Tag: flaw
-
CISA Warns of Actively Exploited iCagenda and Balbooa Forms File Upload Flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two file-upload vulnerabilities, affecting iCagenda and Balbooa Forms, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation in the wild. The alert was issued on July 10, 2026, identifying these flaws as vulnerabilities that allow unrestricted file uploads of dangerous types.…
-
Critical WordPress OAuth SSO Plugin Flaw Allows Unauthenticated Attackers to Gain Admin Access
A critical authentication bypass vulnerability has been disclosed in the widely used miniOrange OAuth Single Sign-On (SSO) WordPress plugin, carrying a near-maximum CVSS score of 9.8. This flaw, tracked as CVE-2026-57807, affects all plugin versions up to and including version 38.5.8. As of now, it remains unpatched, with no official fix available from the vendor.…
-
Australia Alerts Organizations to Ongoing CMS Exploitation Attacks
Australia warns of a global campaign exploiting CMS flaws to deploy webshells on WordPress, Joomla, and other websites. Australia’s Signals Directorate has issued an alert about a large-scale exploitation campaign actively targeting content management systems (CMS) worldwide, with many small and medium-sized Australian businesses already hit. Attackers are scanning websites for known vulnerabilities, deploying webshells…
-
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild.The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below – CVE-2026-48939 – A vulnerability in the First…
-
Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656)
Microsoft has finally released a security update for its Microsoft Malware Protection Engine, which fixes CVE-2026-50656, the Windows Defender local privilege escalation … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/09/microsoft-releases-fix-for-rogueplanet-defender-flaw-cve-2026-50656/
-
HP Linux Imaging and Printing Software Flaw Enables Privilege Escalation Attacks
A critical vulnerability has been discovered in HP Linux Imaging and Printing Software (HPLIP), which exposes Linux systems to potential privilege escalation and remote code execution attacks. This vulnerability, tracked as CVE-2026-14544, has a CVSS v3 score of 9.8, indicating maximum severity due to its potential for network exploitation, low attack complexity, and lack of…
-
GhostApproval Flaw Hits Six Major AI Coding Assistants
Wiz discovered GhostApproval, a symlink flaw in six major AI coding assistants that bypasses approval First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ghostapproval-flaw-ai-coding/
-
GhostApproval Flaws Let Top AI Coding Tools Write Outside Workspaces
Wiz found GhostApproval symlink flaws in major AI coding assistants that could hide sensitive file targets, bypass approval checks and enable system access too. First seen on hackread.com Jump to article: hackread.com/ghostapproval-flaws-ai-coding-tools-outside-workspace/
-
Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656)
Microsoft fixed RoguePlanet (CVE-2026-50656), a Defender flaw allowing local attackers to gain higher privileges through the Malware Protection Engine. Microsoft released security updates for RoguePlanet, a vulnerability tracked as CVE-2026-50656 (CVSS score of 7.8) affecting the Malware Protection Engine used by Defender. The Microsoft Malware Protection Engine (mpengine.dll) powers Defender’s malware scanning, detection, and removal…
-
GhostApproval Attack Impacts Amazon Q, Claude Code, Cursor, Google Antigravity, and Windsurf
A newly disclosed vulnerability pattern known as >>GhostApproval<< is exposing significant flaws in the trust boundary of leading AI coding assistants, including Amazon Q Developer, Anthropic Claude Code, Cursor, Google Antigravity, Augment, and Windsurf. This issue demonstrates how attackers can exploit symbolic links (symlinks) to bypass workspace isolation and manipulate Human-in-the-Loop safeguards, potentially resulting in…
-
Foxit Patches Multiple UseFree Flaws Leading to Remote Code Execution
Foxit has released critical security updates to address multiple use-after-free vulnerabilities that could lead to remote code execution (RCE) in its widely used PDF Reader and PDF Editor products. The vulnerabilities, disclosed in Foxit’s July 8, 2026 security bulletin, affect Windows versions of Foxit PDF Reader and Foxit PDF Editor across multiple release branches, highlighting…
-
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public.The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection Engine (“mpengine.dll”), which provides scanning, detection, and cleaning capabilities for its antivirus and First seen on…
-
Hidden Backdoor Found in Tenda Router Firmware
Unauthenticated Flaw Allows Full Router, Network Takeover. A hidden backdoor, disclosed by CERT/CC and found in multiple firmware versions made by Chinese manufacturer Tenda, bypasses authentication and could grant attackers administrative access. Researchers are reporting exploitation and an Nmap script is making vulnerable devices easier to identify. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hidden-backdoor-found-in-tenda-router-firmware-a-32181
-
Hidden Backdoor Found in Tenda Router Firmware
Unauthenticated Flaw Allows Full Router, Network Takeover. A hidden backdoor, disclosed by CERT/CC and found in multiple firmware versions made by Chinese manufacturer Tenda, bypasses authentication and could grant attackers administrative access. Researchers are reporting exploitation and an Nmap script is making vulnerable devices easier to identify. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hidden-backdoor-found-in-tenda-router-firmware-a-32181
-
GitLab Patches 8 Vulnerabilities Affecting CE and EE Installations
GitLab has released critical security updates to address eight vulnerabilities in its Community Edition (CE) and Enterprise Edition (EE). Administrators are urged to upgrade immediately to versions 19.1.2, 19.0.4, or 18.11.7. The patch rollout on July 8, 2026, includes fixes for high-, medium-, and low-severity flaws affecting core functionalities such as wiki rendering, repository mirroring,…
-
Google Chrome Update Patches 27 Security Vulnerabilities Including Critical UseFree Flaws
Google has released a critical security update for Chrome, upgrading the Stable channel to version 150.0.7871.114/.115 on Windows and macOS, and to version 150.0.7871.114 on Linux. This update addresses 27 vulnerabilities, including several critical use-after-free flaws that could potentially enable remote code execution. The update will roll out gradually over the coming days and weeks,…
-
CERT Warns of Unpatched Tenda Firmware Backdoor Allowing Admin Access
The CERT Coordination Center (CERT/CC) has disclosed a critical security issue affecting multiple Tenda networking devices. Tracked as CVE-2026-11405, the vulnerability stems from an undocumented backdoor in Tenda firmware that allows unauthenticated attackers to gain administrative access to a device’s web management interface. The flaw remains unpatched, prompting CERT to recommend immediate mitigation measures for…
-
Wireshark 4.6.7 patches a dozen security flaws
Network analysts who open packet captures in Wireshark push untrusted data through a large set of protocol dissectors, and each parser is a spot where a malformed frame can … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/09/wireshark-4-6-7-released/
-
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer’s computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead.The affected tools are Amazon Q Developer, Anthropic’s Claude Code, Augment, Cursor, Google…
-
Hidden Backdoor in Tenda Router Firmware
Unauthenticated Flaw Allows Full Router, Network Takeover. A hidden backdoor, disclosed by CERT/CC and found in multiple firmware versions made by Chinese manufacturer Tenda, bypasses authentication and could grant attackers administrative access. Researchers are reporting exploitation and an Nmap script is making vulnerable devices easier to identify. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hidden-backdoor-in-tenda-router-firmware-a-32181
-
Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation
Ubiquiti patched seven UniFi OS flaws, including critical CVE-2026-50746, which allows command injection in UniFi Connect Application. Ubiquiti released security updates for seven critical UniFi OS vulnerabilities, including a maximum-severity flaw, tracked as CVE-2026-50746 (CVSS score of 10.0), enabling command injection attacks. The issue affects UniFi Connect Application versions 3.4.16 and earlier, a platform used…
-
Hackers exploit Roundcube flaw to spy on academic researchers
A China-linked threat cluster has been exploiting vulnerable Roundcube servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-exploit-roundcube-flaw-to-spy-on-academic-researchers/
-
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command execution.The list of vulnerabilities is as follows – CVE-2026-50746 (CVSS score: 10.0) – An improper access control vulnerability in UniFi Connect Application that an…
-
Attackers using Langflow flaw for credential harvesting (CVE-2026-55255)
The US Cybersecurity and Infrastructure Security Agency (CISA) is warning about yet another Langflow vulnerability (CVE-2026-55255) leveraged by attackers in the wild. The … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/langflow-vulnerability-cve-2026-55255-exploited/
-
UNK_MassTraction Exploits Roundcube Flaws Against US, Canadian Universities
China-linked UNK_MassTraction targets US and Canadian universities through Roundcube flaws, stealing sessions and opening access to research mail servers. First seen on hackread.com Jump to article: hackread.com/unk-masstraction-roundcube-us-canada-universities/
-
CISA orders feds to prioritize patching Langflow auth bypass flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until Friday to patch an actively exploited vulnerability in the Langflow visual framework for building AI agents. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-orders-feds-to-prioritize-patching-langflow-auth-bypass-flaw/
-
U.S. CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities (KEV) catalog.…
-
Discord Confirms Bug That Incorrectly Banned 8,200 Users Since May 2026
Discord has confirmed a significant flaw in its automated moderation and enforcement pipeline that led to the wrongful banning of approximately 8,200 user accounts between May and early July 2026. This raises concerns about the reliability of AI-assisted trust and safety systems. The issue was disclosed via Discord’s official support channel on July 7 and…
-
CISA Deploys Anthropic’s Mythos AI to Hunt Vulnerabilities in U.S. Government Code
CISA is using Anthropic’s Mythos AI to scan federal code for vulnerabilities, aiming to find flaws before hackers and foreign intelligence services. Three sources familiar with the matter told Reuters that CISA, the U.S. government’s civilian cyber defense agency, is running Anthropic’s Mythos AI model against federal code repositories to find vulnerabilities before foreign intelligence…
-
Ubiquiti warns of new max severity UniFi OS vulnerability
Ubiquiti has released security updates to patch seven critical vulnerabilities in UniFi OS, including a maximum-severity flaw that can be exploited in command injection attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ubiquiti-warns-of-new-max-severity-unifi-os-vulnerability/

