Tag: update
-
CISA orders feds to prioritize patching Langflow auth bypass flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until Friday to patch an actively exploited vulnerability in the Langflow visual framework for building AI agents. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-orders-feds-to-prioritize-patching-langflow-auth-bypass-flaw/
-
Found fast, fixed slow: The gap the AI clearinghouse must close
The government’s new AI clearinghouse risks becoming a committee that discovers more problems than it solves, unless it’s designed around patching, not just scanning. First seen on cyberscoop.com Jump to article: cyberscoop.com/ai-executive-order-cybersecurity-clearinghouse-vulnerability-patching-gap/
-
Automox MCP Server adds visual reviews and AI-driven patch policy creation
Automox has released Automox MCP Server 2.2, adding interactive review surfaces, first-class Patch by Severity policy creation, and live capability discovery to its governed … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/automox-mcp-server-2-2/
-
Ubiquiti warns of new max severity UniFi OS vulnerability
Ubiquiti has released security updates to patch seven critical vulnerabilities in UniFi OS, including a maximum-severity flaw that can be exploited in command injection attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ubiquiti-warns-of-new-max-severity-unifi-os-vulnerability/
-
Sicherheit: Metas Smart Glasses schalten Kamera bei Manipulation aus
Tags: updateMeta verteilt ein Update für seine Smart Glasses: Ziel ist es, unbemerkte Kameraaufnahmen zu verhindern – durch Deaktivierung der Kamera. First seen on golem.de Jump to article: www.golem.de/news/sicherheit-metas-smart-glasses-schalten-kamera-bei-manipulation-aus-2607-210626.html
-
CISA orders feds to patch max severity ColdFusion flaw by Friday
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch an actively exploited maximum-severity flaw in the Adobe ColdFusion commercial web app development platform by Friday. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-max-severity-coldfusion-flaw-by-friday/
-
How to implement a continuous offensive security testing program
The hard part was never finding the exposure. It was deciding what to do about it: whether to patch, mitigate, monitor, or accept, and banking that that decision would still … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/picus-continuous-offensive-security-testing-program/
-
Anthropic Keeps Claude Fable 5 Available on Paid Plans Until July 12
Anthropic has announced an extension of access to its advanced AI model, Claude Fable 5, allowing users on all paid plans to continue using the system until July 12, 2026. This update, shared via the company’s official X account, comes as enterprises increasingly rely on generative AI models for security research, code analysis, and threat…
-
Rewst AI agent update gives MSPs a new SMB automation play
First seen on scworld.com Jump to article: www.scworld.com/news/rewst-ai-agent-update-gives-msps-a-new-smb-automation-play
-
Hidden Tenda Router Backdoor Grants Admin Access, No Patch Available
CERT/CC warns an unpatched backdoor in several Tenda routers lets attackers bypass login and gain full admin access with a hidden password. CERT/CC published an alert documenting an undocumented authentication backdoor in multiple Tenda firmware versions, tracked as CVE-2026-11405. The flaw gives anyone who knows the right password full administrative access to the device’s web…
-
Windows 11 26H2 Enables Backup Policy to Restore User Apps and Settings
Microsoft has confirmed a significant policy change in the upcoming Windows 11 version 26H2. This update introduces a new default behavior for Windows settings backup, which could affect enterprise security baselines and device resilience strategies. According to an official announcement published on July 6, 2026, the Windows settings backup policy will change from being disabled…
-
Aktive Ausnutzung gemeldet – SharePoint RCE-Lücke funktioniert mit einfachem Benutzerkonto
First seen on security-insider.de Jump to article: www.security-insider.de/cve-2026-45659-sharepoint-rce-deserialisierung-benutzerkonto-a-5f30a8cda8b234615bd275711560a4cf/
-
BeyondTrust warns of critical flaws in remote access software
BeyondTrust warned customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software that could allow attackers to bypass authentication. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/beyondtrust-warns-of-critical-flaws-in-remote-access-software/
-
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated attackers to take control of susceptible devices.The vulnerabilities are listed below – CVE-2026-40138 (CVSS score: 9.2) – A pre-authentication vulnerability exists in the First seen on thehackernews.com Jump…
-
Microsoft Warns Windows 11 Enterprise Devices May Boot to Black Screen After Updates
Microsoft has issued a warning to enterprise administrators about a critical issue affecting Windows 11 systems. This problem may cause devices to boot to a black screen or experience severe shell failures following recent cumulative updates. The issue, documented under KB5072911, affects Windows 11 versions 24H2 and 25H2 when updates released on or after July…
-
Bad Epoll Flaw Gives Attackers Root Access on Linux and Android
Bad Epoll (CVE-2026-46242) lets local attackers gain root on Linux and Android. The flaw was missed by AI but found by a security researcher. A newly disclosed Linux kernel vulnerability, namedBad Epoll(CVE-2026-46242), allows a local attacker with no special privileges to gain full root access on affected Linux systems and Android devices. Security updates are…
-
Community darf helfen: Flipper Zero bekommt nach Kritik wieder Firmware-Updates
Im Schatten des Flipper One wurde die Firmware-Entwicklung des Flipper Zero gestoppt. Nach einem Aufschrei der Community geht es nun aber weiter. First seen on golem.de Jump to article: www.golem.de/news/community-darf-helfen-flipper-zero-bekommt-nach-kritik-wieder-firmware-updates-2607-210525.html
-
New ClamAV security patch closes seven scanner bugs dating back two decades
Open source antivirus scanning sits inside mail gateways, file upload checks, and endpoint tooling at organizations of every size. Much of that work runs through ClamAV, the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/06/clamav-security-patch-versions/
-
Parrot 7.3 released With new menu system and smoother dayday use
Parrot 7.3 arrives focused on refinement rather than a tool glut, rebuilding all editions to deliver perceptible gains on modern hardware and a smoother desktop experience. Released only months after its predecessor, this update concentrates on system-level improvements: optimized builds for newer CPUs, a rewritten menu stack in Go that enables one”‘click installs from the…
-
FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
FBI says TeamPCP poisoned trusted developer tools to steal cloud credentials, spread malware through software updates, and extort victims. On July 2, 2026, the FBI published a FLASH alert identifying the criminal group called TeamPCP and detailing how it compromised widely used developer and security tools to steal credentials from victim environments at scale. The…
-
Angriff per USB-Stick: KI findet gefährliche Lücke in populärem FatFs-Treiber
Das bloße Anschließen eines USB-Sticks reicht aus, um auf vielen Embedded- und IoT-Geräten Schadcode einzuschleusen. Einen Patch gibt es bisher nicht. First seen on golem.de Jump to article: www.golem.de/news/angriff-per-usb-stick-ki-findet-gefaehrliche-luecke-in-populaerem-fatfs-treiber-2607-210484.html
-
FBI Says TeamPCP Uses Trojanized Updates to Steal Cloud Tokens, SSH Keys, and Kubernetes Secrets
Tags: access, advisory, attack, cloud, cyber, cybercrime, exploit, group, kubernetes, software, supply-chain, updateThe Federal Bureau of Investigation (FBI) has issued an urgent FLASH advisory warning that the cybercriminal group TeamPCP is weaponizing trojanized software updates to harvest cloud access tokens, SSH keys, and Kubernetes secrets at scale. This campaign represents one of the most sophisticated software supply chain attacks observed in 2026, exploiting trust in widely deployed…
-
FCC Router Ban Risks Freezing Home Security Updates
Verizon Waiver Is Latest Carve-Out in a Rule Experts Say Undercuts Router Security. The FCC granted Verizon a one-year waiver from its foreign-router ban, the latest carve-out in a rule that critics say would strip millions of home routers of the security patches that keep them safe once temporary exemptions lapse. First seen on govinfosecurity.com…
-
New Chrome Update Fixes 382 Security Bugs Across Desktop, Mobile
Google released a Chrome update addressing 382 security bugs, including sandbox-escape risks. Users and IT teams should update quickly. The post New Chrome Update Fixes 382 Security Bugs Across Desktop, Mobile appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-chrome-update-382-security-bugs/
-
Apple Reverses Age-Old Patch Policy to Keep Up With AI
Expect more compressed patching cycles from Apple going forward, as attackers leverage artificial intelligence to reduce time to exploit. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/apple-patch-policy-ai
-
US cyber agency warns over forgotten SharePoint flaw
An RCE vulnerability in Microsoft SharePoint that was mistakenly omitted from the May Patch Tuesday bulletin is being exploited in the wild, says Cisa. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645307/US-cyber-agency-warns-over-forgotten-SharePoint-flaw
-
U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, microsoft, update, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Microsoft SharePoint Server flaw, tracked as CVE-2026-45659 (CVSS score v3.1 of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. At the end of May, Microsoft released security updates…
-
Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic
Adobe fixed multiple critical flaws, including max severity bugs in ColdFusion and Campaign Classic that could lead to remote code execution Adobe has released security updates for ColdFusion and Campaign Classic, fixing multiple critical vulnerabilities, including seven maximum-severity issues (CVSS score of 10.0). If exploited, the flaws could allow attackers to execute arbitrary code, escalate…
-
What the AI patch gap means for enterprise security
Open-source maintainers are receiving more vulnerability reports than they can act on, and a rising share now comes from an AI system working at machine speed. Over roughly … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/02/open-source-ai-patch-gap/

