Tag: vulnerability
-
Small Language Models ‘Antares” – Cisco bietet KI-Schwachstellen-Analyse für weniger als einen Dollar
First seen on security-insider.de Jump to article: www.security-insider.de/cisco-antares-slms-schwachstellen-quellcode-a-77d83f36c434daaa67b19b1e04c5e76b/
-
TP-Link TL-WR940N Router Flaw Lets Unauthenticated Attackers Execute Code Remotely
TP-Link has announced a high-severity security vulnerability in its TL-WR940N v6 wireless router that could allow an unauthenticated remote attacker to execute arbitrary code and potentially take full control of the affected device. This vulnerability is tracked as CVE-2026-12935 and has a CVSS v4.0 score of 8.7, categorized as high. TP-Link TL-WR940N Router Flaw According…
-
Künstliche Intelligenz ist fester Bestandteil moderner Cyberangriffe
Cyberangreifer operationalisieren künstliche Intelligenz nicht nur, um Schwachstellen innerhalb von Stunden auszunutzen, sondern auch, um KI, die in Unternehmen eingesetzt wird, anzugreifen. Zudem nutzen Angreifer sie auch, um Angriffe entlang der Software-Lieferkette zu skalieren. Dies verdeutlicht der aktuelle <> von Crowdstrike. So nutzten China-nahe Angreifer innerhalb von 24 Stunden nach der Veröffentlichung eines […] First seen…
-
Risiken der KI-Lieferkette
Die jüngste Offenlegung von kritischen Schwachstellen in großen KI-Repositorien wie Hugging Face verdeutlicht ein grundlegendes Problem. Ausgerechnet jene Plattformen, auf die Unternehmen bei der Entwicklung KI-gestützter Anwendungen setzen, entwickeln sich zunehmend zu einem Einfallstor für systemische Risiken. Mit dem Übergang zu agentenbasierten Systemen gewinnt dieses Problem an Dringlichkeit. Von Shadow-IT zu Shadow-AI Über Jahre […]…
-
KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)
A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web apps, may allow attackers … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/03/kindarails2shell-cve-2026-66066-vulnerability/
-
The OpenAI Hack Shows the Genie Is Out of the Bottle
This essay originally appeared in Foreign Policy. Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild. OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it…
-
30 days with Claude Mythos Preview: How Tenable adapted our security program, and why yours is next
Tags: ai, api, attack, business, control, cybersecurity, data, data-breach, endpoint, exploit, flaw, injection, LLM, remote-code-execution, risk, service, threat, tool, update, vulnerabilityTenable spent 30 days running frontier AI models against our own code. It didn’t just find bugs, it proved they’re real, with reproducible exploits. That fundamentally changes code security from ranking potential code defects to a much higher signal focused on the findings that matter. Read on to learn how it reshaped our security team’s…
-
Critical N-able N-central Vulnerability Under Active Exploitation as Hotfix Lands
N-able has confirmed that a critical vulnerability in N-central, its flagship remote monitoring and management (RMM) platform, is being actively exploited in the wild, prompting an emergency hotfix and urgent calls for managed service providers (MSPs) to patch immediately. The flaw, disclosed by N-able on 12 August, affects all currently supported versions of N-central, including…
-
Coldcard-Wallets: Massenhafte Bitcoin-Diebstähle erschüttern die Kryptobranche
Bitcoins im Wert von mehr als 70 Millionen Euro haben zuletzt unverhofft die Besitzer gewechselt. Grund ist eine Schwachstelle in Hardware-Wallets von Coinkite. First seen on golem.de Jump to article: www.golem.de/news/coldcard-wallets-massenhafte-bitcoin-diebstaehle-erschuettern-die-kryptobranche-2608-211532.html
-
Elastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM support
Attackers reaching for kernel access on a Windows machine bring a driver Microsoft already trusts. It is signed, it loads, and it carries a known flaw. That flaw gives them … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/03/elastic-defend-vulnerable-driver-detection/
-
Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing
Ruby on Rails fixed a critical vulnerability that could let unauthenticated attackers read files and achieve remote code execution. Ruby on Rails has patched CVE-2026-66066, a critical vulnerability (CVSS score of 9.5) that could allow unauthenticated attackers to read arbitrary files from vulnerable servers. In the default configuration, applications that generate image variants may expose…
-
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Three high-severity security flaws have been disclosed in Hugging Face’s Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk.”These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the First seen…
-
AI is now both the weapon and the target in cyberattacks
AI generates 2.5 signals for every human-triggered signal CrowdStrike has to assess. Meanwhile, attackers are using AI to weaponize vulnerabilities faster than companies can patch them. First seen on cyberscoop.com Jump to article: cyberscoop.com/crowdstrike-annual-threat-hunting-report-2026/
-
Critical N-able N-central Flaw Actively Exploited to Gain God-Mode Access to MSP Networks
Tags: access, authentication, control, cve, cyber, exploit, flaw, monitoring, msp, network, vulnerabilityN-able has issued an urgent hotfix to address a critical authentication-bypass vulnerability in its N-central remote monitoring and management (RMM) platform, following confirmation of active exploitation. This vulnerability, tracked as CVE-2026-18577, affects N-central servers running earlier than version 2026.3.1.7. It allows a remote, unauthenticated attacker to take over accounts and gain administrative control of the…
-
Metasploit Exploit Targets Critical Ruby on Rails Active Storage RCE Flaw
A new Metasploit Framework module has been submitted for review, targeting the critical Ruby on Rails Active Storage vulnerability, tracked as CVE-2026-66066. This submission poses an increased risk to applications that utilize the Vips image-processing backend. The proposed module is named `exploit/multi/http/rails_activestorage_vips_rce` and was introduced in Rapid7 Metasploit Framework pull request #21733 by contributor jburgess-r7.…
-
CosmosEscape: Schwachstelle gab Zugriff auf jede Azure-Cosmos-DB-Datenbank
Eine Schwachstellenkette in Azure Cosmos DB hätte Angreifern Lese- und Schreibzugriff auf Datenbanken des Cloud-Dienstes verschaffen können. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/schwachstelle-azure
-
Hackers Exploit Critical Arista VeloCloud Flaw to Execute OS Commands
Arista Networks has issued a warning about attackers actively exploiting CVE-2026-16812, a critical unauthenticated OS command injection vulnerability in on-premises VeloCloud Orchestrator (VCO) deployments. This flaw carries a CVSS v3.1 and v4.0 severity score of 10.0, allowing a remote attacker with network access to the VCO web interface to access privileged internal functions and potentially…
-
Coldcard Firmware Flaw Lets Hackers Steal $70 Million in Bitcoin From 1,196 Addresses
Blockchain analysts have linked a rapid series of Bitcoin wallet drains to a reported vulnerability in Coldcard firmware. A total of 1,196 addresses lost a combined 1,082.65 BTC, valued at approximately $70.2 million, in just 41 minutes on July 30, 2026. Galaxy Research stated that its transaction-flow analysis was based on a pattern initially identified…
-
COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/coldcard-wallet-rng-flaw-likely-linked-to-88-million-bitcoin-theft/
-
Security Affairs newsletter Round 588 by Pierluigi Paganini INTERNATIONAL EDITION
Tags: adobe, email, flaw, hacker, international, microsoft, russia, vulnerability, WeeklyReview, wifiA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens Adobe fixed a maximum-severity vulnerability flaw in…
-
Why CVE grading still matters for vulnerability management
First seen on scworld.com Jump to article: www.scworld.com/native/why-cve-grading-still-matters-for-vulnerability-management
-
Rails patches critical Active Storage flaw with RCE potential
A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/rails-patches-critical-active-storage-flaw-with-rce-potential/
-
Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic
Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute…
-
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution.The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system.It has been described as a case of incorrect authorization that could result in…
-
Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
A Chinese-speaking threat actor has been using DeepSeek’s AI models to orchestrate cyber-attacks targeting Asian organizations First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/chinese-hacker-deepseek-ai/
-
Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical
Google Chrome 151 patches 370 security flaws, including seven Critical vulnerabilities. Users on Windows, macOS, and Linux should update now. The post Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-chrome-151-370-vulnerabilities/
-
AI-Enabled Data Breaches Cost Organizations $6 Million on Average
IBM found AI-enabled breaches cost organizations $6 million on average, exposing gaps in vulnerability management, access controls, and AI governance. The post IBM: AI-Enabled Data Breaches Cost Organizations $6 Million on Average appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-ibm-ai-enabled-data-breach-costs/
-
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hacker-uses-deepseek-ai-to-autonomously-attack-vulnerable-servers/
-
Google AI Supercharges Chrome Security, Fixing 1,072 Bugs
Google says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching Google’s Chrome Security team published a detailed account of how AI models have transformed their vulnerability management pipeline, and the headline figure is difficult to dismiss: in the last two Chrome releases alone, the team…
-
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
An academic study has disclosed a “widespread class” of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user’s network session.The findings have been released by a group of researchers from Singapore’s Nanyang Technological University…

