Apache Gravitino SSRF Vulnerability Allows Metadata Theft
A server-side request forgery vulnerability has been discovered in Apache Gravitino. The flaw affects versions 1.0.0 through 1.2.1 and allows authenticated...
Expert analysis, threat intelligence, and practical guidance from Red Secure Tech's security specialists — covering penetration testing, vulnerability assessment, incident response, and secure development for UK businesses.
A server-side request forgery vulnerability has been discovered in Apache Gravitino. The flaw affects versions 1.0.0 through 1.2.1 and allows authenticated attackers to fetch internal metadata and clo...
Read Full ArticleA server-side request forgery vulnerability has been discovered in Apache Gravitino. The flaw affects versions 1.0.0 through 1.2.1 and allows authenticated...
Threat actors have started to target a critical security vulnerability that has been recently patched by Broadcom VMware vCenter. The vulnerability gives a...
A maximum severity level vulnerability was detected in SAP Commerce Cloud, for which patches have been released by SAP. The vulnerability would allow arbit...
A security researcher has released a proof-of-concept exploit for a new Microsoft zero-day called ShieldBreak. The vulnerability demonstrates a full patch...
A new vulnerability affecting Cisco Secure Firewall ASA and FTD software is currently being exploited in the wild, according to Cisco. The flaw allows unau...
A security researcher has published an exploit for a critical OS command injection flaw in CorgetGpsDget. The vulnerability is in the GPS application and e...
A critical unauthenticated remote code execution vulnerability in the JCE extension for Joomla has been exploited. A public proof-of-concept is now availab...
Windows Plug and Play may be leveraged to fetch signed vendor software for an emulated USB device and run the installation component at elevated privileges...
Our blog insights are backed by hands-on service delivery. Whether you need a penetration test, vulnerability assessment, emergency website recovery, or secure web development — our UK cybersecurity specialists are ready to help.
Emergency malware removal, backdoor elimination, blacklist delisting, and full post-incident hardening for compromised websites.
Authorised simulated attacks exposing real vulnerabilities in your web applications, networks, and infrastructure before attackers do.
Systematic identification and prioritisation of security weaknesses across your digital estate — with actionable remediation guidance.
OWASP-aligned web application development with security engineered in from architecture through to penetration-tested deployment.
Advanced adversary simulation testing your organisation's detection and response capabilities against real-world threat actor behaviour.
Actionable intelligence on threat actors, attack vectors, and emerging risks targeting your sector — enabling proactive defensive decisions.
© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067