Vuln deskCybersecurityBusiness & technology

Cybersecurity · Business & technology

ExploitLedger

The business of cybersecurity, read through primary sources. Every story is grounded in a patent record — the technology and strategy behind the security industry, not the marketing.

24Articles indexed
100%Primary-source grounded
PatentsThe IP behind security

Latest Articles

24 articles indexed

Cybersecurity

Deserialization Flaw in iba ibaPDA and ibaDatCoordinator Can Give Remote Attackers Full System Access, NVD Records

CVE-2026-8024, a critical (CVSS 9.8) deserialization-of-untrusted-data vulnerability in iba's ibaPDA and ibaDatCoordinator, can be exploited by a remote, unauthenticated attacker, according to the National Vulnerability Database and a CERT@VDE advisory.

By Priya Anand · Jun 18, 2026 · NVD

Cybersecurity

When a Filename Runs Code: Vim's tar.vim Command Injection

CVE-2026-46483 let a crafted .tgz archive filename inject shell commands through Vim's tar plugin because shellescape() was called without the {special} flag. NVD scores it 3.6 Low.

By Priya Anand · Jun 16, 2026 · NVD

Cybersecurity

CISA Flags an Unauthenticated PeopleSoft Takeover as Ransomware-Linked

CVE-2026-35273 lets an unauthenticated attacker take over Oracle PeopleSoft Enterprise PeopleTools. CISA added it to the Known Exploited Vulnerabilities catalog with a 'known ransomware' tag and a same-day federal remediation deadline.

By Marcus Reyes · Jun 16, 2026 · CISA KEV