Tag: vulnerability
-
Top 10 Vulnerability Assessment and Penetration Testing Companies 2026
In today’s interconnected digital world, no organization is truly safe from cyber threats. A single unpatched vulnerability can become an open door for a devastating cyberattack, leading to data breaches, financial losses, and irreparable damage to a brand’s reputation. To stay ahead of sophisticated attackers, businesses must be proactive, not reactive. This is where vulnerability…
-
Samsung’s August Update Patches 56 Security Vulnerabilities Across Galaxy Devices
Samsung’s August 2026 Galaxy update fixes 56 Android and One UI security flaws, including critical vulnerabilities and clipboard access risks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-samsung-august-2026-galaxy-security-update/
-
Hackers Stalked Me by Hijacking a Smartwatch for Kids
Security researchers tracked and eavesdropped on a WIRED reporter using vulnerabilities in a pink plastic smartwatch. It’s just one piece of a deeply insecure supply chain of GPS-enabled gadgets. First seen on wired.com Jump to article: www.wired.com/story/hackers-stalked-me-by-hijacking-a-smartwatch-for-kids/
-
Swiss government SharePoint breach compromised 200 accounts
Switzerland’s federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/
-
1Password Finds AI Security Patches Fail More Than Half the Time
A 1Password study found AI-generated security patches failed to fully fix vulnerabilities in more than half of tested cases. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/artificial-intelligence/1password-finds-ai-security-patches-fail-more-than-half-the-time/
-
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests.The flaw is tracked as CVE-2026-64561 and affects KVM/x86’s shadow memory management unit (MMU), which…
-
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review.The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode.”These vulnerabilities were found First…
-
AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing
Tags: access, ai, api, application-security, compliance, control, cyber, cybersecurity, data, exploit, flaw, reverse-engineering, risk, software, threat, tool, update, vulnerabilityWe spent 500+ hours and 40 billion tokens testing Anthropic’s Claude Mythos Preview for Project Glasswing. The takeaway: frontier AI won’t run your code security program, but used well, it can make one even stronger. Key takeaways Frontier AI dramatically scales security testing. In one month, Tenable dedicated 11 security experts and more than 40…
-
Critical Paperclip AI Agent Flaws Allow Unauthenticated Remote Code Execution
Critical vulnerabilities in the open-source Paperclip AI-agent orchestration platform could allow attackers to execute commands remotely on exposed servers or on a developer’s local machine. These flaws arise from broken authorization boundaries across agent imports and API routes, as well as trust assumptions for localhost. Paperclip is designed to coordinate autonomous agents across >>companies,<< with…
-
Three in four AI-generated vulnerability patches leave something broken
Ask a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write. When there is a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/1password-ai-generated-vulnerability-patches/
-
Patch Me If You Can, The VPN, the Backup Server, and the Browser Zero-Day
Actively exploited VPN, browser and backup vulnerabilities show why effective patching depends on risk-based cybersecurity governance, not perfect security. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/patch-me-if-you-can-the-vpn-the-backup-server-and-the-browser-zero-day/
-
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports – many of which were found to be describing security flaws that simply didn’t exist. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/apple-bug-bounty-ai-missing-exploits
-
Critical Jenkins Deserialization Flaw Allows Attackers to Execute Code on Controllers
A critical vulnerability in Jenkins, tracked as CVE-2026-70426, may allow attackers to execute arbitrary code on Jenkins controllers by bypassing deserialization protections within the platform’s Remoting library. This flaw, identified as SECURITY-3911, affects Jenkins environments where agents communicate with controllers via serialized Java objects over Remoting, typically deployed as agent.jar or remoting.jar. The Java serialization…
-
Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)
Cisco has fixed a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller (IMC), which allows an attacker to run commands as root through the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/cisco-imc-cve-2026-20200-public-poc-exploit/
-
PoC Released for Linux Kernel STP UseFree Vulnerability
A proof-of-concept (PoC) has been released for a use-after-free vulnerability affecting the Linux kernel’s software bridge implementation found in `net/bridge`. This vulnerability occurs within the Spanning Tree Protocol (STP) timer lifecycle. It can result in timer structures referencing freed bridge memory, potentially allowing for control-flow hijacking. The SSD Secure Disclosure technical team disclosed the issue…
-
U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a JetBrains TeamCity vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a JetBrains TeamCity vulnerability, tracked as CVE-2026-63077 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. At the end of July, JetBrains released security updates for TeamCity…
-
OpenAI Agents Worked Together to Find Exploits and Hack External Systems
OpenAI has revealed new details about an incident involving AI agents, in which multiple autonomous agents reportedly worked together to identify vulnerabilities, bypass containment measures, and gain access to external systems during a cybersecurity evaluation. Speaking at the Black Hat conference in Las Vegas, OpenAI alignment researcher Eric Wallace and security and infrastructure specialist Michael…
-
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
Tags: access, cisa, cve, cybersecurity, data, exploit, flaw, infrastructure, rce, remote-code-execution, vulnerabilityA newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).The vulnerability in question is CVE-2026-63077 (CVSS score: 9.8), a case of deserialization of untrusted data that could allow an unauthenticated attacker with access to a TeamCity…
-
Cisco Patches 7 IOS XE Vulnerability Classes, Including Critical Command Injection Flaws
Cisco has released security-hardening updates for IOS XE Software that address seven classes of vulnerabilities, including a critical command, operating system, and argument injection category identified as CVE-2026-20272. The advisory, released on August 5, has an overall CVSS score of 3.1 and 9.8 and provides no workarounds, meaning that upgrading is the only recommended solution.…
-
CISA Alerts Issues on Actively Exploited TeamCity Remote Code Execution Vulnerability
Tags: cisa, cve, cyber, cybersecurity, data-breach, exploit, flaw, infrastructure, kev, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in JetBrains TeamCity, tracked as CVE-2026-63077, to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation. This flaw allows unauthenticated remote code execution (RCE) on vulnerable TeamCity On-Premises servers exposed via HTTP or HTTPS. CISA Issues on TeamCity RCE…
-
Statische Zugangsdaten – Cisco warnt vor aktiv ausgenutzter FMC-Schwachstelle
First seen on security-insider.de Jump to article: www.security-insider.de/cisco-fmc-cve-2026-20316-statische-zugangsdaten-hotfixes-a-2100ea013718c4c70cce681fe6e105c9/
-
Palo Alto Networks Introduces PAN-OS 12.2 Ceres With AI Security Features
Palo Alto Networks has introduced PAN-OS 12.2 Ceres, a firewall operating system update that adds more than 55 innovations aimed at attacks accelerated by frontier AI. The release centers on Advanced Virtual Patching, Advanced IP Defense and six AI-powered Network Security Agents. Advanced Virtual Patching uses AI to identify unknown vulnerabilities and deliver network protections..…
-
Ridge Security Launches RidgeGen for Continuous Offensive Security Testing
Ridge Security has announced the availability of RidgeGen, an agentic AI platform for continuous offensive security testing. The platform is designed to find unknown and exploitable risks, investigate how vulnerabilities, business logic flaws and misconfigurations could be chained, and validate findings with reproducible evidence before they reach a security team. Ridge Security said the approach..…
-
TP-Link Omada ZTP systems vulnerable to fleet-wide compromise
Tags: vulnerabilityFirst seen on scworld.com Jump to article: www.scworld.com/brief/tp-link-omada-ztp-systems-vulnerable-to-fleet-wide-compromise
-
No Perfect Fix for AI Browser Prompt Injection Flaws
AI browsers from top vendors remain vulnerable to prompt injection attacks despite multiple security guardrails, according to new research. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/no-perfect-fix-ai-browser-prompt-injection-flaws
-
Microsoft Bug Bounty Payouts Reach $20 Million as Researcher Participation Surges
Microsoft paid a record $20 million to 562 bug bounty researchers as AI-assisted reporting and growing participation reshaped vulnerability discovery. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-microsoft-bug-bounty-payouts-20-million/
-
AI Browsers Vulnerable to ‘PleaseFix’ Zero-Click Agent Hijacking
Attackers can take control of agents through malicious instructions hidden in content supplied to AI browsers, and there’s no simple fix for the threat. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/ai-browsers-zero-click-agent-hijacking

