Category

vulnerability

86 articles

Patch Tuesday 2026-May: What to Patch Now

Background The last week has been a stark reminder that modern operating systems are under constant pressure from attackers who have already mapped out how to exploit even well-patched software. Patch Tuesday 2026-May brought an unusually high volume of CVEs, many of which target foundational components: BitLocker recovery pathways, Secure

Edgerunner Edgerunner 6 min read
vulnerability vulnerability cve zero-trust

Ivanti EPMM Zero‑Day Exploited: Hardening Conditional Access to Stop Admin Privilege Abuse

Background The pressure on security teams to harden mobile device management environments has never been more acute. With remote work now fully integrated into business operations, organizations rely heavily on solutions like Microsoft Intune and other MDM platforms for policy enforcement, app deployment, and compliance monitoring. However, these same tools

Edgerunner Edgerunner 3 min read

Exploiting Public-Facing Apps: Why T1190 Still Gets Us Overwhelmed

Background The threat landscape in 2026 continues to highlight how public-facing applications remain a primary attack surface for threat actors leveraging automated exploitation frameworks and opportunistic vulnerability research. The recent surge of high-impact CVEs added to the Known Exploited Vulnerabilities (KEV) catalog—such as BerriAI LiteLLM SQL Injection (CVE-2026‑42208)

Edgerunner Edgerunner 5 min read

CISA KEV Alert: Linux LPE CVE-2026-31431 Now Actively Exploited

Background The threat landscape has shifted from opportunistic scanning to surgical strikes against foundational infrastructure. CISA's recent action—adding CVE-2026-31431 to the Known Exploited Vulnerabilities (KEV) catalog—isn't just administrative housekeeping; it is a signal flare that attackers have moved beyond reconnaissance and are actively weaponizing

Edgerunner Edgerunner 3 min read