Tag: update
-
SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs
SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild. SonicWall’s researchers William Perry and Adam Babis discovered the vulnerabilities. SonicWall confirmed that…
-
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separately said 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise.The incident window ran from approximately August 28 at 20:57…
-
FreeRDP 3.31.0 Fixes 22 Security Flaws Including Heap Overflow and Pre-Auth DoS Bugs
FreeRDP version 3.31.0 has been released as a significant security and stability update, addressing 22 disclosed security vulnerabilities in the widely used open-source implementation of the Remote Desktop Protocol (RDP). Project maintainers have termed this release a “huge bug fix and security release” and strongly encourage distributors to update promptly due to the serious nature…
-
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.The vulnerabilities, discovered internally by SonicWall’s William Perry and Adam Babis, are listed below – CVE-2026-83548 (CVSS score: 10.0) – A pre-authentication SSRF vulnerability in the Appliance First seen…
-
Critical HPE Fabric Composer Flaw Lets Unauthenticated Attackers Execute Commands as Privileged User
Hewlett Packard Enterprise (HPE) has released security updates addressing 52 vulnerabilities in HPE Networking Fabric Composer, including two critical flaws that could allow unauthenticated remote attackers to gain administrative control or execute commands as a privileged operating-system user. These issues affect Fabric Composer versions 7.3.3 and earlier. HPE Fabric Composer Flaw The most severe vulnerability,…
-
Google Patches 26 Chrome Vulnerabilities, Including Critical WebGL and Shared Tab Groups Flaws
Google has released a new update for the Chrome Stable Channel on desktop platforms, addressing 26 security vulnerabilities. This includes two critical use-after-free flaws affecting WebGL and Shared Tab Groups. The update upgrades Chrome to version 152.0.7977.75 on Windows and macOS, while Linux users receive version 152.0.7977.76. Google stated that the update will be rolled…
-
Hackers Chain Two New SonicWall Zero-Day Vulnerabilities
SonicWall has urged customers to patch two new zero-day vulnerabilities being exploited in the wild First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hackers-chain-sonicwall-zeroday/
-
JFrog Artifactory flaw exploited days after patch release
First seen on scworld.com Jump to article: www.scworld.com/news/jfrog-artifactory-flaw-exploited-days-after-patch-release
-
Hackers push malicious Virtualizor update in BGP hijacking attack
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-push-malicious-virtualizor-update-in-bgp-hijacking-attack/
-
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/clickfix-campaign-comprises-31-orgs-abuses-polygon-blockchain
-
Java-Sicherheit – Azul verkürzt Java-Patch-Zyklus auf monatliche Sicherheitsupdates
Tags: updateFirst seen on security-insider.de Jump to article: www.security-insider.de/azul-verkuerzt-java-patch-zyklus-auf-monatliche-sicherheitsupdates-a-f668ef34f032a23de5965643bc62cc64/
-
Java-Sicherheit – Azul verkürzt Java-Patch-Zyklus auf monatliche Sicherheitsupdates
Tags: updateFirst seen on security-insider.de Jump to article: www.security-insider.de/azul-verkuerzt-java-patch-zyklus-auf-monatliche-sicherheitsupdates-a-f668ef34f032a23de5965643bc62cc64/
-
Java-Sicherheit – Azul verkürzt Java-Patch-Zyklus auf monatliche Sicherheitsupdates
Tags: updateFirst seen on security-insider.de Jump to article: www.security-insider.de/azul-verkuerzt-java-patch-zyklus-auf-monatliche-sicherheitsupdates-a-f668ef34f032a23de5965643bc62cc64/
-
BGP Hijacking Attack Delivers Malicious Virtualizor Updates to Servers
A BGP hijacking incident targeting Softaculous infrastructure redirected traffic for Virtualizor update services to attacker-controlled systems, allowing a malicious update package to be delivered to a small number of servers. The incident impacted the IP range 162.55.80.0/24, which is hosted within Hetzner’s infrastructure, from approximately 20:57 UTC on August 28 to 06:10 UTC on August…
-
OpenClaw 2.0 Released With Enhanced AI Agent Security and Credential Protection
OpenClaw has launched version 2.0, offering a major overhaul of its AI-agent platform. This update emphasizes streamlined deployment, a rebuilt browser experience, collaborative cloud sessions, and enhanced security for credentials and connected services. The release on August 30 represents the largest update in the project’s history, according to the OpenClaw Foundation. It features contributions from…
-
Chrome und Edge: Mehrere Browser-Add-ons per Update mit Malware verseucht
Forscher haben 19 mit Malware verseuchte Browsererweiterungen für Chrome und Edge entdeckt. Der Schadcode wurde erst nachträglich eingeschleust. First seen on golem.de Jump to article: www.golem.de/news/chrome-und-edge-mehrere-browser-add-ons-per-update-mit-malware-verseucht-2608-212452.html
-
Microsoft says Windows 11 KB5120998 update resets mouse settings
Microsoft has confirmed that mouse settings are being reverted on Windows 11 systems after installing the KB5120998 August 2026 non-security preview update. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-says-windows-11-kb5120998-update-resets-mouse-settings/
-
Microsoft Defender Bug Triggers False “Antivirus Turned Off” Alerts on Windows
Microsoft has confirmed an issue with Microsoft Defender Antivirus that generates false notifications on Windows systems, claiming >>Microsoft Defender Antivirus is turned off,<< even though the protection is still operational. These alerts may appear after installing the latest Defender updates, potentially causing unnecessary concern for administrators who observe that Defender settings are healthy and security…
-
Android 17 Adds New Network Security Features to Block 2G SMS Blaster Attacks
Android 17 introduces a new set of network security controls to reduce cellular downgrade attacks, protect local networks, and limit metadata exposure during encrypted web sessions. This update includes carrier-managed 2G shutdown capabilities designed to combat SMS blaster campaigns that increasingly target users in public spaces. Google states the Android 17 changes focus on four…
-
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials. The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed these issues in…
-
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials. The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed these issues in…
-
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials. The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed these issues in…
-
Composer Path Traversal Flaw Lets Malicious Packages Expose Sensitive Files
Composer users are urged to update their software following the disclosure of a path-traversal vulnerability. This flaw could allow a malicious or compromised PHP package to change file permissions outside of its own installation directory. The vulnerability is tracked as CVE-2026-59944 and GHSA-96h3-5x6v-m776, affecting Composer versions 2.3.0 through 2.10.2 and versions 1.0 through 2.2.29. Composer…
-
OpenAI Warns Astra AI Model May Develop Zero-Day Exploits and Launch Autonomous Cyberattacks
Tags: ai, cyber, cyberattack, cybersecurity, exploit, intelligence, openai, update, vulnerability, zero-dayOpenAI has issued a warning regarding Astra, an upcoming artificial intelligence model, which may be close to a threshold of cybersecurity capabilities that would allow it to independently discover zero-day vulnerabilities and conduct complex cyberattacks against highly secured systems. In a security update dated August 7, 2026, the company noted that early testing and assessments…
-
AI AppSec tools agree on just 5% of security findings
Software vulnerabilities are turning into exploits within hours, and application security teams carry patch backlogs that go back years. Top types of viable application … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/31/contrast-security-ai-appsec-tools-security-findings-report/
-
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker.The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted customers, which leaves organizations…
-
PaperCut Zero-Day Under Active Attack: Emergency Patch Released
PaperCut warns that a zero-day in NG and MF is being exploited. The company already release emergency patches to address it. PaperCut Software warns that attackers are actively exploiting a zero-day in its NG and MF print management products. The flaw has no CVE yet, and the company has not released technical details. PaperCut issued…
-
Patch-Defizit in Deutschland: Exploit gefährdet 85 Prozent aller Exchange-Server
Auf Github ist ein Exploit für eine gefährliche Exchange-Lücke aufgetaucht. Einen Patch gibt es zwar, doch den haben in Deutschland nur wenige installiert. First seen on golem.de Jump to article: www.golem.de/news/patch-defizit-in-deutschland-exploit-gefaehrdet-85-prozent-aller-exchange-server-2608-212397.html
-
Windows 11 KB5120998 update released with 35 changes and fixes
Microsoft released the KB5120998 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 35 changes, including improvements to the Start menu, taskbar, and Windows search. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/windows-11-kb5120998-update-released-with-35-changes-and-fixes/

