Tag: update
-
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data.The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of…
-
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
IntroductionIn July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. C2Looper supports backdoor commands including executing arbitrary commands, performing reconnaissance,…
-
Microsoft releases Windows 10 KB5120249 extended security update
Microsoft has released Windows 10 KB5120249 Extended Security Updates for versions 22H2 and 21H2 to fix security vulnerabilities and bugs. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-10-kb5120249-cumulative-update-released-with-fixes/
-
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Today is Microsoft’s August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-days/
-
Windows 11 KB5121003 & KB5120240 cumulative updates released
Microsoft has released Windows 11 KB5121003 and KB5120240 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-11-kb5121003-and-kb5120240-cumulative-updates-released/
-
Mozilla updates GPG signing key for Firefox releases after exposure
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/mozilla-updates-gpg-key-for-signing-firefox-thunderbird-releases-after-exposure/
-
Datenschutz im digitalen Marketing – Bringt das Google Consent Update Datenkontrolle oder neue Risiken?
First seen on security-insider.de Jump to article: www.security-insider.de/google-consent-update-datenkontrolle-risiken-a-a479b7d613c46cf31a55b9238daf2ec4/
-
CISA Urges Organizations to Patch Exposed VPNs and Segment Networks Against Gunra Ransomware
Tags: advisory, breach, cisa, credentials, cyber, data, data-breach, encryption, exploit, firewall, infrastructure, international, law, network, organized, ransomware, service, theft, update, vpnCISA and international law-enforcement partners have issued a joint #StopRansomware advisory warning that Gunra ransomware affiliates are exploiting exposed edge infrastructure, including VPN gateways, firewall appliances and RDP-accessible systems, to breach enterprise networks. The advisory positions Gunra as an increasingly organized ransomware-as-a-service operation whose affiliates combine data theft, credential compromise and rapid encryption to pressure…
-
The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists
It’s time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/patch-gap-defenders-chains-not-checklists
-
Weitere Schwachstelle ausgenutzt – Hacker können sich Superuser-Rechte in IBM Langflow verschaffen
First seen on security-insider.de Jump to article: www.security-insider.de/ibm-langflow-oss-kritische-schwachstelle-update-1-10-1-a-c146e1daa10105f960b3a7a824cbbe8a/
-
Metabase 0-Day Flaw Exploited in Attack to Inject Arbitrary SQL and Steal Database Credentials
Tags: attack, cloud, credentials, cyber, endpoint, exploit, flaw, security-incident, sql, update, vulnerability, zero-dayMetabase has reported a critical security incident involving a zero-day vulnerability that is actively being exploited. This vulnerability affects self-hosted deployments running version 1.58 and later. According to the company, an attacker exploited this previously unknown flaw to target Metabase Cloud before the vulnerable endpoints were blocked and a patch was developed. Customers using Metabase…
-
Urlaubszeit Sommerzeit Vorfallzeit: Sechs Ratschläge für Zeiten mit geringer Personalstärke
Management Summary Urlaubszeit ist Risikobetrieb: Reduzierte Personalstärke, höhere Abhängigkeit von IT-Systemen und wachsende Angriffsflächen machen die Sommermonate zu einer Phase mit erhöhtem Kontrollbedarf. KI verändert das Schwachstellenmanagement: Frontier-KI-Modelle beschleunigen die Entdeckung und Veröffentlichung von Verwundbarkeiten; Patch-, CERT- und Threat-Feed-Prozesse müssen deshalb auch in Ferienzeiten aktiv bleiben. Klare Rollen verhindern Wissensmonopole: Ein offiziell definierter Reduced Staff……
-
Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Mapping the malware blast radius a single alert won’t show you In this … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/09/week-in-review-cisco-fixes-imc-bug-patch-tuesday-forecast-black-hat-usa-2026/
-
Critical macOS RCE Vulnerability Allows Attackers to Gain Root Access Without Password
Tags: access, apple, cve, cyber, data-breach, flaw, macOS, password, rce, remote-code-execution, update, vulnerabilityApple has shipped emergency macOS updates to close a critical vulnerability in Screen Sharing, tracked as CVE-2026-65400, which allows unauthenticated remote attackers to execute arbitrary code and access files with root-level privileges. The flaw is especially severe on systems where Screen Sharing is exposed to the public internet. Apple’s August 6 releases macOS Tahoe 26.6.1,…
-
Samsung’s August Update Patches 56 Security Vulnerabilities Across Galaxy Devices
Samsung’s August 2026 Galaxy update fixes 56 Android and One UI security flaws, including critical vulnerabilities and clipboard access risks. The post Samsung’s August Update Patches 56 Security Vulnerabilities Across Galaxy Devices appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-samsung-august-2026-security-update/
-
More than half of AI-generated patches are broken
Research finds your AI generated security patch is more likely to fail than fully fix a vulnerability. It might even introduce brand new flaws to exploit along the way. First seen on cyberscoop.com Jump to article: cyberscoop.com/ai-code-patching-security-risks/
-
WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover
WordPress XSS2Shell flaw enables admin takeover and remote code execution. Users should update to patched versions. Researchers at Pwn just published a report on a vulnerability chain they’re calling XSS2Shell, and the entry point is quite simple: type a username that doesn’t exist, and WordPress echoes it back with a tiny formatting flaw baked into…
-
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
Tags: access, ai, attack, authentication, breach, cisa, ciso, control, credentials, cyberattack, data, data-breach, endpoint, exploit, flaw, governance, identity, Internet, kev, login, malicious, privacy, radius, resilience, strategy, switch, threat, update, vpn, vulnerability, zero-trustThe BreachIt was 9:14 AM when the CISO’s VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn’t see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his…
-
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
Tags: access, ai, attack, authentication, breach, cisa, ciso, control, credentials, cyberattack, data, data-breach, endpoint, exploit, flaw, governance, identity, Internet, kev, login, malicious, privacy, radius, resilience, strategy, switch, threat, update, vpn, vulnerability, zero-trustThe BreachIt was 9:14 AM when the CISO’s VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn’t see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his…
-
OnePlus 10T Is Out of Security Support: Should You Keep Using Yours?
OnePlus 10T security support has ended. Here’s how owners can check their patch level, understand the risks, and decide when to replace the phone. The post OnePlus 10T Is Out of Security Support: Should You Keep Using Yours? appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-oneplus-10t-security-support-ended/
-
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server.Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai, First seen…
-
Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws
Google has released Chrome version 151.0.7922.108/.109 for Windows and macOS, and version 151.0.7922.108 for Linux. This update delivers 41 security fixes across various components of the browser, including rendering, graphics, JavaScript, user interface (UI), media, and authentication. The Stable channel update began rolling out on August 6 and will reach users over the next several…
-
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review.The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode.”These vulnerabilities were found First…
-
August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?
July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was the highest ever and, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/07/august-2026-patch-tuesday-forecast/
-
Hackers Can Abuse Microsoft WSUS Servers to Deploy Malicious Updates via NTLM Relay
Security researchers have shown how attackers could exploit Microsoft Windows Server Update Services (WSUS) infrastructure to distribute malicious software updates across enterprise networks. This technique relies on NTLM authentication coercion and relay attacks targeting WSUS deployments that utilize a separate Microsoft SQL Server database. WSUS is commonly used by organizations to centrally manage, approve, and…
-
Patch Bypass – Hacker umgehen Patch mit neuer FortiOS-Sicherheitslücke
First seen on security-insider.de Jump to article: www.security-insider.de/fortios-ssl-vpn-cve-2025-68686-symlink-schutz-umgehung-a-ade1382fea7c3643c1d8af8d65355388/
-
Azul beschleunigt Java-Patching: Kritische Sicherheitsupdates künftig monatlich
Azul führt monatliche kritische Java-Sicherheitsupdates ein. Unternehmen sollen Schwachstellen schneller schließen und Regressionsrisiken begrenzen können. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/azul-beschleunigt-java-patching-kritische-sicherheitsupdates-kuenftig-monatlich/a46045/
-
NVM Express updates specifications with post-quantum cryptography and SSD virtualization support
First seen on scworld.com Jump to article: www.scworld.com/brief/nvm-express-updates-specifications-with-post-quantum-cryptography-and-ssd-virtualization-support

