Vulnerability scanning vs penetration testing: which one?
Vulnerability scanning vs penetration testing: one finds known flaws at scale, the other proves what an attacker can exploit. Which you need, and why both.
CloudKey Blog
Ranked CVE roundups, zero-day analysis, product walkthroughs and honest comparisons. New posts Mon, Wed and Fri.
Vulnerability scanning vs penetration testing: one finds known flaws at scale, the other proves what an attacker can exploit. Which you need, and why both.
CVE-2026-48907 in Joomla Content Editor lets unauthenticated attackers upload PHP webshells. CISA added it to KEV on June 16; patch to JCE 2.9.99.6 now.
Attackers are exploiting Cisco Catalyst SD-WAN Manager (CVE-2026-20262) and the LiteSpeed cPanel plugin (CVE-2026-54420), both added to CISA KEV on June 15, 2026. Patch now.
CISA added six CVEs to KEV in the week of June 15, 2026: Oracle PeopleSoft, Ivanti Sentry, Cisco SD-WAN, Arista, Chrome and LiteLLM. Scores and what to patch first.
Oracle PeopleSoft PeopleTools CVE-2026-35273: active exploitation, known ransomware use, unauthenticated takeover, CVSS 9.8, on CISA KEV. Who is affected and what to do.
CISA added Ivanti Sentry CVE-2026-10520 to KEV on June 11, 2026. Unauthenticated root RCE, CVSS 10.0, federal due date June 14. Here is who is affected and what to do.
What a CVE is, who assigns the IDs, how the numbering works, and how to act on the 40,000+ published each year. A plain-language guide for IT and security teams.
Four CVEs hit CISA KEV this week: Linux, Android, Magento RCE, and SolarWinds DoS. See which patch cuts the most risk against confirmed exploitation.
CVSS vs EPSS vs KEV: three signals that rank vulnerabilities differently. Why CloudKey patches KEV-listed CVEs first, EPSS-elevated next, CVSS last.
A CloudKey dark web monitoring report, walked section by section: the open-finding ledger, re-test attestations, and the parts auditors ask for first.
SBOM asset inventory reconciliation maps each signed manifest to the host actually running it, so the CVE queue ranks risk on real systems, not the manifests.
Subscribe via RSS: /rss.xml
Ce site est aussi disponible en français.