Tag: flaw
-
CISA orders feds to patch actively exploited Oracle flaw by Saturday
CISA has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite financial application. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-oracle-flaw-by-saturday/
-
Critical Zoom Workplace Flaw Lets Unauthenticated Attackers Take Over Accounts Remotely
Zoom has disclosed a critical vulnerability in its Windows desktop software that could allow unauthenticated attackers to take over user accounts remotely. This issue, tracked as CVE-2026-53412 and addressed in bulletin ZSB-26014, arises from improper input validation in Zoom Workplace for Windows and the Zoom Workplace VDI Client for Windows. The vulnerability has a CVSS…
-
Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide
Pull the certificate off the flash of a Shark RV2320EDUS robot vacuum, and you can run root commands on other people’s Shark vacuums across the same AWS region: watch the camera, drive the robot, read the map of the house, and take the Wi-Fi password in plaintext.A researcher publishing under the handle tokay0 put the…
-
CISA Warns of Actively Exploited Oracle E-Business Suite Flaw
Tags: business, cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, kev, oracle, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that attackers are actively exploiting CVE-2026-46817, an improper privilege management vulnerability in Oracle E-Business Suite that can lead to a takeover of Oracle Payments. The agency added the issue to its Known Exploited Vulnerabilities Catalog on July 15, 2026, and directed affected federal civilian executive…
-
Zoom Fixes CVE-2026-53412, a Critical Account Takeover Bug
Zoom warns of a critical Windows flaw, tracked as CVE-2026-53412, that could let attackers take over accounts without authentication. Zoom has fixed a critical Windows vulnerability, tracked as CVE-2026-53412 (CVSS score of 9.8) that could allow unauthenticated attackers to hijack user accounts. The flaw affects older versions of Workplace, the Windows VDI Client, and the…
-
Chaotic July Patch Tuesday threatens to overwhelm defenders
Another mammoth Patch Tuesday update, likely topping 600 flaws in total, sends defenders into the weeds. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645974/Chaotic-July-Patch-Tuesday-threatens-to-overwhelm-defenders
-
Splunk Enterprise Flaws Expose Stored Credentials and Allow Arbitrary SPL Searches
Splunk has released security updates for three vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. These vulnerabilities could potentially expose stored credential hashes, enable arbitrary Search Processing Language (SPL) searches, and allow files to be written outside of the intended application directory. The flaws, tracked as CVE-2026-20296, CVE-2026-20297, and CVE-2026-20298, were disclosed on July 15,…
-
Critical JetBrains Flaws Impact IntelliJ IDEA, TeamCity, and YouTrack Users
JetBrains has released security updates for IntelliJ IDEA, TeamCity, and YouTrack that address six vulnerabilities, including a critical path traversal issue that could enable code execution in IntelliJ IDEA. The fixes affect core developer tooling, CI/CD infrastructure, and issue-tracking environments, making prompt patching important for organizations that use JetBrains products in software development workflows. The…
-
Zoom Patches Critical Windows Flaw That Could Enable Account Takeover
Zoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover.The vulnerability, tracked as CVE-2026-53412 (CVSS score: 9.8), affects Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows.”Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client…
-
US Launches Gold Eagle to Coordinate AI-Driven Vulnerability Management
The White House announced Gold Eagle to help accelerate the discovery, prioritization and patching of flaws found by AI First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/us-gold-eagle-ai-vulnerability/
-
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP.The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9), an out-of-bounds write flaw that allows an authenticated attacker to leverage logical errors in memory management to cause a memory…
-
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Calendar.Both this and ClaudeBleed need a rogue extension that can already run a script on claude.ai; the difference is scope. Anthropic restricted the arbitrary-prompt…
-
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
Today is Microsoft’s July 2026 Patch Tuesday, and with it comes security updates for a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/
-
Iran abused mobile networks’ vulnerabilities to locate US military in the Middle East, report says
The Iranian government exploited well-known flaws in cellphone networks to locate and then strike U.S. military personnel in the build-up and beginning of the war. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/14/iran-abused-mobile-networks-vulnerabilities-to-locate-u-s-military-in-the-middle-east-report-says/
-
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown
Progress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers last week and has released security updates to patch the flaw. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/
-
Iran abused mobile networks’ vulnerabilities to locate U.S. military in the Middle East, report says
The Iranian government exploited well-known flaws in cellphone networks to locate and then strike U.S. military personnel in the build-up and beginning of the war. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/14/iran-abused-mobile-networks-vulnerabilities-to-locate-u-s-military-in-the-middle-east-report-says/
-
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries.Miggo’s security team, which discovered and reported the flaws, said one “leaks the broker’s confidential OAuth First seen on thehackernews.com…
-
SAP warns of critical flaws in NetWeaver and Commerce Cloud
SAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sap-warns-of-critical-flaws-in-netweaver-and-commerce-cloud/
-
CISA Adds Cisco IOS CSRF Flaw Enabling Arbitrary Command Execution to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2008-4128, a cross-site request forgery (CSRF) vulnerability affecting Cisco IOS, to its Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability was officially listed on July 13, 2026, with a remediation deadline of July 16, 2026, for Federal Civilian Executive Branch agencies. Although this vulnerability dates back…
-
WinFsp Race Condition Flaw Allows Attackers to Gain SYSTEM-Level Access on Windows
A newly disclosed vulnerability in the Windows File System Proxy (WinFsp) could allow a local attacker to gain SYSTEM-level privileges by exploiting a race condition that triggers a kernel heap overflow. Tracked as CVE-2026-3006, this vulnerability affects WinFsp versions 2.1.25156 and earlier, according to an advisory published by the Cyber Security Agency of Singapore (CSA)…
-
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it.In…
-
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it.In…
-
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it.In…
-
RabbitMQ Vulnerability Exposes OAuth Secrets to Attackers
A newly disclosed RabbitMQ vulnerability, tracked as CVE-2026-5721, has raised concerns among enterprise users after researchers revealed that the flaw could allow unauthenticated attackers to retrieve a broker’s confidential OAuth client secret. The successful exploitation could enable attackers to impersonate the broker, obtain administrator-level access, and potentially take control of the messaging infrastructure. First seen…
-
Critical ServiceNow AI Platform Flaw Allows Unauthenticated Attackers to Escape Sandbox and Execute Remote Code
ServiceNow has released security updates to address a critical remote code execution vulnerability in its AI Platform. This vulnerability, tracked as CVE-2026-6875, could allow unauthenticated attackers to execute code within affected ServiceNow environments. The issue is described as a sandbox-escape flaw affecting the ServiceNow AI Platform. Critical ServiceNow AI Platform Flaw According to ServiceNow advisory…
-
U.S. CISA adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cisco, cve, cybersecurity, exploit, flaw, infrastructure, kev, router, service, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco IOS flaw, tracked as CVE-2008-4128, to its Known Exploited Vulnerabilities (KEV) catalog. Cisco IOS 12.4 running on Cisco 871 Integrated Services Routers contains multiple CSRF flaws in…
-
CISA warns of actively exploited RCE flaws in Joomla extensions
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through arbitrary file uploads. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-warns-of-actively-exploited-rce-flaws-in-joomla-extensions/
-
Progress Urges ShareFile Shutdown Over ‘Credible’ Threat
Honeypot Records Exploitation Attempt Against Flaw Patched Earlier This Year. Progress Software has issued a security alert to all organizations using self-managed instances of ShareFile Storage Zone Controller, advising them to immediately power down their servers in light of a credible external security threat to their data. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/progress-urges-sharefile-shutdown-over-credible-threat-a-32210
-
Hackers Can Exploit RabbitMQ OAuth Flaw to Access Every Message, Queue, and User
Security researchers have disclosed two access-control vulnerabilities in RabbitMQ, the open-source message broker used in an estimated 8% of all containers running today, that could allow attackers to seize full administrative control of a broker or silently map out sensitive queue data across shared tenants. Both flaws were discovered by Miggo Security’s autonomous research system,…
-
CISA Warns of Actively Exploited Joomla Zero-Day Vulnerabilities
Tags: attack, cisa, cvss, cybersecurity, exploit, flaw, infrastructure, kev, malicious, vulnerability, zero-dayThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities (KEV) catalog after reports confirmed active zero-day attacks targeting the iCagenda and Balbooa extensions for Joomla. Both flaws carry the maximum CVSS severity score of 10.0 and can allow attackers to upload malicious files that ultimately lead to remote code execution. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cisa-cve-2026-48939-cve-2026-56291/

