
CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones (FIXED)Stephen Fewer
CVE-2026-52806: Authenticated RCE via Argument Injection in Gogs (FIXED as of June 7, 2026)Jonah Burgess
CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)Jonah Burgess, Stephen Fewer
CVE-2026-31381, CVE-2026-31382: Gainsight Assist Information Disclosure and Cross-Site Scripting (FIXED)Christopher O’Boyle
The Phone is Listening: A Cold War–Style Vulnerability in Modern VoIPDouglas McKee, Director, Vulnerability Intelligence
CVE-2026-2329: Critical Unauthenticated Stack Buffer Overflow in Grandstream GXP1600 VoIP Phones (FIXED)Stephen Fewer
CVE-2025-10184: OnePlus OxygenOS Telephony provider permission bypass (FIXED as of October 11, 2025)Rapid7
CVE-2025-4365/CVE-2024-12284: NetScaler Console/SDX Authenticated Arbitrary File Read/Write (FIXED)Calum Hutton