Vulnerabilities

131 articles

🐛 Vulnerabilities

CISA Expands Vulnerability Reporting

CISA has created a new pathway for researchers to report vulnerabilities to its Known Exploited Vulnerabilities catalog, enhancing its ability to identify and share critical threat information.

🐛 Vulnerabilities

Open-Source Vulnerabilities Concern CISA Chief

CISA acting director Nick Andersen warns of the risks posed by open-source vulnerabilities and the need for urgent security improvements to prevent widespread attacks.

🐛 Vulnerabilities

Chromium Flaw Exposes Browsers to Remote Code Execution

Google accidentally leaked details of an unfixed Chromium flaw that allows remote code execution on devices, impacting all Chromium-based browsers.

🐛 Vulnerabilities

UK Cybercrime Law Reform Plans

The UK's proposed cybercrime law reform would offer limited legal protections, leaving most security researchers vulnerable to prosecution.

🐛 Vulnerabilities

GitHub Internal Repositories Compromised

GitHub's internal repositories were impacted after an employee device was compromised through a poisoned Visual Studio Code extension, with critical secrets rotated and the highest-impact credentials prioritized first.

🐛 Vulnerabilities

CISA Credential Leak Raises Alarms

A reported public exposure of sensitive CISA credential data on GitHub has raised concerns and prompted Congress to demand answers from the agency.

🐛 Vulnerabilities

Device Security Shares Load with Identity

Identity alone is no longer sufficient for cybersecurity, as device security must share the load to prevent attacks, with 44.7% of breaches involving stolen credentials.

🐛 Vulnerabilities

Microsoft Introduces Rampart and Clarity AI Tools

Microsoft released Rampart and Clarity, two new AI-powered tools to help developers design more secure software and assist incident responders in the face of ongoing breaches.

🐛 Vulnerabilities

CVE-2026-45585 Windows BitLocker Zero-Day

Microsoft has shared mitigations for the YellowKey Windows zero-day vulnerability, tracked as CVE-2026-45585, which grants access to protected drives.

🐛 Vulnerabilities

Microsoft Teams Location Prompts on macOS

Microsoft blames a recent macOS security update for non-dismissible location prompts in the Teams app on some macOS systems, affecting users who have enabled location access in their Teams settings.

🐛 Vulnerabilities

Microsoft Enhances Windows 11 Driver Quality

Microsoft is introducing the Driver Quality Initiative to improve Windows 11 driver quality, focusing on safer user-mode drivers and better Windows Update catalog hygiene.

🐛 Vulnerabilities

Huawei Zero-Day Attack Causes Nationwide Telecom Outage

A previously unknown vulnerability in Huawei enterprise router software was exploited in a zero-day attack, causing a nationwide telecoms outage in Luxembourg last year.

🐛 Vulnerabilities

Microsoft Disrupts Malware Signing Service

Microsoft has disrupted a malware-signing-as-a-service operation that abused its Artifact Signing platform to generate fraudulent code-signing certificates used by ransomware gangs and other cybercriminals.

🐛 Vulnerabilities

AI Models Boost Vulnerability Reports

New AI models like Anthropic's Mythos and OpenAI's Daybreak are generating a flood of vulnerability reports, but many are low-quality submissions without proof of concept.

🐛 Vulnerabilities

Windows MiniPlasma Zero-Day Exploit

A new Windows zero-day exploit dubbed 'MiniPlasma' gives attackers SYSTEM access on fully patched Windows systems, with a proof-of-concept released by researcher Chaotic Eclipse.

🐛 Vulnerabilities

Canvas Breach Highlights SaaS Security Risks

The Canvas breach exposed 3.65 terabytes of data from 275 million users, highlighting the need for robust SaaS security and identity governance.

🐛 Vulnerabilities

Microsoft Edge Updates Password Storage

Microsoft Edge will no longer load saved passwords into memory on startup, following a security researcher's disclosure of the browser's behavior.

🐛 Vulnerabilities

May 2026 Patch Tuesday Updates

Microsoft and other major software vendors released a record volume of security patches this month, addressing over 1,000 vulnerabilities, with 118 fixes from Microsoft alone.

🐛 Vulnerabilities

CVE-2026-20182: Cisco SD-WAN zero-day exploited

A max-severity zero-day vulnerability in Cisco Catalyst SD-WAN Controller and Manager is being exploited by a persistent threat group, with a CVSS rating of 10 and potential for high-impact operations.

🐛 Vulnerabilities

Azure Backup Vulnerability Report Rejected by Microsoft

Microsoft rejected a critical Azure vulnerability report, claiming the issue was expected behavior, despite the researcher documenting a silent patch.

🐛 Vulnerabilities

Avada Builder WordPress Plugin Vulnerabilities

Two vulnerabilities in the Avada Builder plugin allow hackers to read arbitrary files and extract sensitive information from the database, potentially leading to site credential theft.

🐛 Vulnerabilities

Microsoft Edge Password Risk

Microsoft Edge stores passwords in process memory, posing a significant risk to enterprise security, especially in shared environments.

🐛 Vulnerabilities

Mistral AI Code Repositories Stolen by TeamPCP Hackers

TeamPCP hackers are selling nearly 450 Mistral AI code repositories for $25,000 after a supply-chain attack compromised the company's codebase management system.

🐛 Vulnerabilities

Microsoft Introduces Automatic Driver Rollback

Microsoft is introducing Cloud-Initiated Driver Recovery, a feature that automatically rolls back faulty Windows drivers delivered through Windows Update.

🐛 Vulnerabilities

CVE pending: Funnel Builder WordPress plugin

A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce checkout pages, affecting over 40,000 websites.

Vulnerabilities

CVE-2026-20182: Critical SD-WAN Flaw Exploited in Zero-Day Attacks

A critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, is being exploited in zero-day attacks, allowing attackers to gain administrative privileges on compromised devices.

Vulnerabilities

NGINX Vulnerability Allows DoS and Potential RCE

An 18-year-old flaw in NGINX, tracked as CVE-2026-42945, can be exploited for denial of service and potential remote code execution under certain conditions.

Vulnerabilities

CVE-2023: TanStack npm Supply Chain Attack Impacts OpenAI

OpenAI is taking actions to protect users after a supply chain attack corrupted the signing keys used to verify the company's applications, with macOS users required to update by June 12.

Vulnerabilities

TanStack Supply Chain Attack

OpenAI confirms a security breach in the recent TanStack supply chain attack, which impacted hundreds of npm and PyPI packages, with two employees' devices breached and code-signing certificates rotated as a precaution.

Vulnerabilities

CVE-2026-44338 Exploited

Hackers targeted a PraisonAI vulnerability less than four hours after public disclosure, with exploitation attempts starting within three hours and 44 minutes.

Vulnerabilities

AI-Powered Vulnerability Detection

Microsoft and Palo Alto Networks used AI to discover dozens of vulnerabilities in their own code, highlighting the potential of AI in cybersecurity.

Vulnerabilities

CVE-2026-45185 Exim Mailer Flaw

A critical vulnerability in Exim mailer, identified as CVE-2026-45185, allows remote code execution on affected Linux and Unix servers.

Vulnerabilities

Sweet Security Launches AI Red Teaming

Sweet Security introduces Agentic AI Red Teaming to counter the 'Mythos Moment' with automated continuous red teaming built on detailed knowledge of each client's infrastructure.

Vulnerabilities

Windows 11 May 2026 Patch Tuesday

Microsoft has released Windows 11 KB5089549 and KB5087420 cumulative updates to fix security vulnerabilities and add new features, including an Xbox mode on desktop.

Vulnerabilities

Canvas Cyberattack: US Govt Seeks Instructure Testimony

The US House Committee on Homeland Security is investigating a massive breach at Instructure's Canvas platform, which impacted millions of students and educators.

Vulnerabilities

Google Introduces Intrusion Logging to Combat Spyware

Google has launched a feature for Android phones to make it harder for spyware vendors to hide, with a new intrusion logging feature that keeps track of possible intrusions for forensic purposes.

Vulnerabilities

Android 17 Security Updates

Android 17 will introduce several security and privacy features, including expanded protections against banking scam calls and device theft.

Vulnerabilities

Curl Vulnerability Found by Claude Mythos

A test of Anthropic's Claude Mythos model found only one low-severity vulnerability in the open source data transfer tool curl, casting doubt on the AI company's claims.

Vulnerabilities

AI-Generated Zero-Day Exploit Detected by Google

Google has identified a zero-day exploit believed to have been developed using artificial intelligence, designed to bypass two-factor authentication on an open source web-based system administration tool.

Vulnerabilities

AI-Generated Zero-Day Exploit Targets Web Admin Tool

Google researchers found a zero-day exploit likely generated using AI, targeting a popular open-source web administration tool to bypass two-factor authentication protection.

Vulnerabilities

Active Directory Breach

Changing passwords doesn't immediately invalidate old credentials across every authentication path in Active Directory and hybrid Entra ID environments, leaving a window for attackers to maintain access.

Vulnerabilities

CheckMarx Jenkins Plugin Compromised

A rogue version of the CheckMarx Jenkins Application Security Testing plugin was published on the Jenkins Marketplace, containing credential-stealing malware.

Vulnerabilities

Build App Firewalls

A build application firewall may be the solution to prevent supply chain attacks by inspecting each package that enters the build process.

Vulnerabilities

Trellix Source Code Breach Claimed by RansomHouse

RansomHouse hackers have claimed responsibility for a breach of Trellix's source code repository, leaking screenshots as proof of the intrusion.

Vulnerabilities

CVE-2026-6973 Zero-Day Vulnerability Exploited in Ivanti EPMM

Attackers are exploiting a zero-day vulnerability in Ivanti Endpoint Manager Mobile, with limited exploitation reported in the wild, requiring authenticated administrative access to implement.

Vulnerabilities

Browser-Based Data Loss

Modern DLP controls often lack visibility into browser-based data movement, with 46% of sensitive file uploads sent to unsanctioned accounts.

Vulnerabilities

Cybersecurity News Roundup

The US government proposes 72-hour patch cycles for critical vulnerabilities, while a new Linux backdoor called PamDOORa is being marketed on a Russian cybercrime forum.

Vulnerabilities

ShinyHunters Hack Canvas Login Portals

ShinyHunters extortion gang breached education technology giant Instructure, defacing Canvas login portals for hundreds of colleges and universities, threatening to leak stolen data if a ransom is not paid by May 12, 2026.

Vulnerabilities

CVE-2026-0300: Zero-Day Exploited in Palo Alto Networks Firewalls

Suspected state-sponsored hackers have been exploiting a critical-severity PAN-OS firewall zero-day vulnerability, tracked as CVE-2026-0300, for nearly a month, allowing unauthenticated attackers to execute arbitrary code with root privileges.

Vulnerabilities

CVE-2026-0300: Zero-Day Exploited in Palo Alto Networks Firewalls

A critical zero-day vulnerability, CVE-2026-0300, is being exploited in the wild, affecting some Palo Alto Networks' customers' firewalls, allowing unauthenticated attackers to run code with root privileges.

Vulnerabilities

CVE-2026-0300: Palo Alto Networks Firewall Zero-Day

Palo Alto Networks warns of a critical-severity unpatched vulnerability in the PAN-OS User-ID Authentication Portal, tracked as CVE-2026-0300, which is being exploited in attacks.

Vulnerabilities

Schemata API Flaw Exposed Military Data

A defense technology company exposed user records and military training materials through API endpoints lacking authorization checks, affecting hundreds of user records and sensitive course information.

Vulnerabilities

DAEMON Tools Breach Confirmed

DAEMON Tools devs confirm breach, release malware-free version after supply chain attack trojanized software, impacting thousands of systems worldwide.

Vulnerabilities

Australia Establishes Cyber Review Board

Australia has launched a Cyber Incident Review Board to conduct independent reviews of major cyberattacks, focusing on systemic lessons rather than individual culpability.

Vulnerabilities

CVE Blind Spot: EOL Software

Approximately 5.4 million end-of-life package versions are not being checked by security tools, leaving organizations vulnerable to exploits.

Vulnerabilities

Hacking AI Systems

Joey Melo, a Principal Security Researcher at CrowdStrike, discusses his approach to hacking AI systems, focusing on controlling the experience without changing the rules.

Vulnerabilities

Linux Vulnerability CVE-2026-31431 Exploited

Attackers are actively exploiting a Linux vulnerability, dubbed 'Copy Fail', which allows for total control of a system with authenticated local access, affecting mainstream Linux kernels built since 2017.

Vulnerabilities

Microsoft Defender Flags DigiCert Certs as Malware

Microsoft Defender has incorrectly identified legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha, leading to false-positive alerts and removal of certificates from Windows systems.

Vulnerabilities

April Windows Updates Cause Backup Failures

Microsoft confirms that the April 2026 security updates cause failures in third-party backup applications using the psmounterex.sys driver due to a VSS service timeout.

Vulnerabilities

AI Agents Exploit Identity Vulnerabilities

Anthropic's AI model Mythos discovered thousands of unknown software vulnerabilities, highlighting the risk of AI agents exploiting security flaws and impersonating humans.

Vulnerabilities

Brazilian Anti-DDoS Firm Linked to Attacks

A Brazilian tech firm specializing in DDoS protection has been linked to a botnet responsible for massive DDoS attacks against Brazilian ISPs, with evidence suggesting a security breach and potential competitor involvement.

Vulnerabilities

CVE-2026-41940: cPanel Authentication Bypass

A severe authentication bypass vulnerability in cPanel, tracked as CVE-2026-41940, is being actively exploited in the wild, affecting over 1.5 million instances.

Vulnerabilities

Windows 11 KB5083631 Update Released

Microsoft has released the KB5083631 optional cumulative update for Windows 11, including 34 changes and fixes, such as a new Xbox mode and improved security for batch files.

Vulnerabilities

ConsentFix v3 Targets Azure

ConsentFix v3 attacks automate OAuth abuse against Microsoft Azure, using social engineering and phishing to obtain tokens and hijack accounts despite multi-factor authentication.

Vulnerabilities

Cisco Model Provenance Kit

Cisco has released an open source tool, Model Provenance Kit, to help organizations address potential issues associated with the use of third-party AI models.

Vulnerabilities

Microsoft Fixes Remote Desktop Security Warnings Bug

Microsoft has fixed a bug causing Remote Desktop security warnings to display incorrectly on devices with multiple monitors and different display scaling settings.

Vulnerabilities

More Than 10,000 Zimbra Servers Remain Unpatched Amid Active XSS Exploitation

Over 10,500 Zimbra Collaboration Suite servers exposed to the internet are still unpatched against CVE-2025-48700, an actively exploited cross-site scripting flaw. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch within three days.

Vulnerabilities

CVE-2026-41651 'Pack2TheRoot' Flaw Grants Root Access on Linux via PackageKit

A newly disclosed vulnerability tracked as CVE-2026-41651, dubbed 'Pack2TheRoot,' allows local Linux users to gain root privileges through the PackageKit daemon. The high-severity flaw has existed for nearly 12 years and affects numerous popular distributions.

Vulnerabilities

BRIDGE:BREAK Flaws in Serial-to-IP Converters Put OT and Healthcare at Risk

Forescout Technologies has uncovered 20 new vulnerabilities in serial device servers from Silex and Lantronix, collectively dubbed BRIDGE:BREAK, enabling remote code execution, firmware tampering, and device takeovers in critical OT and healthcare environments.

Vulnerabilities

TP-Link Router Flaw Targeted for a Year, But Hackers Keep Failing to Pull It Off

Threat actors have spent over a year attempting to exploit CVE-2023-33538, a high-severity command injection flaw in discontinued TP-Link routers, but errors in their own exploit code have prevented any successful compromise, according to Palo Alto Networks.

Vulnerabilities

Apache ActiveMQ CVE-2026-34197 Now Actively Exploited Days After Disclosure

A critical Apache ActiveMQ Classic flaw tracked as CVE-2026-34197, dormant in the codebase for 13 years, is being actively exploited just weeks after patched versions were released. CISA has added it to the Known Exploited Vulnerabilities catalog with a federal patch deadline of April 30.

Vulnerabilities

Microsoft Edge Update Bug Disables Right-Click Paste in Teams Desktop Client

A code regression introduced by a recent Microsoft Edge update has left Teams desktop users unable to paste content via right-click context menus. Microsoft is rolling out a staged fix while recommending keyboard shortcuts as a workaround.

Vulnerabilities

Critical RCE Vulnerability in protobuf.js Allows JavaScript Code Injection

A critical remote code execution flaw tracked as GHSA-xq3m-2v4x-88gg has been discovered in protobuf.js, a JavaScript library pulling nearly 50 million weekly npm downloads. Proof-of-concept exploit code is now public, though no active in-the-wild attacks have been observed.

Vulnerabilities

Splunk Fixes High-Severity RCE Flaw in Enterprise and Cloud Platform

Splunk has released security fixes addressing a high-severity remote code execution vulnerability tracked as CVE-2026-20204 in Splunk Enterprise and Cloud Platform, along with several other flaws across its product lineup.

Vulnerabilities

NIST Narrows NVD Analysis Priorities as CVE Submissions Surge 263% Since 2020

Overwhelmed by a growing flood of vulnerabilities, NIST has announced it will limit in-depth CVE analysis to those in CISA's known exploited vulnerabilities catalog, federal government software, and critical software under Executive Order 14028.

Vulnerabilities

Eight Industrial Control System Vendors Release Security Advisories on Patch Tuesday

Siemens, Schneider Electric, Aveva, Rockwell Automation, ABB, Phoenix Contact, Mitsubishi Electric, and Moxa have all published new ICS security advisories, addressing vulnerabilities ranging from critical Wi-Fi flaws to privilege escalation and denial-of-service issues.

Vulnerabilities

Microsoft Rolls Out New Windows Defenses Against Weaponized RDP Files

Microsoft's April 2026 cumulative updates for Windows 10 and Windows 11 introduce new safeguards against phishing attacks that weaponize Remote Desktop Protocol (.rdp) files, including security warnings and disabled resource redirections by default.

Vulnerabilities

SAP's April 2026 Patch Day Tackles 9.9-Severity ABAP SQL Injection Flaw

SAP released 20 security notes on its April 2026 patch day, led by CVE-2026-27681, a critical 9.9-rated SQL injection vulnerability in Business Planning and Consolidation and Business Warehouse that enables arbitrary code execution.

Vulnerabilities

CVE-2026-5194: Critical wolfSSL Flaw Lets Attackers Pass Off Forged Certificates

A critical cryptographic validation bug in the widely deployed wolfSSL library allows improperly weak digests to be accepted during certificate verification, potentially letting attackers impersonate malicious servers. The flaw was patched in wolfSSL 5.9.1 on April 8, 2026.

Vulnerabilities

Adobe Issues Emergency Patch for Actively Exploited Acrobat and Reader Zero-Day

Adobe has pushed an out-of-band security update for Acrobat and Reader to address CVE-2026-34621, a zero-day vulnerability exploited in the wild since at least December that allows malicious PDFs to escape sandbox protections and execute arbitrary code.

Vulnerabilities

Microsoft's March 2026 Patch Tuesday: 77 Fixes, AI-Discovered CVE Among Highlights

Microsoft addressed 77 security vulnerabilities this Patch Tuesday, with no active zero-days but notable fixes including privilege escalation bugs, critical Office RCE flaws, and a first-of-its-kind CVE discovered by an autonomous AI penetration testing agent.

Vulnerabilities

Anthropic's Mythos AI Can Write Zero-Day Exploits — But Can It Be Kept Safe?

Anthropic unveiled Claude Mythos Preview on April 7, an LLM capable of finding and exploiting zero-days across major operating systems and browsers. The company's Project Glasswing initiative aims to keep the powerful model in defensive hands, but experts remain skeptical.

Vulnerabilities

Juniper Networks Releases Patches for Nearly 30 Junos OS Security Flaws

Juniper Networks has issued fixes for close to three dozen vulnerabilities across Junos OS and related products, including a critical 9.8-severity default password flaw that could hand attackers full control of affected devices.

🐛 Vulnerabilities

Critical WordPress Plugin Vulnerability Affects Millions of Sites

A critical SQL injection vulnerability discovered in a widely used WordPress plugin has put millions of websites at risk. Exploitation has been observed in the wild, and site administrators should take immediate action to patch or mitigate.