News
The zero-day is described as a critical deserialization vulnerability affecting Sitecore Experience Manager (XM), Sitecore ...
An ASP.NET feature, ViewState stores the state of a webpage in a hidden HTML field, for persistence. Attackers can target the ...
Attackers exploited a now-patched zero-day vulnerability in a popular content management system that powers websites for ...
Threat actors have been exploiting a zero-day vulnerability in legacy Sitecore deployments to deploy WeepSteel reconnaissance ...
Attackers are leveraging a sample machine key in Sitecore products for initial access before ViewState code injections lead ...
"The upshot of CVE-2025-53690 is that an enterprising threat actor somewhere has apparently been using a static ASP.NET ...
The Register on MSN21h
Attackers snooping around Sitecore, dropping malware via public sample keys
You cut and pasted the machine key from the official documentation? Ouch Unknown miscreants are exploiting a configuration ...
Google Cloud’s Mandiant successfully disrupted an active ViewState deserialization attack affecting Sitecore deployments ...
Take advantage of response compression middleware in ASP.NET Core to reduce bandwidth requirements and improve the responsiveness of your apps.
Results that may be inaccessible to you are currently showing.
Hide inaccessible results