Tag: flaw
-
Adobe ColdFusion flaw CVE-2026-48282 now exploited in the wild
Attackers are exploiting the critical Adobe ColdFusion flaw CVE-2026-48282, which allows remote code execution on unpatched servers. Attackers have started exploiting CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion. The flaw is a path traversal issue that could result in arbitrary code execution without authentication. It affects ColdFusion 2025.9, 2023.20, and earlier versions, allowing remote attackers…
-
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
A use-after-free bug in Linux’s KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel that runs it.Dubbed ‘Januscape’ and tracked as CVE-2026-53359, the flaw sits in the shadow MMU code that KVM shares across both Intel and AMD. The public proof-of-concept panics the host; the…
-
JadePuffer: The First Complete LLM-Driven Ransomware Attack
An agentic threat actor successfully exploited a Langflow flaw to steal data from a production database server and encrypt other systems. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/jadepuffer-first-complete-llm-driven-ransomware-attack
-
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure
Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig.The vulnerability in question is CVE-2026-20896 (CVSS score: 9.8), a vulnerability that stems from the DevOps platform trusting the “X-WEBAUTH-USER” header from any source IP address, effectively allowing an unauthenticated internet client to get elevated…
-
Japanese teen arrested over cyberattack that disrupted anime streaming service
The unnamed student, who lives in a city near Tokyo, allegedly exploited a flaw in a subscription-based anime streaming platform to fraudulently cancel more than 46,000 user subscriptions. First seen on therecord.media Jump to article: therecord.media/japanese-teen-arrested-over-attack-disrupted-streaming-service
-
Opera GX Flaw Let Sites Auto-Install Mods to Steal Data
Opera GX flaw let sites automatically install mods to steal data from other pages, now patched First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/opera-gx-flaw-gx-mods-css/
-
Max severity Adobe ColdFusion flaw now exploited in attacks
Attackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, the Canadian Center for Cyber Security (CCCS) warned on Thursday. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/
-
Veeam Backup BinaryFormatter Flaw Enables Remote Code Execution
A newly discovered deserialization vulnerability, tracked as CVE-2026-44963, affects Veeam Backup & Replication. This vulnerability allows authenticated domain users to execute remote code on backup servers by exploiting weaknesses in the handling of BinaryFormatter. The issue, detailed by SecureLayer7 Labs, is part of a concerning trend of flaws in Veeam’s .NET Remoting attack surface, where…
-
Seven Bugs in FatFs Put IoT and Embedded Devices at Risk
runZero found 7 flaws in FatFs, a filesystem used in IoT and embedded devices. Bugs can cause memory corruption, crashes, or data leaks via crafted storage. Cybersecurity firm runZero has disclosed seven vulnerabilities in FatFs, a compact open-source library that lets embedded devices read and write FAT and exFAT formatted storage, the same formats used…
-
Critical fast-mcp-telegram Vulnerability Lets Attackers Access Telegram Session Without Token
A critical vulnerability in fast-mcp-telegram (CVE-2026-52830, GHSA-rxw2-pc8j-vxwm) allows attackers to access a Telegram MCP session over HTTP without a valid bearer token by abusing a path-traversal flaw in how session files are resolved on disk. This breaks the intended high-entropy token boundary and exposes the default Telegram account to full message and MTProto access. Critical…
-
Bad Epoll Flaw Gives Attackers Root Access on Linux and Android
Bad Epoll (CVE-2026-46242) lets local attackers gain root on Linux and Android. The flaw was missed by AI but found by a security researcher. A newly disclosed Linux kernel vulnerability, namedBad Epoll(CVE-2026-46242), allows a local attacker with no special privileges to gain full root access on affected Linux systems and Android devices. Security updates are…
-
PHP TLS Flaw Lets Remote Server Trigger DoS and Crash Entire FPM Process
A newly disclosed high-severity vulnerability in PHP, tracked as CVE-2026-12184, poses a significant risk to web applications by allowing a remotely triggerable denial-of-service (DoS) condition. This vulnerability can cause entire PHP-FPM process pools to crash. Details of the issue are outlined in the GitHub advisory GHSA-mhmq-mmqj-2v39. It affects multiple supported PHP branches, including versions before…
-
Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages
Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use it to lift specific data from the pages a victim visits.In a proof of concept, they reconstructed a signed-in user’s full Gmail address from a single visit, with no…
-
ModSecurity Security Flaws Enable WAF Rule Evasion With Crafted HTTP Requests
ModSecurity, a widely used open-source web application firewall (WAF), has multiple security vulnerabilities that allow attackers to bypass detection with specially crafted HTTP requests. These vulnerabilities, identified as CVE-2026-52761 and CVE-2026-52747, affect ModSecurity versions up to 3.0.15. They have been addressed in version 3.0.16. These issues reveal significant inconsistencies in input transformation and request parsing,…
-
Bad Epoll Linux Kernel UAF Flaw Lets Unprivileged Attackers Gain Root on Linux and Android
A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-46242 and dubbed “Bad Epoll,” exposes a critical race-condition use-after-free (UAF) flaw in the epoll subsystem that allows unprivileged users to escalate privileges to root across Linux systems and potentially Android devices. The flaw was discovered and exploited by security researcher Jaeyoung Chung as part of Google’s…
-
CISA adds SharePoint flaw to known exploited vulnerabilities list
First seen on scworld.com Jump to article: www.scworld.com/news/cisa-adds-sharepoint-flaw-to-known-exploited-vulnerabilities-list
-
Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attack
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Companies keep bolting AI onto their products, and the security bill is … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/05/week-in-review-simplehelp-vulnerability-exploited-oracle-ebs-payments-flaw-under-attack/
-
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
Security firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards.The flaws matter because FatFs is nearly everywhere. It ships inside the firmware that runs security cameras, drones, industrial controllers, hardware crypto wallets, and…
-
New “Bad Epoll” Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
A newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and Android, and a fix is out.Bad Epoll sits in the same small stretch of kernel code where Anthropic’s most powerful AI model, Mythos,…
-
AI Oversight, Security Flaws, and Industry Shifts Define This Week in Tech
See what you missed in Daily Tech Insider from June 29July 2. The post AI Oversight, Security Flaws, and Industry Shifts Define This Week in Tech appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/ai-oversight-security-flaws-and-industry-shifts-define-this-week-in-tech/
-
JADEPUFFER: First EndEnd AI-Driven Ransomware Operation
Sysdig reports an AI agent ran a full ransomware attack end-to-end, exploiting flaws, stealing creds, moving laterally, and encrypting data without humans. Sysdig’s Threat Research Team has documented what it assesses to be the first ransomware operation driven end-to-end by a large language model. The operator, which Sysdig calls JADEPUFFER, broke into a server, harvested…
-
ChatGPT Guardrail Bypass Vulnerability Exposes LFI Risk Through Download Flow
A now-patched guardrail bypass in ChatGPT that could be exploited through a Local File Inclusion (LFI) vulnerability via its file download mechanism. This incident underscores how logic flaws in large language model (LLM) workflows, particularly concerning temporary file handling and access controls, can create exploitable weaknesses, even in sandboxed environments. ChatGPT Guardrail Bypass Vulnerability The…
-
Claude Cowork Sandbox Flaw Lets Attackers Execute Commands as Root in Hyper-V VM
A newly disclosed sandbox escape technique in Anthropic’s Claude Cowork for Windows illustrates how attackers can achieve root-level command execution inside a Hyper-Visolated Ubuntu virtual machine (VM) by exploiting design vulnerabilities in CoworkVMService and its Remote Procedure Call (RPC) interface. This issue, documented by researcher Nick McClendon from Armadin, highlights weaknesses in the interaction between…
-
CitrixBleed Vulnerability Exploitation Within 24 Hours of Disclosure
Citrix NetScaler appliances are currently facing significant threats due to the rapid exploitation of a newly disclosed memory disclosure vulnerability, CVE-2026-8451, which is part of the evolving “CitrixBleed” class. This high-severity flaw (CVSS 8.8), disclosed on June 30, 2026, in Citrix advisory CTX696604, was observed being exploited in the wild within just 24 hours of…
-
Apple’s ‘Hide My Email’ Privacy Flaw Exposes Real Email Addresses
Researchers say Apple’s Hide My Email flaw may expose real addresses, despite two fixes. Here’s what users should know about the privacy risk. The post Apple’s ‘Hide My Email’ Privacy Flaw Exposes Real Email Addresses appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-apple-hide-my-email-privacy-flaw/
-
US cyber agency warns over forgotten SharePoint flaw
An RCE vulnerability in Microsoft SharePoint that was mistakenly omitted from the May Patch Tuesday bulletin is being exploited in the wild, says Cisa. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645307/US-cyber-agency-warns-over-forgotten-SharePoint-flaw
-
U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, microsoft, update, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Microsoft SharePoint Server flaw, tracked as CVE-2026-45659 (CVSS score v3.1 of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. At the end of May, Microsoft released security updates…
-
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories
This week’s security news is mostly about weak spots.Browsers, bots, sandboxes, AI systems, and email flows all show the same problem in different ways. Everything looks normal until someone tests a small gap and finds a way through.This is not one big break. It is small permissions, weak checks, open systems, and normal tools doing…
-
Cisco finally confirms attackers exploiting Unified CM flaw
Cisco confirmed that attackers are now exploiting a Unified Communications Manager (Unified CM) vulnerability patched in early June. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-finally-confirms-attackers-exploiting-unified-cm-flaw/
-
Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation
A new Sysdig report traces how an LLM agent abused a Langflow flaw, stole credentials, reached production MySQL, and destroyed Nacos config data in minutes flat. First seen on hackread.com Jump to article: hackread.com/sysdig-jadepuffer-first-agentic-ransomware-operation/

