Tag: vulnerability
-
Industry reacts to Gold Eagle vulnerability management plan
As AI-discovered software vulnerabilities accumulate at an unprecedented pace, security pros say they hope Gold Eagle creates some order from the chaos. First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366645907/Industry-reacts-to-Gold-Eagle-vulnerability-management-plan
-
Threat group claims credit for ransomware attack on Coca-Cola’s dairy unit
The attackers previously exploited vulnerabilities or used stolen credentials for initial access.; First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/threat-group-ransomware-coca-colas-dairy-Fairlife/825900/
-
New InfraTrust report reveals infrastructure flaws admins should patch first
Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-infratrust-report-reveals-infrastructure-flaws-admins-should-patch-first/
-
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint (“/api/w/{workspace}/jobs_u/get_log_file/{filename}”).”The filename parameter is concatenated into First seen on thehackernews.com Jump to article: thehackernews.com/2026/07/hackers-exploit-windmill-flaw-to-read.html
-
Forescout Threat Review 2026H1 zeigt: KI-Boom treibt Cyberrisiken drastisch nach oben
Im ersten Halbjahr 2026 wurden weltweit 37.137 Schwachstellen veröffentlicht. Gegenüber dem Vorjahreszeitraum entspricht das einem Anstieg von 51 Prozent. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/forescout-threat-review-2026h1-zeigt-ki-boom-treibt-cyberrisiken-drastisch-nach-oben/a45831/
-
Apple Fixes Hide My Email Vulnerability That Exposed Users’ Real Email Addresses
Apple has addressed a year-old vulnerability in its >>Hide My Email<< privacy feature, which could expose users' real email addresses. This incident has already led to a class action lawsuit and increased scrutiny of Apple's privacy claims. Hide My Email, part of the paid iCloud+ subscription, allows users to generate random alias addresses that forward…
-
U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the KeV catalog: The first issue added to the catalog…
-
Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. >>WatchTowr is … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/22/sharepoint-cve-2026-50522-exploited/
-
CISA orders urgent action on actively exploited Langflow RCE flaw
Tags: ai, cisa, cybersecurity, exploit, flaw, framework, government, infrastructure, rce, remote-code-execution, update, vulnerabilityThe Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-langflow-rce-flaw/
-
New Ubuntu Desktop Vulnerability Turns Local Access Into Root Control
A vulnerability in snap-confine lets an unprivileged user gain root access on affected Ubuntu Desktop systems. Install the latest snapd update to fix the issue. First seen on hackread.com Jump to article: hackread.com/ubuntu-desktop-vulnerability-local-access-root-control/
-
CISA Warns WordPress Core SQL Injection Vulnerability Is Actively Exploited in Attacks
Tags: attack, cisa, cve, cyber, cybersecurity, exploit, infrastructure, injection, kev, sql, vulnerability, wordpressThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has classified a critical SQL injection vulnerability in WordPress Core, tracked as CVE-2026-60137, as one of its Known Exploited Vulnerabilities (KEV) due to its active exploitation in real-world attacks. This vulnerability affects the core functionality of WordPress when themes or plugins fail to properly validate untrusted input…
-
Ubuntu snap-confine Vulnerability Enables Local Root Access
New Ubuntu snap-confine race condition lets local users escalate to root on default installs First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ubuntu-snap-confine-local-root-cve/
-
Google Makes CodeMender Available as Managed AI Security Agent
CodeMender actively builds and runs exploits in customer-managed sandboxes to verify if vulnerabilities are truly exploitable First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/google-codemender-available-ai/
-
Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands
ASUS has announced a significant security vulnerability in its router firmware that could enable remote attackers to execute arbitrary commands through a man-in-the-middle (MITM) attack. This raises substantial concerns for both enterprise and home network security. The flaw, identified as CVE-2026-13385, impacts multiple branches of ASUS router firmware, including the widely used versions 3.0.0.4_386, 3.0.0.4_388,…
-
Google’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter
Google’s Gemini 3.5 Flash Cyber model finds, validates, and patches vulnerabilities before they can be exploited while helping mitigate broader misuse. It is part of a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/22/google-gemini-3-5-flash-cyber-model/
-
SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root
SolarWinds has released Serv-U 2026.3, which includes fixes for a cluster of 9.1 CVSS critical vulnerabilities that allow remote code execution (RCE) and privilege escalation up to root on Unix-like systems. This update significantly strengthens the managed file transfer (MFT) and FTP server platform against potential takeovers. While Windows instances are rated as having a…
-
Apple Faces Lawsuit Over Hide My Email Privacy Vulnerability
Apple is facing a proposed class-action lawsuit after Anthony Alvarez alleged that the company’s Hide My Email feature failed to protect users’ real email addresses as advertised. The complaint, filed in the U.S. District Court for the Northern District of California, claims Apple promoted Hide My Email as a privacy safeguard while continuing to charge customers for…
-
Google Unveils Gemini 3.5 Flash Cyber to Find and Fix Software Vulnerabilities Faster
Google has introduced Gemini 3.5 Flash Cyber, a lightweight AI model designed to improve cybersecurity by helping defenders identify, validate, and patch software vulnerabilities more efficiently. Built on Gemini 3.5 Flash and optimized for security tasks, Flash Cyber aims to deliver a cost-effective alternative to larger AI models while supporting large-scale vulnerability analysis. First seen on thecyberexpress.com Jump to…
-
Security teams keep finding critical flaws after scheduled testing ends
Enterprise environments change between scheduled security assessments, leaving organizations with periods where new vulnerabilities can go undetected. Synack’s State of … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/22/continuous-security-testing-gaps-report/
-
Google Launches Gemini 3.5 Flash Cyber to Find, Validate, and Patch Critical Vulnerabilities
Google has introduced Gemini 3.5 Flash Cyber, a lightweight AI model specifically designed to help security teams discover, validate, and patch critical software vulnerabilities at scale. Announced on July 21, 2026, this model builds on Gemini 3.5 Flash and is optimized for security workflows. It enables agents to inspect large codebases, explore numerous execution paths,…
-
Google Chrome Update Fixes 12 High-Severity Vulnerabilities That Enable Browser Attacks
Google has released a Chrome security update that addresses 12 high-severity vulnerabilities affecting various components, including WebAudio, ANGLE, Chromecast, extensions, Skia, the V8 JavaScript engine, certificate handling, the user interface, and GPU elements. Many of these vulnerabilities involve memory corruption issues, such as out-of-bounds reads and writes, use-after-free bugs, stack buffer overflows, and type confusion.…
-
OpenAI Exploits Zero-Day to Gain Internet Access and Compromise Hugging Face Servers
OpenAI has revealed that during an internal evaluation of advanced cyber capabilities, AI agents exploited a zero-day vulnerability, escaped a constrained research environment, and compromised parts of Hugging Face’s production infrastructure. While Hugging Face detected and contained the activity, OpenAI’s internal security team also identified unusual behavior during the assessment. OpenAI Compromise Hugging Face Servers…
-
F5 fixes critical nginx vulnerability CVE-2026-42533
First seen on scworld.com Jump to article: www.scworld.com/brief/f5-fixes-critical-nginx-vulnerability-cve-2026-42533
-
F5 fixes critical nginx vulnerability CVE-2026-42533
First seen on scworld.com Jump to article: www.scworld.com/brief/f5-fixes-critical-nginx-vulnerability-cve-2026-42533
-
HollowByte vulnerability allows denialservice attacks on OpenSSL
First seen on scworld.com Jump to article: www.scworld.com/brief/hollowbyte-vulnerability-allows-denial-of-service-attacks-on-openssl
-
Android lock screen vulnerability allows Gemini to send messages without PIN
First seen on scworld.com Jump to article: www.scworld.com/brief/android-lock-screen-vulnerability-allows-gemini-to-send-messages-without-pin
-
Kritische Rechteausweitung in Standardinstallationen von Ubuntu-Desktop
Ubuntu-Desktop ist in Unternehmen, öffentlichen Einrichtungen und bei Entwicklern im deutschsprachigen Raum weit verbreitet. Da die betroffenen Versionen in Standardkonfiguration verwundbar sind, sollten IT- und Sicherheitsverantwortliche zeitnah handeln. Die Qualys Threat Research Unit (TRU) hat eine Local-Privilege-Escalation-Schwachstelle (LPE) in snap-confine identifiziert (CVE-2026-8933). Diese Schwachstelle erlaubt es einem nicht privilegierten lokalen Benutzer, auf Standardinstallationen von Ubuntu-Desktop…
-
Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522
Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8), is being actively exploited following the release of a public proof-of-concept (PoC) code, according to watchTowr researchers. Patched in Microsoft’s July 2026 Patch Tuesday, the deserialization…
-
Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task
The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/finding-and-prioritizing-vulnerabilities-no-easy-task

