Vulnerabilities

279 articles

Vulnerabilities

Linux Kernel Vulnerabilities & AI-Powered Malware

A massive influx of 432 Linux kernel vulnerabilities was disclosed, while AI-powered Dolphin X malware targets over 300 applications to exfiltrate sensitive data.

Vulnerabilities

CIRCIA Cyber Incident Reporting

Industry groups are pushing back against the Cyber Incident Reporting for Critical Infrastructure Act, seeking fewer reporting requirements and less information sharing.

Vulnerabilities

OpenAI Patches ChatGPT Agent Flaw

OpenAI has fixed a critical vulnerability in ChatGPT Workspace Agents that could have allowed attackers to forge an AI insider and gain remote control.

Vulnerabilities

FedRAMP Rev5 Ends: Understanding 20X Transition Requirements

FedRAMP 20X replaces narrative-heavy controls with Key Security Indicators, requiring organizations to continuously prove their security posture with machine-readable evidence.

Vulnerabilities

CVE-2025-66376: Zimbra Email Theft via Zero-Click Flaw

Russian hackers exploit a Zimbra zero-click flaw to steal email data from organizations, using a combination of phishing attacks and the CVE-2025-66376 vulnerability.

Vulnerabilities

CVE-2026-16232 SmartConsole Zero-Day

Check Point's SmartConsole GUI admin panel has a zero-day flaw, tracked as CVE-2026-16232, allowing unauthenticated attackers to obtain an application login token with administrator privileges.

Vulnerabilities

Vibe-Coded Apps Security Flaws

Vibe-coded apps are found to be riddled with exploitable security flaws, with 434 issues discovered in a recent study, highlighting the need for improved security measures in AI-assisted development.

Vulnerabilities

Material Breach Tracker

A new index tracks disclosed material breaches, providing a resource for cybersecurity professionals and citizens to access information on cyber incidents.

Vulnerabilities

Windows LegacyHive Zero-Day Exploit

A new Windows zero-day exploit, dubbed LegacyHive, allows attackers to escalate privileges on up-to-date Windows systems, granting admin access with additional credentials.

Vulnerabilities

Abbott Laboratories Probes Cyber Incidents Amid Extortion Claims

Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy systems and a separate claim of a breach at its LabCentral portal.

Vulnerabilities

CMMC Phase 2 Suspension

The Department of War has suspended CMMC Phase 2's mandatory third-party assessment requirement, citing concerns over scalability and compliance costs.

Vulnerabilities

CVE-2026-46817: Actively Exploited Oracle Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch the actively exploited Oracle E-Business Suite flaw by Saturday, July 18.

Vulnerabilities

Operational Technology Security Challenges

The security of operational technology (OT) systems is a growing concern, with legacy systems and real-world impacts making it a complex issue to address. OT security issues are distinct from IT security issues, with a greater emphasis on preventing denial of service (DoS) attacks that can have catastrophic consequences.

Vulnerabilities

CVE: Claude Chrome Extension Flaw

A flaw in the Claude Chrome extension allows malicious extensions to trigger predefined AI actions, potentially abusing access to connected services like Gmail and Salesforce.

Vulnerabilities

SonicWall Zero-Day Vulnerabilities Exploited

Attackers are exploiting two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, in SonicWall SMA1000 appliances, with the goal of ransomware attacks.

Vulnerabilities

Windows 10 KB5099539 Update Released

Microsoft releases Windows 10 KB5099539 extended security update, fixing 570 vulnerabilities, including two exploited and one publicly disclosed zero-day flaws.

Vulnerabilities

Windows Bind Link Attacks Evade EDR Tools

Researchers at Bitdefender demonstrate three attack techniques using Windows' bind links to evade endpoint detection and response products, highlighting a security problem that relies heavily on paths.

Vulnerabilities

AI-Generated Code Security Risks

AI-generated code poses significant security risks, with 45% of code produced by AI tools being insecure, according to Veracode's 2025 GenAI Code Security report.

Vulnerabilities

Ransomware Enablers Sanctioned by US Treasury

The US Treasury Department sanctioned two individuals and one entity for enabling ransomware attacks against US organizations, causing billions of dollars in losses.

Vulnerabilities

Windows 11 KB5101650 & KB5099414 Updates Released

Microsoft releases Windows 11 KB5101650 and KB5099414 cumulative updates to fix security vulnerabilities and add new features.

Vulnerabilities

Microsoft Addresses Record 570 Security Flaws

Microsoft released software updates to fix at least 570 security holes in its Windows operating systems and other software, including 60 critical bugs and three zero-day flaws.

Vulnerabilities

Vulnerability Management Evolution

The gap between vulnerability disclosure and exploitation is closing, with new flaws emerging at a rate of one every 7.4 minutes, and AI turning advisories into working exploits in under a day.

Vulnerabilities

CMMC Phase 2 Suspension

The Pentagon suspends CMMC phase 2 requirements pending a 60-day review, citing bureaucratic obstacles and a shortage of approved third-party assessors.

Vulnerabilities

CISA GitHub Leak Exposes Internal Credentials

A recent data leak at CISA exposed dozens of internal credentials, including AWS Govcloud keys, in a public GitHub repository for almost six months before being notified.

Vulnerabilities

Dutch Hackers Implicated in Odido Breach

The Dutch National Police suspect Dutch hackers were involved in a February breach at telecommunications provider Odido, affecting 6.2 million customers.

Vulnerabilities

CISA Credential Leak Response

CISA strengthens protections after a major credential leak in May, improving vulnerability reporting and incident response plans.

Vulnerabilities

Windows Security Updates to Increase with AI-Discovered Flaws

Microsoft expects more Windows security updates as AI accelerates vulnerability discovery, allowing engineers to identify security issues before they can be exploited in zero-day attacks.

Vulnerabilities

Zimbra Web Client XSS Vulnerability

Zimbra urges customers to patch a critical stored cross-site scripting flaw in the Classic Web Client, which could allow attackers to steal session data or account settings.

Vulnerabilities

Ghostcommit Attack

Researchers have discovered a new attack method called 'Ghostcommit' that hides malicious instructions in images to fool AI agents and steal secrets from repositories.

Vulnerabilities

UK Unveils Agentic AI Defense Plan

The UK government has announced a new national cyber defense capability, Cyber Shield, which will utilize agentic AI to identify and remediate vulnerabilities and detect breaches.

Vulnerabilities

AI Agents Expose Identity Security Gaps

AI agents are accelerating identity security gaps, with machine identities outnumbering human users by up to 50 to 1, and 43% of organizations experiencing breaches due to inadequate governance.

Vulnerabilities

U-Boot Vulnerabilities Enable Stealthy Firmware Attacks

Six vulnerabilities in U-Boot bootloader could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks.

Vulnerabilities

Ransomware Negotiator Sentenced to 70 Months

A former DigitalMint ransomware negotiator has been sentenced to 70 months in jail for deceiving clients and conspiring with ransomware affiliates to extort $75.3 million from five US companies.

Vulnerabilities

EU Takes Member States to Court Over Unimplemented NIS2 Directive

The European Commission has filed legal referrals against Ireland, Spain, France, and the Netherlands for failing to implement the NIS2 Directive, a cybersecurity law covering critical infrastructure.

Vulnerabilities

Chrome 150 Update Resolves 27 Security Vulnerabilities

Google's Chrome 150 update patches 27 vulnerabilities, including two critical-severity flaws, with most discovered by Google, resulting in lower bug bounty rewards.

Vulnerabilities

Critical Flaws in BeyondTrust Remote Access Software

BeyondTrust warns of critical flaws in its Remote Support and Privileged Remote Access software, which could allow attackers to bypass authentication and gain unauthorized access.

Vulnerabilities

Deepfake CSAM Lawsuit Expands Against xAI and Grok

A class-action lawsuit against xAI and its Grok tool has expanded to include two new plaintiffs who claim the tool was used to create nonconsensual deepfake child sexual assault material.

Vulnerabilities

GitHub Actions Attack Pattern

A class of CI/CD weakness, named Cordyceps, allows attackers to exploit GitHub Actions workflows, even when security scanners report no issues.

Vulnerabilities

US Army Websites Defaced with Pro-Kurdish Sentiments

Multiple U.S. Army websites were defaced with pro-Kurdish messages and insults to President Donald Trump, in a 404 hijacking campaign discovered by independent cybersecurity researcher Ronald Lovelace.

Vulnerabilities

CVE-2026-20230 Exploited by Attackers

Attackers are now exploiting the Unified Communications Manager vulnerability patched in early June, with Cisco confirming active exploitation of CVE-2026-20230.

Vulnerabilities

Canadian Hacker Jailed, Open Source Zero-Days Discovered

A Canadian hacker has been sentenced to 18 months in prison for a cyberattack on the Texas GOP website, while a researcher has published proof-of-concept code for dozens of zero-day vulnerabilities in open source projects.

Vulnerabilities

Auditing AI-Driven Software Development

Conduct a successful audit of AI-driven software development to identify AI-linked vulnerabilities and ensure protected products, as one in five organizations has experienced a serious security incident directly tied to AI-generated code.

Vulnerabilities

Pegasus Spyware Targets EU Committee Member

A member of the European Parliament's PEGA Committee was infected with Pegasus spyware twice in 2022 and 2023, highlighting the need for stronger measures to prevent spyware abuses.

Vulnerabilities

UK National Cyber Action Plan Delayed

The UK's National Cyber Action Plan has been delayed amid the Labour leadership crisis, with its publication initially due on Monday, according to multiple sources.

Vulnerabilities

DHS Revives Critical Infrastructure Cybersecurity Council

The Department of Homeland Security is reviving a key cybersecurity information sharing effort with critical infrastructure, over a year after the Trump administration shut down the existing Critical Infrastructure Partnership Advisory Council.

Vulnerabilities

Agentic AI Identity Crisis

Agentic AI has an identity problem, with attackers taking notice of the lack of proper identity and access management for autonomous digital actors.

Vulnerabilities

Windows 10 ESU Support Extended

Microsoft has quietly extended its free Windows 10 Extended Security Updates program to October 12, 2027, giving users an additional year to upgrade to a newer operating system.

Vulnerabilities

MCP Specification Upgrade

The new MCP 2026-07-28 specification introduces a stateless protocol layer, bringing new security challenges and potential attack surfaces for enterprise-scale deployments.

Vulnerabilities

Akrites Open Source Security Project

The Linux Foundation's Akrites project establishes a shared Security Incident Response Team for coordinated discovery, patching, and public disclosure of OSS security defects.

Vulnerabilities

CVE-2026-50751: Patching is Not Enough

A recent emergency directive from CISA highlights the limitations of patching in preventing cyber attacks, as a vulnerability in Check Point's Remote Access VPN was exploited by a Qilin ransomware affiliate.

Vulnerabilities

Windows 11 Update KB5095093

Microsoft releases Windows 11 KB5095093 update with new Point-in-Time restore feature, fixing numerous bugs and improving system reliability.

Vulnerabilities

Agentic AI Security Risks

Agentic AI can make bad decisions confidently and quickly if given incomplete or inaccurate context, posing significant security risks.

Vulnerabilities

AIVEX Triage Model

AIVEX, a new triage model, aims to reduce supply chain threats by providing context to vulnerability remediation priority, addressing the limitations of traditional SBOM, VEX, and CVSS scores.

Vulnerabilities

Open-Source Security Challenges

The US government faces unique difficulties in protecting open-source software, with experts citing years of underinvestment and a lack of systematic vulnerability disclosure processes.

Vulnerabilities

Vulnerability Exploitation in Hours

The time between vulnerability disclosure and exploitation has decreased to just 8 hours, making it crucial for organizations to prove exploitability without relying on patches or public exploits.

Vulnerabilities

Scattered Spider Hackers Plead Guilty to TfL Breach

Two members of the Scattered Spider cybercrime group have pleaded guilty to hacking Transport for London, causing £29 million in financial damage.

Vulnerabilities

FortiBleed Campaign Targets FortiGate Devices

The FortiBleed campaign has targeted over 430,000 FortiGate devices worldwide, using custom sniffers to steal credentials and authentication secrets from compromised firewalls.

Vulnerabilities

CVE-2026-4020 Exploited in Gravity SMTP WordPress Plugin

Hackers are exploiting a medium-severity info disclosure bug in the Gravity SMTP WordPress plugin, affecting 100,000 sites and exposing sensitive information like API keys and credentials.

Vulnerabilities

iPhone BootROM Exploit

A new BootROM exploit called Usbliter8 affects millions of iPhones, allowing attackers to bypass Apple's SecureROM and execute arbitrary code with full system privileges.

Vulnerabilities

AutoGen Studio Flaw Enables Code Execution

A vulnerability chain dubbed AutoJack in Microsoft's AutoGen Studio allows attackers to execute arbitrary commands on a host system by visiting a malicious webpage.

Vulnerabilities

Klue OAuth Breach

Klue has confirmed a security incident where threat actors stole OAuth tokens to access customers' Salesforce environments, with the Icarus hackers claiming responsibility for the attack.

Vulnerabilities

Apple Patches Beats Eavesdropping Flaw

Apple released a firmware update for Beats Studio Buds, patching a critical vulnerability that allowed nearby attackers to listen via the microphone on unpaired devices.

Vulnerabilities

AI Agents: The Overlooked Identities

Most organizations don't treat AI agents as identities, despite their ability to access critical business services and create security risks, with 65% of organizations experiencing a security incident involving an AI agent in the past year.

Vulnerabilities

FortiBleed Leak: 74,000 Fortinet Credentials Exposed

CISA warns Fortinet users to secure devices after the FortiBleed leak exposed nearly 74,000 firewall and VPN credentials, which have been used by threat actors to target government and private-sector organizations worldwide.

Vulnerabilities

CISA Faces Cuts and Staffing Gaps

Sen. Mark Warner warns of widespread cuts and staffing gaps at the Cybersecurity and Infrastructure Security Agency, citing a dangerous underestimation of national threats.

Vulnerabilities

NGINX Vulnerabilities Patches Released

F5 has released out-of-band security updates to address multiple NGINX web server vulnerabilities, including two critical-severity flaws that could allow attackers to execute code on vulnerable systems.

Vulnerabilities

Klue OAuth Breach Linked to Icarus

Klue suffered an OAuth breach, enabling the Icarus threat actors to steal Salesforce CRM data from multiple organizations in an ongoing extortion campaign.

Vulnerabilities

FortiBleed Leak Exposes 73,000 Fortinet VPN Credentials

A data leak known as FortiBleed has exposed Fortinet and FortiGate VPN credentials for 73,932 devices worldwide, potentially allowing attackers to access internal networks.

Vulnerabilities

AI Model Security Risks

Researchers found dozens of security vulnerabilities in Anthropic's Claude Code, highlighting the challenges of securing AI models with rapid update cycles.

Vulnerabilities

CVE-2026-48558: SimpleHelp Bug Allows Rogue Remote Support Accounts

A critical vulnerability in SimpleHelp remote management software, tracked as CVE-2026-48558, allows unauthenticated attackers to create privileged technician accounts on servers using OpenID Connect authentication.

Vulnerabilities

OptinMonster WordPress Plugin Hacked

The OptinMonster WordPress plugin was compromised in a supply-chain attack, affecting over 1.2 million websites, with malicious scripts collecting authentication tokens and creating rogue administrator accounts.

Vulnerabilities

Fable 5 AI Model Restrictions

Cybersecurity experts disagree with the White House's decision to impose export controls on Anthropic's Fable 5 AI model, citing lack of evidence for unique threats.

Vulnerabilities

Maine Breach Portal Abused

Maine's official breach portal was used to publish fake data breach disclosures, including a false claim affecting 2.4 million VRChat users.

Vulnerabilities

CVE-2026-20245: Zero-Day Vulnerability in Cisco SD-WAN

Cisco's SD-WAN management software is affected by a seventh actively exploited zero-day vulnerability this year, marked as CVE-2026-20245, allowing authenticated attackers to execute commands as root.

Vulnerabilities

Microsoft Patches Record 200 Security Holes

Microsoft released updates to fix nearly 200 security vulnerabilities, including 32 critical bugs, with exploit code publicly available for at least three weaknesses.

Vulnerabilities

AI-driven Threats Expose MSP Security Limits

AI-driven threats are outpacing traditional security operations, with Gartner predicting a 50% reduction in exploit time by 2027, emphasizing the need for unified, AI-powered security stacks.

Vulnerabilities

US Cyber Force Proposal Narrowly Defeated

A proposal to establish a US Cyber Force as the country's latest military branch was narrowly defeated in the Senate Armed Services Committee with a 14-13 vote.

Vulnerabilities

Miasma Worm Source Code Leaked on GitHub

The Miasma credential-stealing attack framework's source code was briefly leaked on GitHub, potentially leading to increased supply-chain attacks on the open-source ecosystem.

Vulnerabilities

Microsoft's Record Patch Tuesday

Microsoft released fixes for over 200 security flaws, including one bug under active attack and a 'wormable' flaw in the Windows core.

Vulnerabilities

Windows Update Failures on Upgraded Devices

Microsoft warned that some Windows devices upgraded to Windows 11 24H2 or 25H2 may fail to install the latest monthly updates, showing 0x80073712 or 0x800f0993 errors.

Vulnerabilities

Microsoft Patch Tuesday June 2026

Microsoft addressed 206 vulnerabilities in its June 2026 Patch Tuesday update, marking the vendor's largest monthly batch of security patches on record.

Vulnerabilities

AI's Impact on Bug Bounty Industry

The rise of AI models like Anthropic's Claude Mythos threatens to disrupt the bug bounty and in-house offensive security industries, with potential to find thousands of zero-day vulnerabilities.

Vulnerabilities

OpenClaw AI Agent Vulnerable to Phishing Attacks

Researchers found that the OpenClaw AI agent can be tricked by phishing attacks, potentially exposing sensitive user data, including AWS credentials and customer records.

Vulnerabilities

NSO Group Defies Spyware Injunction

Meta accuses NSO Group of violating a court injunction by continuing to target WhatsApp users with spyware, despite a $168 million damages ruling.

Vulnerabilities

AI Architect: Secure AI-Built Apps

Atsign's AI Architect uses cryptographic invisibility to protect AI-built applications from vulnerabilities and attacks by securing identities and making them invisible to attackers.

Vulnerabilities

CISA Overhauls Cyber Vulnerability Assessment

CISA plans to transform how it assesses cyber vulnerabilities and risks, prioritizing some over others to be more effective in an environment where risks are spiking.

Vulnerabilities

Claude Mythos Exploit Creation

Claude Mythos Preview can build working exploits targeting known vulnerabilities within hours, increasing threats faced by organizations in the patch gap.

Vulnerabilities

Shai-Hulud Attack Compromises 19 PyPI Packages

A new Shai-Hulud supply-chain attack has trojanized 19 science-focused PyPI packages, compromising hundreds of thousands of downloads to steal developer secrets.

Vulnerabilities

Vibe Coding Security Risks

Vibe coding, a rapid AI-assisted development method, poses significant security risks as 45% of AI-generated code contains OWASP Top 10 vulnerabilities and many applications are deployed without security or authentication.

Vulnerabilities

Meta AI Support Hack Exposes 20,000 Instagram Accounts

Over 20,000 Instagram accounts were hijacked after attackers exploited a flaw in Meta's AI-powered support system to reset passwords without two-factor authentication.

Vulnerabilities

CVE: Exposed Gas Station Tank Gauge Systems

Over 900 US gas station tank gauge systems are exposed to attacks, vulnerable to security flaws including hardcoded credentials and SQL injection vulnerabilities.

Vulnerabilities

CVE-2026-3300: Critical Everest Forms Pro Flaw

Hackers are actively exploiting a critical vulnerability in the Everest Forms Pro plugin to take complete control of WordPress sites, creating rogue administrator accounts.

Vulnerabilities

CVE-2026-28318: SolarWinds Serv-U Flaw Exploited

Hackers are actively exploiting a high-severity SolarWinds Serv-U flaw, tracked as CVE-2026-28318, to crash servers, with over 12,000 Serv-U servers exposed online.

Vulnerabilities

CVE-free Polyfill Login Prompts

Toshiba and Muji warned visitors of suspicious sign-in screens on their websites, potentially collecting credentials, after an issue with the external service hosted at polyfill[.]io.

Vulnerabilities

CVE Lite CLI

CVE Lite CLI is a free, open-source command line tool that scans projects in seconds to find and fix vulnerable dependencies in JavaScript and Typescript files.

Vulnerabilities

Project Glasswing Expansion

Anthropic's Project Glasswing program has expanded to 150 organizations in 15 countries, discovering over 10,000 high-severity software vulnerabilities since its launch in April.

Vulnerabilities

Microsoft Vulnerability Disclosure Debate

A public dispute between Microsoft and a security researcher has reignited debate over vulnerability disclosure, with some experts arguing that the company's response was overly aggressive and harmed trust with the research community.

Vulnerabilities

Trump's AI Cybersecurity Order

President Trump has signed an executive order for federal vetting of advanced AI models before public release, aiming to balance innovation and security.

Vulnerabilities

CVE-2026-20245: Unpatched Cisco SD-WAN Zero-Day

Cisco warns of a high-severity, unpatched zero-day in the Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20245, actively exploited in attacks to gain root privilege escalation.

Vulnerabilities

CVE: Cyberattacks target fuel tank monitoring systems

CISA warns of cyberattacks targeting internet-exposed automatic tank gauge systems used to monitor fuel and liquid storage tanks across various critical infrastructure sectors.

Vulnerabilities

AI-Powered Cybersecurity

AI models are discovering vulnerabilities faster than teams can patch them, leaving organizations caught between speed of discovery and slowness of remediation.

Vulnerabilities

VS Code Zero-Day Exploited to Steal GitHub Tokens

A VS Code zero-day vulnerability allows attackers to steal GitHub authentication tokens by tricking users into clicking a link, with exploit code already released.

Vulnerabilities

AI Agent Security Risks

A recent study by Adversa AI found that 98% of 100 tested AI agents have a 'lethal trifecta' of private data access, exposure to untrusted content, and ability for outbound actions, making them vulnerable to security risks.

Vulnerabilities

HTTP/2 Bomb Exploit

The HTTP/2 Bomb exploit can knock major web servers offline in seconds by combining a compression bomb with a Slowloris-style hold, affecting over 880,000 websites.

Vulnerabilities

CVE Exposure: 345 Days of Untested Risk

A single VPN vulnerability led to data breaches at over 70 financial institutions, highlighting the risks of untested exposure in the banking sector.

Vulnerabilities

HTTP/2 Bomb DoS Attack

A new DoS attack, dubbed HTTP/2 Bomb, can crash web servers in under a minute by exploiting default HTTP/2 configurations, affecting major web servers like NGINX, Apache, and Microsoft IIS.

Vulnerabilities

Exchange Online Outage Causes Email Delays

Microsoft Exchange Online users are experiencing significant delays or failures in sending and receiving emails due to a widespread service issue.

Vulnerabilities

Red Hat Removes Tainted Packages After Supply Chain Compromise

Red Hat removed dozens of packages from its software distribution pipeline after attackers used a compromised GitHub account to distribute credential-stealing malware to developers, affecting 32 packages downloaded roughly 117,000 times a week.

Vulnerabilities

Meta's AI Support Bot Exploited to Hijack Instagram Accounts

Hackers used Meta's AI support bot to seize control of high-profile Instagram accounts, including those of the Obama White House and the Chief Master Sergeant of the U.S. Space Force.

Vulnerabilities

NIST Vulnerability Database Ineffective

The National Institute of Standards and Technology's National Vulnerability Database has a backlog of over 27,000 unprocessed security vulnerabilities, undermining its utility and public trust.

Vulnerabilities

Faster Vulnerability Alerts

New vulnerabilities increased by 67% between 2023 and 2025, with the median time to exploitation dropping to 1.6 days, highlighting the need for immediate vulnerability alerts.

Vulnerabilities

Red Hat npm Packages Compromised

Over 30 Red Hat npm packages were compromised to steal developer credentials in a supply-chain attack distributing the Miasma malware variant.

Vulnerabilities

CVE-2026-0257: Palo Alto Networks Authentication Bypass

Attackers are exploiting a critical authentication-bypass vulnerability in Palo Alto Networks firewalls, allowing remote attackers to bypass security restrictions and establish a VPN connection.

Vulnerabilities

CVE-2026-41089 Windows Netlogon RCE Exploited

Attackers are now exploiting the critical Windows Netlogon vulnerability CVE-2026-41089, allowing remote code execution on targeted domain controllers with a CVSS score of 9.8.

Vulnerabilities

CVE-2026-8732 Vulnerability in WP Maps Pro

A critical vulnerability in the WP Maps Pro plugin allows hackers to create rogue administrator accounts on WordPress sites without authentication.

Vulnerabilities

CVE-2026-0257: Palo Alto GlobalProtect VPN Auth Bypass

Hackers are exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, to breach corporate networks via unauthorized VPN connections.

Vulnerabilities

CVE: CIFSwitch Linux Flaw Gives Root Access

A newly discovered Linux flaw, dubbed CIFSwitch, allows attackers to gain root privileges on multiple distributions by exploiting a local privilege escalation vulnerability in the Linux kernel.

Vulnerabilities

CVE-2026-35616 Exploited to Deliver EKZ Infostealer

Hackers are exploiting a FortiClient EMS flaw to deliver an undocumented credential stealer called EKZ, disguised as a Fortinet endpoint update.

Vulnerabilities

Chrome Device Bound Session Credentials

Google Chrome's DBSC feature is now available to all users, preventing account takeovers by cryptographically binding session cookies to a specific device.

Vulnerabilities

Gogs Zero-Day Vulnerability Exposes Servers

A critical-severity zero-day vulnerability in Gogs exposes servers to remote code execution, allowing attackers to compromise the server and read every repository on the instance.

Vulnerabilities

Microsoft Condemns Zero-Day Releases

Microsoft has condemned the uncoordinated release of Windows zero-day vulnerabilities, calling them 'never justifiable' and warning of potential legal action against those who enable cybercrime.

Vulnerabilities

NIST's NVD Mismanagement Exposed

A Department of Commerce inspector general report found that the National Institute of Standards and Technology's National Vulnerability Database is plagued by poor planning, duplication, and inefficiencies, resulting in a growing backlog of unprocessed security flaws.

Vulnerabilities

AI Coding Agents Security

Edamame's new platform aims to catch AI coding agents going off the rails by detecting code drift and attack patterns in real-time.

Vulnerabilities

Zapier Bug Chain Patched

Security researchers discovered a bug chain in Zapier that could have granted access to millions of user accounts and connected systems, but the issues have been fixed.

Vulnerabilities

Active Directory Password Security

Enforce strong Active Directory password rules without frustrating users by adopting passphrases, blocking weak and compromised passwords, and rethinking password expirations.

Vulnerabilities

SymJack Attack Exploits AI Coding Agents

The SymJack attack turns AI coding agents into supply chain attack delivery systems by hijacking symlinks and injecting malicious code.

Vulnerabilities

Mythos Model Uncovers Over 10,000 Software Flaws

Anthropic's Mythos model has identified over 10,000 high- or critical-severity software vulnerabilities in its first month of operation, shifting the central problem in cybersecurity from discovery to verification and patching.

Vulnerabilities

Federal Cybersecurity Logging Rules Updated

The White House has updated rules for federal agencies to keep logs of significant cyber activities, aiming to cut back on red tape and focus on evolving cybersecurity risks.

Vulnerabilities

Microsoft Defender Automatic Endpoint Isolation

Microsoft Defender can now automatically isolate hacked endpoints to prevent lateral movement and reduce the risk of further impact.

Vulnerabilities

CVE-2026-9082: Critical Drupal SQL Injection Flaw

Drupal warns of exploitation attempts targeting a highly critical SQL injection vulnerability, tracked as CVE-2026-9082, affecting various Drupal versions using PostgreSQL.

Vulnerabilities

CVE-2026-26980 SQL injection flaw in Ghost CMS

A large-scale campaign is exploiting a critical SQL injection vulnerability in Ghost CMS to inject malicious JavaScript code, impacting over 700 domains.

Vulnerabilities

Mythos Model Detects 23,000 OSS Vulnerabilities

Anthropic's Claude Mythos model has identified over 23,000 potential vulnerabilities across 1,000 open source software projects, with nearly 3,900 critical and high-severity issues expected to be confirmed.

Vulnerabilities

Underminr Vulnerability

The Underminr vulnerability allows attackers to hide malicious connections behind trusted domains, potentially affecting 88 million domains worldwide.

Vulnerabilities

CVE-2026-34926: Trend Micro Apex One Zero-Day

Trend Micro warns of an Apex One zero-day vulnerability exploited in attacks targeting Windows systems, with federal agencies ordered to patch by June 4.

Vulnerabilities

UniFi OS Vulnerabilities Patched by Ubiquiti

Ubiquiti has released security updates to patch three maximum severity vulnerabilities in UniFi OS, which can be exploited by remote attackers without privileges.

Vulnerabilities

CVE-2024-9643 Exploited by Botnets

Attackers are exploiting CVE-2024-9643, an authentication bypass flaw in Four-Faith industrial routers, to compromise devices and fold them into botnets for further campaigns.

Vulnerabilities

CISA Expands Vulnerability Reporting

CISA has created a new pathway for researchers to report vulnerabilities to its Known Exploited Vulnerabilities catalog, enhancing its ability to identify and share critical threat information.

Vulnerabilities

Open-Source Vulnerabilities Concern CISA Chief

CISA acting director Nick Andersen warns of the risks posed by open-source vulnerabilities and the need for urgent security improvements to prevent widespread attacks.

Vulnerabilities

UK Cybercrime Law Reform Plans

The UK's proposed cybercrime law reform would offer limited legal protections, leaving most security researchers vulnerable to prosecution.

Vulnerabilities

GitHub Internal Repositories Compromised

GitHub's internal repositories were impacted after an employee device was compromised through a poisoned Visual Studio Code extension, with critical secrets rotated and the highest-impact credentials prioritized first.

Vulnerabilities

CISA Credential Leak Raises Alarms

A reported public exposure of sensitive CISA credential data on GitHub has raised concerns and prompted Congress to demand answers from the agency.

Vulnerabilities

Device Security Shares Load with Identity

Identity alone is no longer sufficient for cybersecurity, as device security must share the load to prevent attacks, with 44.7% of breaches involving stolen credentials.

Vulnerabilities

Microsoft Introduces Rampart and Clarity AI Tools

Microsoft released Rampart and Clarity, two new AI-powered tools to help developers design more secure software and assist incident responders in the face of ongoing breaches.

Vulnerabilities

CVE-2026-45585 Windows BitLocker Zero-Day

Microsoft has shared mitigations for the YellowKey Windows zero-day vulnerability, tracked as CVE-2026-45585, which grants access to protected drives.

Vulnerabilities

Microsoft Teams Location Prompts on macOS

Microsoft blames a recent macOS security update for non-dismissible location prompts in the Teams app on some macOS systems, affecting users who have enabled location access in their Teams settings.

Vulnerabilities

Microsoft Enhances Windows 11 Driver Quality

Microsoft is introducing the Driver Quality Initiative to improve Windows 11 driver quality, focusing on safer user-mode drivers and better Windows Update catalog hygiene.

Vulnerabilities

Huawei Zero-Day Attack Causes Nationwide Telecom Outage

A previously unknown vulnerability in Huawei enterprise router software was exploited in a zero-day attack, causing a nationwide telecoms outage in Luxembourg last year.

Vulnerabilities

Microsoft Disrupts Malware Signing Service

Microsoft has disrupted a malware-signing-as-a-service operation that abused its Artifact Signing platform to generate fraudulent code-signing certificates used by ransomware gangs and other cybercriminals.

Vulnerabilities

AI Models Boost Vulnerability Reports

New AI models like Anthropic's Mythos and OpenAI's Daybreak are generating a flood of vulnerability reports, but many are low-quality submissions without proof of concept.

Vulnerabilities

Windows MiniPlasma Zero-Day Exploit

A new Windows zero-day exploit dubbed 'MiniPlasma' gives attackers SYSTEM access on fully patched Windows systems, with a proof-of-concept released by researcher Chaotic Eclipse.

Vulnerabilities

Canvas Breach Highlights SaaS Security Risks

The Canvas breach exposed 3.65 terabytes of data from 275 million users, highlighting the need for robust SaaS security and identity governance.

Vulnerabilities

Microsoft Edge Updates Password Storage

Microsoft Edge will no longer load saved passwords into memory on startup, following a security researcher's disclosure of the browser's behavior.

Vulnerabilities

May 2026 Patch Tuesday Updates

Microsoft and other major software vendors released a record volume of security patches this month, addressing over 1,000 vulnerabilities, with 118 fixes from Microsoft alone.

Vulnerabilities

CVE-2026-20182: Cisco SD-WAN zero-day exploited

A max-severity zero-day vulnerability in Cisco Catalyst SD-WAN Controller and Manager is being exploited by a persistent threat group, with a CVSS rating of 10 and potential for high-impact operations.

Vulnerabilities

Azure Backup Vulnerability Report Rejected by Microsoft

Microsoft rejected a critical Azure vulnerability report, claiming the issue was expected behavior, despite the researcher documenting a silent patch.

Vulnerabilities

Avada Builder WordPress Plugin Vulnerabilities

Two vulnerabilities in the Avada Builder plugin allow hackers to read arbitrary files and extract sensitive information from the database, potentially leading to site credential theft.

🐛 Vulnerabilities

Microsoft Edge Password Risk

Microsoft Edge stores passwords in process memory, posing a significant risk to enterprise security, especially in shared environments.

Vulnerabilities

Mistral AI Code Repositories Stolen by TeamPCP Hackers

TeamPCP hackers are selling nearly 450 Mistral AI code repositories for $25,000 after a supply-chain attack compromised the company's codebase management system.

Vulnerabilities

Microsoft Introduces Automatic Driver Rollback

Microsoft is introducing Cloud-Initiated Driver Recovery, a feature that automatically rolls back faulty Windows drivers delivered through Windows Update.

Vulnerabilities

CVE pending: Funnel Builder WordPress plugin

A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce checkout pages, affecting over 40,000 websites.

Vulnerabilities

CVE-2026-20182: Critical SD-WAN Flaw Exploited in Zero-Day Attacks

A critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, is being exploited in zero-day attacks, allowing attackers to gain administrative privileges on compromised devices.

Vulnerabilities

NGINX Vulnerability Allows DoS and Potential RCE

An 18-year-old flaw in NGINX, tracked as CVE-2026-42945, can be exploited for denial of service and potential remote code execution under certain conditions.

Vulnerabilities

CVE-2023: TanStack npm Supply Chain Attack Impacts OpenAI

OpenAI is taking actions to protect users after a supply chain attack corrupted the signing keys used to verify the company's applications, with macOS users required to update by June 12.

Vulnerabilities

TanStack Supply Chain Attack

OpenAI confirms a security breach in the recent TanStack supply chain attack, which impacted hundreds of npm and PyPI packages, with two employees' devices breached and code-signing certificates rotated as a precaution.

Vulnerabilities

CVE-2026-44338 Exploited

Hackers targeted a PraisonAI vulnerability less than four hours after public disclosure, with exploitation attempts starting within three hours and 44 minutes.

Vulnerabilities

AI-Powered Vulnerability Detection

Microsoft and Palo Alto Networks used AI to discover dozens of vulnerabilities in their own code, highlighting the potential of AI in cybersecurity.

Vulnerabilities

CVE-2026-45185 Exim Mailer Flaw

A critical vulnerability in Exim mailer, identified as CVE-2026-45185, allows remote code execution on affected Linux and Unix servers.

Vulnerabilities

Sweet Security Launches AI Red Teaming

Sweet Security introduces Agentic AI Red Teaming to counter the 'Mythos Moment' with automated continuous red teaming built on detailed knowledge of each client's infrastructure.

Vulnerabilities

Windows 11 May 2026 Patch Tuesday

Microsoft has released Windows 11 KB5089549 and KB5087420 cumulative updates to fix security vulnerabilities and add new features, including an Xbox mode on desktop.

Vulnerabilities

Canvas Cyberattack: US Govt Seeks Instructure Testimony

The US House Committee on Homeland Security is investigating a massive breach at Instructure's Canvas platform, which impacted millions of students and educators.

Vulnerabilities

Google Introduces Intrusion Logging to Combat Spyware

Google has launched a feature for Android phones to make it harder for spyware vendors to hide, with a new intrusion logging feature that keeps track of possible intrusions for forensic purposes.

Vulnerabilities

Android 17 Security Updates

Android 17 will introduce several security and privacy features, including expanded protections against banking scam calls and device theft.

Vulnerabilities

Curl Vulnerability Found by Claude Mythos

A test of Anthropic's Claude Mythos model found only one low-severity vulnerability in the open source data transfer tool curl, casting doubt on the AI company's claims.

Vulnerabilities

AI-Generated Zero-Day Exploit Detected by Google

Google has identified a zero-day exploit believed to have been developed using artificial intelligence, designed to bypass two-factor authentication on an open source web-based system administration tool.

Vulnerabilities

AI-Generated Zero-Day Exploit Targets Web Admin Tool

Google researchers found a zero-day exploit likely generated using AI, targeting a popular open-source web administration tool to bypass two-factor authentication protection.

Vulnerabilities

Active Directory Breach

Changing passwords doesn't immediately invalidate old credentials across every authentication path in Active Directory and hybrid Entra ID environments, leaving a window for attackers to maintain access.

Vulnerabilities

CheckMarx Jenkins Plugin Compromised

A rogue version of the CheckMarx Jenkins Application Security Testing plugin was published on the Jenkins Marketplace, containing credential-stealing malware.

Vulnerabilities

Build App Firewalls

A build application firewall may be the solution to prevent supply chain attacks by inspecting each package that enters the build process.

Vulnerabilities

Trellix Source Code Breach Claimed by RansomHouse

RansomHouse hackers have claimed responsibility for a breach of Trellix's source code repository, leaking screenshots as proof of the intrusion.

Vulnerabilities

CVE-2026-6973 Zero-Day Vulnerability Exploited in Ivanti EPMM

Attackers are exploiting a zero-day vulnerability in Ivanti Endpoint Manager Mobile, with limited exploitation reported in the wild, requiring authenticated administrative access to implement.

Vulnerabilities

Browser-Based Data Loss

Modern DLP controls often lack visibility into browser-based data movement, with 46% of sensitive file uploads sent to unsanctioned accounts.

Vulnerabilities

Cybersecurity News Roundup

The US government proposes 72-hour patch cycles for critical vulnerabilities, while a new Linux backdoor called PamDOORa is being marketed on a Russian cybercrime forum.

Vulnerabilities

ShinyHunters Hack Canvas Login Portals

ShinyHunters extortion gang breached education technology giant Instructure, defacing Canvas login portals for hundreds of colleges and universities, threatening to leak stolen data if a ransom is not paid by May 12, 2026.

Vulnerabilities

CVE-2026-0300: Zero-Day Exploited in Palo Alto Networks Firewalls

Suspected state-sponsored hackers have been exploiting a critical-severity PAN-OS firewall zero-day vulnerability, tracked as CVE-2026-0300, for nearly a month, allowing unauthenticated attackers to execute arbitrary code with root privileges.

Vulnerabilities

CVE-2026-0300: Zero-Day Exploited in Palo Alto Networks Firewalls

A critical zero-day vulnerability, CVE-2026-0300, is being exploited in the wild, affecting some Palo Alto Networks' customers' firewalls, allowing unauthenticated attackers to run code with root privileges.

Vulnerabilities

CVE-2026-0300: Palo Alto Networks Firewall Zero-Day

Palo Alto Networks warns of a critical-severity unpatched vulnerability in the PAN-OS User-ID Authentication Portal, tracked as CVE-2026-0300, which is being exploited in attacks.

Vulnerabilities

Schemata API Flaw Exposed Military Data

A defense technology company exposed user records and military training materials through API endpoints lacking authorization checks, affecting hundreds of user records and sensitive course information.

Vulnerabilities

DAEMON Tools Breach Confirmed

DAEMON Tools devs confirm breach, release malware-free version after supply chain attack trojanized software, impacting thousands of systems worldwide.

Vulnerabilities

Australia Establishes Cyber Review Board

Australia has launched a Cyber Incident Review Board to conduct independent reviews of major cyberattacks, focusing on systemic lessons rather than individual culpability.

Vulnerabilities

CVE Blind Spot: EOL Software

Approximately 5.4 million end-of-life package versions are not being checked by security tools, leaving organizations vulnerable to exploits.

Vulnerabilities

Hacking AI Systems

Joey Melo, a Principal Security Researcher at CrowdStrike, discusses his approach to hacking AI systems, focusing on controlling the experience without changing the rules.

Vulnerabilities

Linux Vulnerability CVE-2026-31431 Exploited

Attackers are actively exploiting a Linux vulnerability, dubbed 'Copy Fail', which allows for total control of a system with authenticated local access, affecting mainstream Linux kernels built since 2017.

Vulnerabilities

Microsoft Defender Flags DigiCert Certs as Malware

Microsoft Defender has incorrectly identified legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha, leading to false-positive alerts and removal of certificates from Windows systems.

Vulnerabilities

April Windows Updates Cause Backup Failures

Microsoft confirms that the April 2026 security updates cause failures in third-party backup applications using the psmounterex.sys driver due to a VSS service timeout.

Vulnerabilities

AI Agents Exploit Identity Vulnerabilities

Anthropic's AI model Mythos discovered thousands of unknown software vulnerabilities, highlighting the risk of AI agents exploiting security flaws and impersonating humans.

Vulnerabilities

Brazilian Anti-DDoS Firm Linked to Attacks

A Brazilian tech firm specializing in DDoS protection has been linked to a botnet responsible for massive DDoS attacks against Brazilian ISPs, with evidence suggesting a security breach and potential competitor involvement.

Vulnerabilities

CVE-2026-41940: cPanel Authentication Bypass

A severe authentication bypass vulnerability in cPanel, tracked as CVE-2026-41940, is being actively exploited in the wild, affecting over 1.5 million instances.

Vulnerabilities

Windows 11 KB5083631 Update Released

Microsoft has released the KB5083631 optional cumulative update for Windows 11, including 34 changes and fixes, such as a new Xbox mode and improved security for batch files.

Vulnerabilities

ConsentFix v3 Targets Azure

ConsentFix v3 attacks automate OAuth abuse against Microsoft Azure, using social engineering and phishing to obtain tokens and hijack accounts despite multi-factor authentication.

Vulnerabilities

Cisco Model Provenance Kit

Cisco has released an open source tool, Model Provenance Kit, to help organizations address potential issues associated with the use of third-party AI models.

Vulnerabilities

Microsoft Fixes Remote Desktop Security Warnings Bug

Microsoft has fixed a bug causing Remote Desktop security warnings to display incorrectly on devices with multiple monitors and different display scaling settings.

Vulnerabilities

More Than 10,000 Zimbra Servers Remain Unpatched Amid Active XSS Exploitation

Over 10,500 Zimbra Collaboration Suite servers exposed to the internet are still unpatched against CVE-2025-48700, an actively exploited cross-site scripting flaw. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch within three days.

Vulnerabilities

CVE-2026-41651 'Pack2TheRoot' Flaw Grants Root Access on Linux via PackageKit

A newly disclosed vulnerability tracked as CVE-2026-41651, dubbed 'Pack2TheRoot,' allows local Linux users to gain root privileges through the PackageKit daemon. The high-severity flaw has existed for nearly 12 years and affects numerous popular distributions.

Vulnerabilities

BRIDGE:BREAK Flaws in Serial-to-IP Converters Put OT and Healthcare at Risk

Forescout Technologies has uncovered 20 new vulnerabilities in serial device servers from Silex and Lantronix, collectively dubbed BRIDGE:BREAK, enabling remote code execution, firmware tampering, and device takeovers in critical OT and healthcare environments.

Vulnerabilities

TP-Link Router Flaw Targeted for a Year, But Hackers Keep Failing to Pull It Off

Threat actors have spent over a year attempting to exploit CVE-2023-33538, a high-severity command injection flaw in discontinued TP-Link routers, but errors in their own exploit code have prevented any successful compromise, according to Palo Alto Networks.

Vulnerabilities

Apache ActiveMQ CVE-2026-34197 Now Actively Exploited Days After Disclosure

A critical Apache ActiveMQ Classic flaw tracked as CVE-2026-34197, dormant in the codebase for 13 years, is being actively exploited just weeks after patched versions were released. CISA has added it to the Known Exploited Vulnerabilities catalog with a federal patch deadline of April 30.

Vulnerabilities

Microsoft Edge Update Bug Disables Right-Click Paste in Teams Desktop Client

A code regression introduced by a recent Microsoft Edge update has left Teams desktop users unable to paste content via right-click context menus. Microsoft is rolling out a staged fix while recommending keyboard shortcuts as a workaround.

Vulnerabilities

Critical RCE Vulnerability in protobuf.js Allows JavaScript Code Injection

A critical remote code execution flaw tracked as GHSA-xq3m-2v4x-88gg has been discovered in protobuf.js, a JavaScript library pulling nearly 50 million weekly npm downloads. Proof-of-concept exploit code is now public, though no active in-the-wild attacks have been observed.

Vulnerabilities

Splunk Fixes High-Severity RCE Flaw in Enterprise and Cloud Platform

Splunk has released security fixes addressing a high-severity remote code execution vulnerability tracked as CVE-2026-20204 in Splunk Enterprise and Cloud Platform, along with several other flaws across its product lineup.

Vulnerabilities

NIST Narrows NVD Analysis Priorities as CVE Submissions Surge 263% Since 2020

Overwhelmed by a growing flood of vulnerabilities, NIST has announced it will limit in-depth CVE analysis to those in CISA's known exploited vulnerabilities catalog, federal government software, and critical software under Executive Order 14028.

Vulnerabilities

Eight Industrial Control System Vendors Release Security Advisories on Patch Tuesday

Siemens, Schneider Electric, Aveva, Rockwell Automation, ABB, Phoenix Contact, Mitsubishi Electric, and Moxa have all published new ICS security advisories, addressing vulnerabilities ranging from critical Wi-Fi flaws to privilege escalation and denial-of-service issues.

Vulnerabilities

Microsoft Rolls Out New Windows Defenses Against Weaponized RDP Files

Microsoft's April 2026 cumulative updates for Windows 10 and Windows 11 introduce new safeguards against phishing attacks that weaponize Remote Desktop Protocol (.rdp) files, including security warnings and disabled resource redirections by default.

Vulnerabilities

SAP's April 2026 Patch Day Tackles 9.9-Severity ABAP SQL Injection Flaw

SAP released 20 security notes on its April 2026 patch day, led by CVE-2026-27681, a critical 9.9-rated SQL injection vulnerability in Business Planning and Consolidation and Business Warehouse that enables arbitrary code execution.

Vulnerabilities

CVE-2026-5194: Critical wolfSSL Flaw Lets Attackers Pass Off Forged Certificates

A critical cryptographic validation bug in the widely deployed wolfSSL library allows improperly weak digests to be accepted during certificate verification, potentially letting attackers impersonate malicious servers. The flaw was patched in wolfSSL 5.9.1 on April 8, 2026.

Vulnerabilities

Adobe Issues Emergency Patch for Actively Exploited Acrobat and Reader Zero-Day

Adobe has pushed an out-of-band security update for Acrobat and Reader to address CVE-2026-34621, a zero-day vulnerability exploited in the wild since at least December that allows malicious PDFs to escape sandbox protections and execute arbitrary code.

Vulnerabilities

Microsoft's March 2026 Patch Tuesday: 77 Fixes, AI-Discovered CVE Among Highlights

Microsoft addressed 77 security vulnerabilities this Patch Tuesday, with no active zero-days but notable fixes including privilege escalation bugs, critical Office RCE flaws, and a first-of-its-kind CVE discovered by an autonomous AI penetration testing agent.

Vulnerabilities

Anthropic's Mythos AI Can Write Zero-Day Exploits — But Can It Be Kept Safe?

Anthropic unveiled Claude Mythos Preview on April 7, an LLM capable of finding and exploiting zero-days across major operating systems and browsers. The company's Project Glasswing initiative aims to keep the powerful model in defensive hands, but experts remain skeptical.

Vulnerabilities

Juniper Networks Releases Patches for Nearly 30 Junos OS Security Flaws

Juniper Networks has issued fixes for close to three dozen vulnerabilities across Junos OS and related products, including a critical 9.8-severity default password flaw that could hand attackers full control of affected devices.

🐛 Vulnerabilities

Critical WordPress Plugin Vulnerability Affects Millions of Sites

A critical SQL injection vulnerability discovered in a widely used WordPress plugin has put millions of websites at risk. Exploitation has been observed in the wild, and site administrators should take immediate action to patch or mitigate.