Tag: vulnerability
-
Phoenix Security Launches Exploit Hunt to Validate Vulnerabilities With AI-Generated Exploits
Phoenix Security has launched Exploit Hunt, an AI red-team capability that works from a live threat model and reports a vulnerability only after generating and validating a runnable proof-of-concept exploit. Announced Aug. 5 and timed to Black Hat USA 2026, Exploit Hunt is available now in Phoenix Purple. It can run continuously, on every pull..…
-
Apple Caps Open Bug-Bounty Reports After Surge in Unvalidated AI Findings
Apple is limiting some bug-bounty submissions after unvalidated AI findings increased the volume of reports in its review queue. Introduced in June, the restriction limits how many vulnerability reports each researcher can keep open at once. Researchers who reach the undisclosed cap reportedly face a 30-day wait before filing again, although they may request capacity…
-
Hackers run khunt post-exploitation toolkit from Oracle database
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-run-khunt-post-exploitation-toolkit-from-oracle-database/
-
CrowdStrike Warns AI Adoption Is Creating ‘Underdefended’ Attack Surfaces
CrowdStrike warns that AI adoption, rapid vulnerability exploitation, cloud attacks, and malicious npm packages are creating new enterprise security risks. The post CrowdStrike Warns AI Adoption Is Creating ‘Underdefended’ Attack Surfaces appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-crowdstrike-ai-underdefended-attack-surfaces/
-
COLDCARD security audit phishing attack installs remote access tool
A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/coldcard-security-audit-phishing-attack-installs-remote-access-tool/
-
U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The first issue added to the catalog, tracked as CVE-2026-9198, is a critical issue in IBM…
-
What Gold Eagle Validates, and What Your Organization Still Has to Own (July 2026)
Tags: ai, business, compliance, data, finance, framework, government, intelligence, open-source, update, vulnerabilityWhat Gold Eagle Validates, and What Your Organization Still Has to Own (July 2026) The federal government just stood up a clearinghouse to find and validate vulnerabilities faster, with AI doing the finding. That is not the same thing as a clearinghouse that owns the consequence when a patch does not land in time. Key…
-
OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root
OVSwrap is a 13-year-old Linux kernel flaw that lets local users gain root privileges on most distributions using Open vSwitch. Security researcher Asim Manizada disclosed OVSwrap (CVE-2026-64531, CVSS score of 7.8), a local privilege escalation vulnerability in the Linux kernel’s Open vSwitch datapath that lets an ordinary user become root on a wide range of…
-
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-langflow-n-central-apache-tomcat-flaws/
-
Arctic Wolf gibt CyberReadiness-Accelerator für Partner bekannt
Arctic Wolf gibt die Verfügbarkeit des <> bekannt. Das neue, partnergeführte Programm unterstützt Unternehmen dabei, Cyberrisiken besser zu verstehen und ihre Widerstandsfähigkeit in einer zunehmend von KI beschleunigten Bedrohungslandschaft zu stärken. Trotz Vulnerability- und Patch-Management bleiben Unternehmen unbekannten Risiken durch blinde Flecken innerhalb ihrer Angriffsfläche ausgesetzt, Tendenz steigend. Laut dem weltweiten Verizon-2026-Data-Breach- […] First seen…
-
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django.The three most serious: An unauthenticated flaw in Veeam’s console that hands over a managed agent’s credentials, rated 9.5 A cross-tenant flaw in HashiCorp’s MCP server that lets one user’s Terraform token be reused for…
-
Hackers Smuggle Post-Exploitation Toolkit Into Oracle Database Via Classic SQL Injection Flaw
A SQL injection vulnerability that many organisations might consider a decades-old, well-understood threat has been used as the entry point for a far more sophisticated attack, after threat actors were caught planting a custom-built, database-resident toolkit inside an Oracle database. Security firm Huntress said it was alerted to suspicious activity on an endpoint hosting an…
-
Microsoft Paid Record $20 Million in Bug Bounties to 562 Security Researchers Worldwide
Microsoft’s Bug Bounty Program awarded over $20 million to 562 security researchers this year, marking the highest total payout and the largest number of recognized researchers in the program’s history. Contributors hailed from 64 countries, highlighting the global nature of coordinated vulnerability disclosure efforts that help protect Microsoft customers worldwide. This represents significant growth over…
-
OVSwrap Open vSwitch Flaw Lets Unprivileged Linux Users Gain Root Access
A recently disclosed Linux local privilege-escalation vulnerability, tracked as CVE-2026-64531 and referred to as OVSwrap, affects the kernel’s Open vSwitch (OVS) implementation. This vulnerability could allow unprivileged local users to gain root-level access on affected systems. Researcher Asim Viladi Oglu Manizada reported this issue on July 28 after coordinating with the Linux kernel security team…
-
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
A memory corruption flaw in the Linux kernel’s Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds.The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclosed by…
-
Code review used to be the only way to catch these bugs
An automated system called NOVA read the source code of 3,915 open-source projects over two months and came back with 14,090 vulnerabilities, each one confirmed through the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/05/code-review-ai-vulnerability-discovery/
-
15 TP-Link Omada Flaws Exploit Zero-Touch Provisioning to Hijack Devices and Infiltrate Networks
Security researchers have disclosed 15 vulnerabilities in TP-Link’s Omada zero-touch provisioning (ZTP) ecosystem, which can be exploited to hijack devices, compromise controllers, expose credentials, and create access points into internal networks. The research, titled >>Zero Day Provisioning,<< was presented at Black Hat USA 2026 and focuses on weaknesses in the trust relationships that enable Omada…
-
15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic
TP-Link prints the serial number of an Omada router on its packaging and on a label attached to the device. Those numbers run in sequence, and feeding a guessed one to the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/05/forescout-tp-link-omada-vulnerabilities/
-
TP-Link Zero-Touch Provisioning Flaws Could Expose Enterprise Networks, Warns Forescout
Forescout Vedere Labs research has uncovered 15 previously unknown vulnerabilities affecting TP-Link’s Omada Zero-Touch Provisioning (ZTP) ecosystem, warning that weaknesses in automated device deployment could allow attackers to compromise not just individual devices, but the management infrastructure responsible for entire networks. The research highlights an emerging security challenge as organisations increasingly rely on Zero-Touch Provisioning…
-
Critical Veeam ONE Flaw Lets Unauthenticated Attackers Execute Code Remotely
Veeam has issued security updates to address multiple vulnerabilities in Veeam ONE, including a critical flaw that could enable an unauthenticated remote attacker to execute arbitrary code on an affected agent host. This issue, identified as CVE-2026-64633, has received the highest CVSS v4.0 score of 10.0, indicating it is the most severe vulnerability addressed in…
-
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, injection, kev, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.The list of vulnerabilities is as follows – CVE-2026-9198 (CVSS score: 9.8) – A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full…
-
Snyk Brings Evo Continuous Offensive Security to General Availability at Black Hat
Snyk brought Evo Continuous Offensive Security to general availability at Black Hat USA 2026, adding an autonomous, AI-powered penetration testing capability that runs continuously rather than on a once- or twice-a-year schedule. The company said Evo COS is designed to find architectural flaws and business-logic vulnerabilities that traditional scanners can miss. It uses application context..…
-
7-Zip Default Setting Lets Extracted Files Bypass Windows SmartScreen
7-Zip’s default configuration allows files extracted from internet-delivered archives to shed the Mark of the Web (MotW), meaning Windows SmartScreen never runs its reputation check and unsigned payloads can execute without a “Windows protected your PC” warning. That behavior, long treated as a red-team trick, is now formally recognized and tracked in multiple 7-Zip vulnerabilities,…
-
Django Flaws Let Attackers Trigger RCE, SSRF, DoS, and XSS Attacks
The Django project has released security updates, specifically Django 6.0.8 and Django 5.2.17, to address four vulnerabilities that could lead to server-side request forgery (SSRF), arbitrary file writes with potential for remote code execution (RCE), denial-of-service (DoS), and stored cross-site scripting (XSS) attacks. An advisory posted by Natalia Bidart on August 4, 2026, urges all…
-
Cyberrisiken schneller eindämmen: Qualys erkennt Schwachstellen in Minuten
Tags: vulnerabilityFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/cyberrisiken-eindaemmung-schwachstellen-2026
-
TP-Link patches Omada ZTP flaws allowing hackers to breach networks
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/tp-link-patches-omada-ztp-flaws-allowing-hackers-to-breach-networks/
-
Hackers steal over $130M by exploiting bug in offline hardware wallets
A security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $130 million, according to blockchain-monitoring firms. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/
-
Hackers steal over $130 million by exploiting bug in offline hardware wallets
A security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $130 million, according to blockchain monitoring firms. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/
-
Prolific ransomware group behind SonicWall zero-day attacks
INC ransomware wasn’t the first group to exploit the zero-days, but it’s been the most assertive and effective in chaining both vulnerabilities to steal and encrypt data for extortion. First seen on cyberscoop.com Jump to article: cyberscoop.com/inc-ransomware-sonicwall-zero-day-attacks/
-
Six Flowise Vulnerabilities Enable Remote Code Execution on AI Workflow Servers
Six newly disclosed vulnerabilities in Flowise, a popular open”‘source platform for building AI agents and LLM workflows, allow unauthenticated and low”‘privileged attackers to achieve remote code execution (RCE) on self”‘hosted and cloud AI workflow servers running vulnerable versions. These flaws collectively expose organizations to full server compromise, data exfiltration, and AI pipeline manipulation if instances…

