Lydia Zhang, president of Ridge Security, said this recent attack was more closely related to CVE-2024-53704 rather than CVE-2024-40766. Zhang said the “53704” SonicWall SSL VPN vulnerability leaks the swap cookie and session ID, which lets a remote attacker bypass authentication and take over an existing session.
Recent Posts
- GitLab Unauthenticated Path Traversal Exploited in the Wild (CVE-2026-85706)
- The Harness Advantage in Autonomous Red Teaming: Why Frontier LLMs Alone Fail Offensive Security and How RidgeGen Solves the Alignment Dilemma
- Your Pentest Agent Needs the Credential. Its LLM Doesn’t. Can We Keep Them Apart?
- Ridge Security Join Anthropic’s Cyber Verification Program
- Disposable Code, Durable Side Effects
Category Tags
- Blog
- How are collaborative AI agents (Agentic AI) reshaping offensive security?
- How can AI-driven validation drastically reduce the time between detection and remediation?
- How can you prove that a vulnerability represents a real breach risk?
- What do recent CVEs reveal about the most common mistakes in vulnerability management?
- What lessons can we learn from recent cases like the Salesforce token abuse or Fortra GoAnywhere CVEs?
- What makes Continuous Threat Exposure Management (CTEM) different from traditional penetration testing?
- What role does automation play in solving the “vulnerability overload” challenge?
- Why are API attacks still rising, and how can organizations prevent OAuth token abuse?
- Why do so many security teams prioritize irrelevant vulnerabilities while overlooking exploitable ones?