Every month, major operating systems, browsers, runtimes, and cloud platforms drop dozens of CVEs. We filter out the noise, isolate the actively exploited zero-days, and link directly to line-by-line high-level code teardowns.
Monthly security rollups, kernel elevation of privilege exploits, and critical system service vulnerabilities.
Triage of 79 CVEs including CVE-2024-30051 DWM zero-day exploited in the wild by ransomware.
Triage of Ubuntu's September 2026 kernel rollups addressing critical io_uring memory corruption, eBPF verifier...
Technical triage of Canonical's August 2026 kernel update patching critical Netfilter nf_tables double-free an...
Triage of Ubuntu's July 2026 kernel updates fixing critical OverlayFS file capability bypasses and container s...
Technical triage of Ubuntu's core system library updates resolving the Glibc __vsyslog_internal buffer overflo...
Triage of Ubuntu's May 2026 kernel advisory addressing Kernel TLS zero-copy use-after-free and cryptographic s...
Technical triage of Ubuntu's April 2026 update fixing AppArmor socket mediation bypasses and packet filter san...
Handset security bulletins, baseband/kernel hardware zero-days, and browser sandbox exploits.
Analysis of CVE-2024-23222 WebKit JIT type confusion targeted by commercial spyware.
Triage of Google's September 2026 Android bulletin resolving actively exploited zero-days in the Binder IPC dr...
Technical triage of Android's August 2026 release addressing critical Qualcomm Adreno GPU kernel memory corrup...
Triage of Android's July 2026 security release addressing remote code execution via malformed H.264/H.265 vide...
Technical triage of Google's June 2026 Pixel advisory resolving actively exploited zero-days in the Arm Mali G...
Triage of Android's May 2026 security updates resolving framework intent redirection flaws and mutable Pending...
Technical triage of Android's April 2026 release addressing zero-click Bluetooth HCI fragmentation heap buffer...
V8 engine type confusions, HTTP request smuggling in llhttp, and runtime permission sandbox escapes.
Emergency stable channel patch for CVE-2024-4947 V8 Turbofan compiler type confusion.
Triage of the coordinated September 2026 Node.js release patching critical HTTP request smuggling in llhttp ac...
Technical triage of Node.js July 2026 security release fixing filesystem sandbox escapes in the experimental p...
Triage of Node.js May 2026 release fixing CRLF header injection and SSRF protections in the built-in global fe...
Technical triage of Node.js April 2026 emergency update fixing critical command argument injection on Windows ...
Control plane authorization bypasses, runc container breakouts, and Ingress annotation code injection.
Triage of the Kubernetes September 2026 release addressing authorization bypasses in aggregated API servers an...
Technical triage of the July 2026 ingress-nginx security advisory resolving custom annotation code injection a...
Triage of the May 2026 Kubernetes release addressing named pipe impersonation and container host breakout on W...
Technical triage of the landmark Leaky Vessels runc container breakout (CVE-2024-21626) affecting Docker, Kube...