Tag: update
-
Samsung’s August Update Patches 56 Security Vulnerabilities Across Galaxy Devices
Samsung’s August 2026 Galaxy update fixes 56 Android and One UI security flaws, including critical vulnerabilities and clipboard access risks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-samsung-august-2026-galaxy-security-update/
-
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review.The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode.”These vulnerabilities were found First…
-
AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing
Tags: access, ai, api, application-security, compliance, control, cyber, cybersecurity, data, exploit, flaw, reverse-engineering, risk, software, threat, tool, update, vulnerabilityWe spent 500+ hours and 40 billion tokens testing Anthropic’s Claude Mythos Preview for Project Glasswing. The takeaway: frontier AI won’t run your code security program, but used well, it can make one even stronger. Key takeaways Frontier AI dramatically scales security testing. In one month, Tenable dedicated 11 security experts and more than 40…
-
Patch Me If You Can, The VPN, the Backup Server, and the Browser Zero-Day
Actively exploited VPN, browser and backup vulnerabilities show why effective patching depends on risk-based cybersecurity governance, not perfect security. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/patch-me-if-you-can-the-vpn-the-backup-server-and-the-browser-zero-day/
-
Three in four AI-generated vulnerability patches leave something broken
Ask a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write. When there is a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/1password-ai-generated-vulnerability-patches/
-
U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a JetBrains TeamCity vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a JetBrains TeamCity vulnerability, tracked as CVE-2026-63077 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. At the end of July, JetBrains released security updates for TeamCity…
-
Microsoft extends zero trust deeper into enterprise AI
Microsoft expanded its Zero Trust for AI strategy with updates to the Zero Trust Assessment tool and the Zero Trust Workshop. The additions help organizations assess security … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/microsoft-zero-trust-for-ai-strategy-updates/
-
Cisco Patches 7 IOS XE Vulnerability Classes, Including Critical Command Injection Flaws
Cisco has released security-hardening updates for IOS XE Software that address seven classes of vulnerabilities, including a critical command, operating system, and argument injection category identified as CVE-2026-20272. The advisory, released on August 5, has an overall CVSS score of 3.1 and 9.8 and provides no workarounds, meaning that upgrading is the only recommended solution.…
-
Palo Alto Networks Introduces PAN-OS 12.2 Ceres With AI Security Features
Palo Alto Networks has introduced PAN-OS 12.2 Ceres, a firewall operating system update that adds more than 55 innovations aimed at attacks accelerated by frontier AI. The release centers on Advanced Virtual Patching, Advanced IP Defense and six AI-powered Network Security Agents. Advanced Virtual Patching uses AI to identify unknown vulnerabilities and deliver network protections..…
-
Novee Brings Continuous AI Pentesting to Mobile Applications
Novee has expanded its AI penetration testing platform to mobile applications, extending continuous testing across mobile, web, APIs, desktop software and AI-enabled applications. The company announced the update ahead of Black Hat USA 2026. Novee said users can upload a mobile application package and receive results within hours, alongside findings from their other application assets……
-
Metasploit Opens Its Exploit Engine to LLMs via New MCP Integration
If there was any reason to patch your systems, this would be it: The release of Metasploit 6.5, which brings the penetration testing framework into the AI age. Now, script kiddies and sophisticated foreign operatives don’t even have to cut and paste their code to break into your systems. They can just ask Metasploit to..…
-
Miggo Adds DefenseDepth Mitigation to Close Patch Gaps in Minutes
Miggo Security has announced Defense-in-Depth Mitigation, a capability that coordinates protections at the network edge and inside an application while a permanent patch is being prepared. The release was issued from Black Hat USA and says Miggo is presenting the capability in Las Vegas during the event. The approach gives security teams multiple mitigation points..…
-
Assail Updates Ares With New Harness and AI Model for Autonomous Red Teaming
Assail has introduced Ares v2, a redesigned version of its autonomous offensive security platform, with a new interface, purpose-built model and rebuilt agentic harness. The company is tying the update to its Black Hat 2026 program, where founder and CEO Alissa Knight is scheduled to discuss how organizations should evaluate offensive AI systems. The new..…
-
OnePlus Nord 6 Gets Six Years of Security Updates, Four Android Upgrades
The OnePlus Nord 6 will receive six years of security updates but only four generations of Android upgrades. Here’s how that split could affect app compatibility, device management, and long-term purchasing decisions. The post OnePlus Nord 6 Gets Six Years of Security Updates, Four Android Upgrades appeared first on TechRepublic. First seen on techrepublic.com Jump…
-
Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted
Tags: access, ai, attack, breach, cloud, container, control, credentials, data, data-breach, github, guide, infection, intelligence, kubernetes, malicious, malware, microsoft, open-source, risk, sbom, service, software, threat, update<div cla TL;DR A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted. The malware executes through a malicious preinstall hook, steals npm, GitHub, cloud, Kubernetes, Vault, CI/CD, and other credentials, then uses stolen publishing access to compromise additional packages. Organizations that installed an affected version should…
-
Menlo Security Extends MARS to Protect AI Assistants and Coding Agents
Menlo Security has expanded Menlo Agent Runtime Security, or MARS, with controls aimed at protecting AI assistants and coding agents from prompt injection, malware and data loss as they browse the web, use applications and process files. The company is highlighting the update at Black Hat USA 2026. MARS is a cloud-based capability in Menlo’s..…
-
What Gold Eagle Validates, and What Your Organization Still Has to Own (July 2026)
Tags: ai, business, compliance, data, finance, framework, government, intelligence, open-source, update, vulnerabilityWhat Gold Eagle Validates, and What Your Organization Still Has to Own (July 2026) The federal government just stood up a clearinghouse to find and validate vulnerabilities faster, with AI doing the finding. That is not the same thing as a clearinghouse that owns the consequence when a patch does not land in time. Key…
-
Reco Expands AI Runtime With Browser Controls and Prompt Blocking
Reco is expanding its AI Runtime capability with browser-based enforcement, real-time prompt analysis and blocking, and automated remediation. The company said the update is designed to act on the risk posed by AI agents without requiring security teams to route traffic through a new gateway or proxy. Reco’s Smart Remediation feature turns findings into proposed..…
-
Arctic Wolf gibt CyberReadiness-Accelerator für Partner bekannt
Arctic Wolf gibt die Verfügbarkeit des <> bekannt. Das neue, partnergeführte Programm unterstützt Unternehmen dabei, Cyberrisiken besser zu verstehen und ihre Widerstandsfähigkeit in einer zunehmend von KI beschleunigten Bedrohungslandschaft zu stärken. Trotz Vulnerability- und Patch-Management bleiben Unternehmen unbekannten Risiken durch blinde Flecken innerhalb ihrer Angriffsfläche ausgesetzt, Tendenz steigend. Laut dem weltweiten Verizon-2026-Data-Breach- […] First seen…
-
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django.The three most serious: An unauthenticated flaw in Veeam’s console that hands over a managed agent’s credentials, rated 9.5 A cross-tenant flaw in HashiCorp’s MCP server that lets one user’s Terraform token be reused for…
-
ScreenConnect Attackers Hide Windows, Delete Installers and Masquerade as Software Updates
ScreenConnect is being systematically weaponized in the SMOKE#SCREEN campaign, where attackers hide execution windows, delete installers, and disguise malicious activity as routine software updates to plant fully functional, signed ScreenConnect agents across Windows and macOS endpoints. The result is persistent, “legitimate-looking” remote access that blends into normal IT operations while silently bypassing user awareness and…
-
Critical Veeam ONE Flaw Lets Unauthenticated Attackers Execute Code Remotely
Veeam has issued security updates to address multiple vulnerabilities in Veeam ONE, including a critical flaw that could enable an unauthenticated remote attacker to execute arbitrary code on an affected agent host. This issue, identified as CVE-2026-64633, has received the highest CVSS v4.0 score of 10.0, indicating it is the most severe vulnerability addressed in…
-
Django Flaws Let Attackers Trigger RCE, SSRF, DoS, and XSS Attacks
The Django project has released security updates, specifically Django 6.0.8 and Django 5.2.17, to address four vulnerabilities that could lead to server-side request forgery (SSRF), arbitrary file writes with potential for remote code execution (RCE), denial-of-service (DoS), and stored cross-site scripting (XSS) attacks. An advisory posted by Natalia Bidart on August 4, 2026, urges all…
-
CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access
A critical cPanel flaw (CVE-2026-58048) lets authenticated users execute SQL as root. Users should update to fixed versions immediately. If you run a shared hosting box, this one’s worth reading before your morning coffee gets cold. cPanel just patched a flaw, tracked as CVE-2026-58048 (CVSS score of 9.4), that let an ordinary authenticated hosting customer,…
-
Critical Adobe Campaign Flaws Let Unauthenticated Attackers Execute Arbitrary Code
Adobe has released an urgent security update for Adobe Campaign Classic, addressing multiple critical vulnerabilities that could allow remote attackers to execute arbitrary code on vulnerable servers without authentication. The update is documented in bulletin APSB26-120, published on August 3, 2026, and carries Adobe’s highest Priority 111 rating. The company urges organizations that use affected…
-
The U.S. Cyber Strategy Has a Scaling Problem and AI Is Exposing It
AI can discover and weaponize software vulnerabilities faster than organizations can patch them, making exploit mitigation and runtime protection essential to cybersecurity. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-u-s-cyber-strategy-has-a-scaling-problem-and-ai-is-exposing-it/
-
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild.The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows First seen…

