Tag: update
-
Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
Adobe has released patches for multiple maximum-severity security flaws impacting Adobe ColdFusion and Adobe Campaign Classic.The ColdFusion updates “resolves critical and important vulnerabilities”¯that could lead to”¯arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass,” Adobe said in an alert released Tuesday.The vulnerabilities are listed First seen on thehackernews.com Jump to article:…
-
Smart Home: Update kann Signifys Hue Bridge Pro kaputt machen
Tags: updateBesitzer einer Hue Bridge Pro sollten vorerst keine Updates installieren. Falls dabei ein Defekt auftritt, muss die Bridge ausgetauscht werden. First seen on golem.de Jump to article: www.golem.de/news/smart-home-update-macht-signifys-hue-bridge-pro-kaputt-2607-210370.html
-
(g+) Kernel Live-Patching: Patchen ohne Neustart – und warum der Reboot trotzdem kommt
Tags: updateLive-Patching schließt Kernel-Lücken ohne Neustart – aber nicht jede Lücke. Wie Live-Patching funktioniert und wo seine Grenzen liegen. First seen on golem.de Jump to article: www.golem.de/news/kernel-live-patching-patchen-ohne-neustart-und-warum-der-reboot-trotzdem-kommt-2607-210375.html
-
Self-harm and cyberflashing added to online safety offences list
The Online Safety Act has been updated to include ‘self-harm’ and ‘cyberflashing’ as ‘priority offences’, meaning online service providers will need to update their risk assessments of both categories First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645166/Self-harm-and-cyberflashing-added-to-online-safety-offences-list
-
Riesiges Update: 382 Sicherheitslücken in Google Chrome entdeckt
Die neueste Chrome-Version schließt fast 400 teils kritische Sicherheitslücken. Auch für Edge, Vivaldi und Brave dürften entsprechende Updates folgen. First seen on golem.de Jump to article: www.golem.de/news/riesiges-update-382-sicherheitsluecken-in-google-chrome-entdeckt-2607-210372.html
-
Riesiges Update: 382 Sicherheitslücken in Google Chrome entdeckt
Die neueste Chrome-Version schließt fast 400 teils kritische Sicherheitslücken. Auch für Edge, Vivaldi und Brave dürften entsprechende Updates folgen. First seen on golem.de Jump to article: www.golem.de/news/riesiges-update-382-sicherheitsluecken-in-google-chrome-entdeckt-2607-210372.html
-
Smart Home: Update macht Signifys Hue Bridge Pro kaputt
Tags: updateBesitzer einer Hue Bridge Pr sollten vorerst keine Updates installieren. Falls dabei ein Defekt auftritt, muss die Bridge ausgetauscht werden. First seen on golem.de Jump to article: www.golem.de/news/smart-home-update-macht-signifys-hue-bridge-pro-kaputt-2607-210370.html
-
Smart Home: Update macht Signifys Hue Bridge Pro kaputt
Tags: updateBesitzer einer Hue Bridge Pr sollten vorerst keine Updates installieren. Falls dabei ein Defekt auftritt, muss die Bridge ausgetauscht werden. First seen on golem.de Jump to article: www.golem.de/news/smart-home-update-macht-signifys-hue-bridge-pro-kaputt-2607-210370.html
-
Google Chrome 151 Released With 382 Security Fixes for Critical Vulnerabilities
Google has promoted Chrome 151 to the stable channel for Windows, macOS and Linux, delivering a major security update that addresses 382 vulnerabilities across the browser’s core engine, graphics stack, extensions framework and cross”‘platform components. The release, dated June 30, 2026, significantly hardens Chrome against memory corruption, type confusion, and policy”‘enforcement flaws that could be…
-
Citrix Patches Six NetScaler Flaws Allowing File Read and DenialService
Citrix on Tuesday released security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that could be exploited by an attacker to facilitate arbitrary file reads or trigger a denial-of-service (DoS) condition.The vulnerabilities are listed below – CVE-2026-8451 (CVSS score: 8.8) – An insufficient input validation First…
-
SolarWinds partner program update adds tiered discounts, training and rewards
First seen on scworld.com Jump to article: www.scworld.com/news/solarwinds-partner-program-update-adds-tiered-discounts-training-and-rewards
-
Aikido Buys Root for $70M to Automate Open-Source Patching
Deal Adds Hardened Packages, Automated CVE Fixes to Application Security Platform. Belgian software vendor Aikido Security acquired Boston-based Root for $70 million to embed automated vulnerability remediation into its application security platform, enabling enterprises to deploy hardened open-source packages and container images while reducing software supply-chain risk. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/aikido-buys-root-for-70m-to-automate-open-source-patching-a-32118
-
iPhone Security Fixes May Arrive Sooner as AI Speeds Up Threats
Apple is releasing some iPhone security fixes earlier as AI raises concerns about faster cyberattacks and shorter patch windows. The post iPhone Security Fixes May Arrive Sooner as AI Speeds Up Threats appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-apple-iphone-ai-security-updates/
-
Apple Fixes WebKit Flaws in iOS and macOS, With Help From AI Tools
Apple released updates for iOS, iPadOS, macOS, and Safari, fixing WebKit flaws, four of which were found using AI tools like Claude and Codex Apple pushed out security updates for iOS, iPadOS, macOS, and Safari on Monday, and this round comes with a twist worth noticing. Four of the WebKit vulnerabilities patched were found using…
-
Apple Fixes WebKit Flaws in iOS and macOS, With Help From AI Tools
Apple released updates for iOS, iPadOS, macOS, and Safari, fixing WebKit flaws, four of which were found using AI tools like Claude and Codex Apple pushed out security updates for iOS, iPadOS, macOS, and Safari on Monday, and this round comes with a twist worth noticing. Four of the WebKit vulnerabilities patched were found using…
-
PoC Released for NTLM reflection bypass Vulnerability that Emanbles SYSTEM Access on Windows Server
A proof-of-concept has been published that bypasses Microsoft’s mitigation for the NTLM reflection vulnerability tracked as CVE-2025-33073 and allows escalation to NT AUTHORITY\SYSTEM on Windows Server. The exploit leverages two conceptual weaknesses left unaddressed by the original patch: the mitigation was limited to the SMB client path, and recent SMB features let attackers coerce privileged…
-
Kali Linux 2026.2 released with 9 new tools, NetHunter updates
Kali Linux 2026.2, the second release of the year, is now available for download, featuring 9 new tools and numerous Kali NetHunter improvements. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/linux/kali-linux-20262-released-with-9-new-tools-nethunter-updates/
-
Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API.The flaw, tracked as CVE-2026-8037, carries a CVSS score of 9.8 according to ZDI. A patch is available. If you run LoadMaster with the API enabled, update now.Progress…
-
Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs
Apple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit that were discovered using artificial intelligence (AI) tools like Anthropic Claude and OpenAI Codex Security.The WebKit vulnerabilities are listed below – CVE-2026-43707 – A memory corruption issue that could result…
-
Update Chrome Now: Google Fixes 18 Security Flaws, Including Critical Bugs
Google’s Chrome 149 security update fixes 18 bugs, including four critical flaws affecting WebGL, Autofill, and Blink components. The post Update Chrome Now: Google Fixes 18 Security Flaws, Including Critical Bugs appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-chrome-149-security-update/
-
âš¡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More
This week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and suddenly the door is open.The noise is not all noise, either. Forums are talking, researchers are finding easy cracks, and defenders have more cleanup waiting.Here’s the full Monday recap.âš¡ Threat of…
-
DirtyClone: Fourth Linux Kernel Flaw in Six Weeks Escalates to Root
DirtyClone: a Linux kernel privilege escalation that silently rewrites executables in memory, leaving no disk trace. Patch now. JFrog Security Research published a working exploit walkthrough on June 25 for CVE-2026-43503 (CVSS score of 8.8), a Linux kernel privilege escalation they call DirtyClone. It’s the fourth vulnerability in the DirtyFrag family, all sharing the same…
-
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
Tags: attack, cisa, cisco, communications, cybersecurity, exploit, flaw, infrastructure, update, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-sets-urgent-deadline-to-fix-cisco-flaw-exploited-in-attacks/
-
Microsoft Extends Windows 10 Security Updates to 2027
Microsoft extended Windows 10 security updates for personal devices through Oct. 12, 2027, giving users more time to upgrade. The post Microsoft Extends Windows 10 Security Updates to 2027 appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-windows-10-security-updates-2027/
-
Meeting Trump’s 2030 Quantum Deadline Will be Expensive, Complex
Tags: updateGetting accurate visibility into IT and OT systems will be compounded by multivendor environments, misaligned update life cycles, and interoperability gaps. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/meeting-2030-quantum-deadline-expensive-complex
-
AWS unveils agent security, data access tools
The updates reflect Anthropic’s Mythos model and the speed at which vulnerabilities can be surfaced. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/aws-continuum-ai-security-claude-mythos/823393/
-
New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets
DirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough for the flaw on June 25, the first public demonstration for this variant.Tracked as CVE-2026-43503 (CVSS 8.8), it lets a local user corrupt file-backed memory through a cloned network packet and gain root. The patch…
-
Synology issues critical fix for MailPlus Server vulnerabilities
Synology has has fixed critical vulnerabilities in MailPlus Server, a software package used to run private email infrastructure on Synology NAS devices. The security update … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/26/synology-mailplus-server-vulnerabilities/
-
Metropolitan Police chief warns against law updates amid substantial tech expansion
The Metropolitan Police is to significantly expand use of AI, drones and facial recognition to ‘regain the advantage’ over criminals, but warns progress could be held back by legislation and data integration issues First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645086/Metropolitan-Police-chief-warns-against-law-updates-amid-substantial-tech-expansion
-
macOS.Gaslight: North Korea-Linked Malware That Tries to Gaslight the Analyst
macOS.Gaslight: DPRK Rust implant for Mac with a prompt injection payload designed to fool AI-based malware analysts. SentinelLabs researchers spotted a Rust-based macOS implant, dubbed macOS.Gaslight, that surfaced in early June after an Apple XProtect update pointed to a VirusTotal sample uploaded on May 22. The binary was undetected by static engines at the time…

