Tag: update
-
PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.The company has released an emergency patch for v25 and v26 to address the issue. It said it’s “aware of confirmed customer incidents and is treating this matter…
-
PaperCut Warns of Actively Exploited Vulnerability Affecting NG and MF Servers
PaperCut has issued an urgent security advisory after confirming the active exploitation of a vulnerability affecting all versions of its PaperCut NG and PaperCut MF print-management servers. Organizations with Application Servers exposed to the internet are urged to immediately restrict web access to trusted internal IP addresses and deploy emergency updates for versions 25 and…
-
CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday
CISA has ordered U.S. government agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution vulnerability by Saturday. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-hackers-now-exploiting-citrix-netscaler-rce-flaw-in-attacks/
-
GitLab Duo Claude AI Agent Flaw Lets Attackers Execute Arbitrary Commands in CI Pipelines
GitLab has released security updates for both its Community Edition and Enterprise Edition, addressing seven vulnerabilities, including a high-severity flaw in its Duo Claude AI agent. This vulnerability could allow authenticated developers to execute arbitrary commands within a CI (Continuous Integration) context. GitLab Duo Claude AI Agent Flaw The issue, tracked as CVE-2026-18252, arises from…
-
Critical Veeam ONE Flaw Lets Unauthenticated Attackers Coerce SMB Authentication From Service Accounts
Veeam has released security updates for a critical vulnerability in Veeam ONE that could allow an unauthenticated network attacker to coerce SMB authentication from the account running an affected service. Tracked as CVE-2026-65641, the vulnerability received a CVSS v4.0 severity score of 9.3. Veeam disclosed the issue through Knowledge Base article 4905, published on August…
-
AI agents will try every door and find the ones left unlocked
Enterprises are working out how to give AI agents identities of their own, says Ping Identity CEO Andre Durand, just as frontier models start finding vulnerabilities faster than anyone can patch them First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649703/AI-agents-will-try-every-door-and-find-the-ones-left-unlocked
-
KI-Governance auf mobilen Endgeräten: Die alten Regeln gelten nicht mehr
KI-Funktionen wandern zunehmend vom Chatfenster in Apps, Agenten und mobile Endgeräte. Für Unternehmen bedeutet das: Klassische KI-Governance greift zu kurz, wenn sie mobile Nutzung, App-Updates, Netzwerkwechsel und rollenbasierte Risiken nicht gezielt berücksichtigt. Management Summary Klassische KI-Governance reicht für mobile Endgeräte nicht mehr aus: KI steckt heute zunehmend in nativen Apps, Updates und Agenten statt nur……
-
Ubiquiti Fixes 22 UniFi Flaws Enabling Command Injection, Authentication Bypass and Privilege Escalation
Ubiquiti has released security updates to address 22 vulnerabilities across its UniFi ecosystem. These updates include multiple critical flaws that could allow unauthenticated command injection, authentication bypass, and privilege escalation on exposed devices. Documented in Security Advisory Bulletin 067 and published on August 26, 2026, these vulnerabilities affect several components, including UniFi OS, UniFi Protect,…
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
OWASP updates top 10 security risks for LLM applications
First seen on scworld.com Jump to article: www.scworld.com/analysis/owasp-updates-top-10-security-risks-for-llm-applications
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
Android Malware Hijacks Update System for Car Head Units
Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/android-malware-hijacks-update-system-car-head-units
-
Stop Building a 2003 SOC with AI: Local Context, Failure Modes and Your Path (Part 3)
In Part 1 of this series, we dumped a pile of uncomfortable questions on you and promised answers. In Part 2 of the series, we talked about why 1990s-2000s alert triage must die. The core thesis, if you recall: if you add AI agents into a legacy, swivel-chair SOC structure, you are essentially building a robotic…
-
Update Chrome before you browse again
Chrome’s latest update fixes 327 security vulnerabilities, including some that malicious websites could exploit as soon as you visit them. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/update-chrome-before-you-browse-again/
-
SonicWall NetExtender Flaw Lets Attackers Write Arbitrary Files as Root
SonicWall has released security updates for two high-severity vulnerabilities in its NetExtender Linux Client. One of these is a path traversal flaw that could allow attackers to write arbitrary files with root privileges. The most severe issue, tracked as CVE-2026-66152, has a CVSS score of 8.8/10 and affects NetExtender Linux Client versions 10.3.5 and earlier.…
-
Google Chrome 152 Patches 327 Security Flaws, Including 10 Critical Vulnerabilities
Google has released Chrome version 152 for Windows, macOS, and Linux, addressing 327 security vulnerabilities, including 10 rated as Critical. This stable-channel update is being rolled out as version 152.0.7977.64 for Linux and 152.0.7977.64/.65 for Windows and macOS. This update is significant due to the sheer number and severity of memory-safety issues fixed across Chrome’s…
-
Microsoft SharePoint Flaws Let Unauthenticated Attackers Execute Remote Code
Microsoft SharePoint Server administrators are being urged to patch two vulnerabilities that could be combined to allow unauthenticated remote code execution on exposed on-premises servers. The flaws, tracked as CVE-2026-55040 and CVE-2026-63520, affect SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Microsoft SharePoint Flaws The urgency has increased after Defused reported…
-
Jetzt updaten: Hunderte Sicherheitslücken in Google Chrome gepatcht
Unzählige Chrome-Nutzer sind über mehr als 300 Sicherheitslücken Angreifbar. Das jüngste Update schützt davor und sollte zügig installiert werden. First seen on golem.de Jump to article: www.golem.de/news/jetzt-updaten-327-sicherheitsluecken-in-google-chrome-gepatcht-2608-212303.html
-
Jetzt updaten: 327 Sicherheitslücken in Google Chrome gepatcht
Unzählige Chrome-Nutzer sind über mehr als 300 Sicherheitslücken Angreifbar. Das jüngste Update schützt davor und sollte zügig installiert werden. First seen on golem.de Jump to article: www.golem.de/news/jetzt-updaten-327-sicherheitsluecken-in-google-chrome-gepatcht-2608-212303.html
-
OpenSSL Flaws Allow Remote Attackers to Crash Servers With Malformed Packets
OpenSSL has released security updates addressing nine vulnerabilities that could allow remote attackers to crash QUIC, DTLS, CMS, CMP, and TLS-enabled applications through malformed network packets or cryptographic messages. The advisory dated August 25, 2026, highlights three moderate-severity issues and six low-severity flaws. Most of these problems could lead to denial-of-service (DoS) conditions due to…
-
Microsoft Teams Outage Disrupts Meetings and Screen Sharing for Users
Microsoft confirmed that some customers were unable to use multiple features of Microsoft Teams. However, the company reported that monitoring indicated the disruption was largely under control. In a customer update posted at 7:26 a.m. IST on August 26, Microsoft stated that engineers would continue to monitor the service for another 15 to 30 minutes…
-
WhatsApp Passkeys Now Protect Over 1 Billion Users Against Account Takeover Attacks
WhatsApp has announced that over one billion people now use passkeys to secure their accounts, enhancing phishing-resistant authentication across one of the world’s largest messaging platforms. This update, revealed on August 25, introduces support for multiple passkeys, stronger two-step verification credentials, and additional context for calls from unknown numbers. These changes target common account takeover…
-
Nucleus Security Adds Agentic AI Engine to Exposure Management Portfolio
Nucleus Security today extended its exposure management platform to add an artificial intelligence (AI) engine and a set of AI agents that have been trained to automate specific tasks. Additionally, Nucleus Security is providing enhanced remediation guidance, vulnerability-type routing, Patch Tuesday intelligence, end-of-life operating system insights, and the ability to enrich Stakeholder-Specific Vulnerability Categorization (SSVC),..…
-
Car Infotainment Malware Builds Criminal Proxy Botnet
DoFun Software Updates Exploited to Infect Android Head Units. Attackers are exploiting legitimate software updates to infect Android-based car infotainment systems, or head units, turning them into reverse proxies. Kaspersky linked the malware campaign to the MoYu Group, a threat actor linked to BADBOX and BADBOX 2.0. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/car-infotainment-malware-builds-criminal-proxy-botnet-a-32652
-
Android Car Systems Infected With Malware Through Software Updates
Kaspersky uncovered malware spreading via software updates on Android-based car head units, turning infected systems into proxy nodes in a botnet. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity-threats/news-android-car-malware-software-update-botnet/
-
Actively Exploited Oracle WebLogic Bug Gets Patch Order
Federal Agencies Must Apply Oracle’s January Patch by Aug. 27. CISA ordered federal agencies to patch CVE-2026-21962 by Aug. 27 after confirming active exploitation of the maximum-severity Oracle middleware flaw, which lets unauthenticated attackers use crafted HTTP requests to access or modify critical data. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/actively-exploited-oracle-weblogic-bug-gets-patch-order-a-32650
-
Oasis Security Researchers Reveal Security Flaw in NemoClaw AI Agent
Cybersecurity researchers from Oasis Security today disclosed a vulnerability in instances of the NemoClaw artificial intelligence (AI) agent running on a local machine that could lead to it being taken over. Elad Luz, head of research at Oasis Security, said the vulnerability (CVE-2026-65105) has been remediated in the latest update to NemoClaw but organizations will..…
-
Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable
Two CVSS 9.8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database. Manual patch required. Two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On WordPress plugin, both rated CVSS 9.8, are under active exploitation. Both CVE-2026-61979 and CVE-2026-15981 allow an unauthenticated attacker to…

