Tag: vulnerability
-
Google AI Supercharges Chrome Security, Fixing 1,072 Bugs
Google says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching Google’s Chrome Security team published a detailed account of how AI models have transformed their vulnerability management pipeline, and the headline figure is difficult to dismiss: in the last two Chrome releases alone, the team…
-
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
An academic study has disclosed a “widespread class” of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user’s network session.The findings have been released by a group of researchers from Singapore’s Nanyang Technological University…
-
Critical JetBrains TeamCity Flaw Enables Unauthenticated Remote Code Execution
Tags: access, authentication, cve, cyber, data-breach, flaw, network, remote-code-execution, risk, vulnerabilityJetBrains has revealed a critical security vulnerability in TeamCity On-Premises that enables unauthenticated remote code execution (RCE) on affected servers. This poses a significant risk to CI/CD environments exposed over HTTP(S). The vulnerability, tracked as CVE-2026-63077, affects all supported versions of TeamCity On-Premises and allows attackers with network access to bypass authentication checks and execute…
-
Google Uses AI to Fix 1,072 Chrome Security Vulnerabilities
Google has announced that its AI-assisted security workflows have helped Chrome fix 10,721 security vulnerabilities across Chrome Stable milestones 149 and 150. This number exceeds the total number of bugs patched across the previous 23 milestones combined. In a new report, the Chrome Security Team detailed how large language models are integrated throughout the vulnerability…
-
CVE-2026-20316 Zero-Day Actively Exploited, Cisco Releases Fix
Cisco has released security updates for an actively exploited zero-day vulnerability, CVE-2026-20316, affecting Cisco Secure FMC (Secure Firewall Management Center) software. The flaw, disclosed on July 29, 2026, allows a remote, unauthenticated attacker to log in to vulnerable systems using a built-in low-privilege account and access sensitive data. First seen on thecyberexpress.com Jump to article:…
-
47 Tage Gültigkeit: Wenn Zertifikate die Schwachstellen der App-Bereitstellung entlarven
Tags: vulnerabilityFür Organisationen, die gar hunderte Zertifikate noch von Hand verwalten, bedeutet das: ein Dauerfeuer an Erneuerungsvorgängen, das handisch kaum zu bewältigen ist. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/47-tage-gueltigkeit-wenn-zertifikate-die-schwachstellen-der-app-bereitstellung-entlarven/a45962/
-
PHP Patches 3 Security Flaws Enabling SQL Injection, Memory Corruption and DoS Attacks
PHP maintainers have released security updates to address three vulnerabilities affecting the PostgreSQL, BCMath, and Phar extensions. These vulnerabilities could potentially lead to SQL injection attacks, out-of-bounds memory writes, and denial-of-service attacks in vulnerable applications. The issues impact several actively maintained PHP release branches and have been resolved in versions PHP 8.2.338.2, 8.3.338.3, 8.4.248.4, and…
-
CosmosEscape Vulnerability Enables Full Takeover of Azure Cosmos DB Databases
A critical vulnerability chain in Azure Cosmos DB, named CosmosEscape, allowed attackers to gain full read and write access to every Cosmos DB database, including potentially those managed internally by Microsoft. The issue specifically affected the service’s Gremlin API. It exposed a cross-tenant attack path that could bypass customer network isolation controls. CosmosEscape Vulnerability According…
-
Companies push AI, sysadmins keep it on a short leash
In 2024, sysadmins expected AI to automate patch management optimization, vulnerability prioritization, infrastructure monitoring, and incident response within two years. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/31/action1-sysadmins-ai-expectations-report/
-
JetBrains warns of critical TeamCity remote code execution flaw
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/jetbrains-warns-of-critical-teamcity-remote-code-execution-flaw/
-
VMware fixes three critical flaws allowing auth bypass, VM escapes
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/
-
Google says AI helped Chrome fix 1,072 security bugs in two releases
Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser’s two most recent releases as it expands its use of AI. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/google/google-says-ai-helped-chrome-fix-1-072-security-bugs-in-two-releases/
-
Cybercriminals Are Leveraging Autonomous AI Offensive Security Agents
Resecurity warns AI offensive agents are lowering hacking barriers, fueling an AI-driven race between attackers and defenders. Resecurity analyzed how autonomous offensive security agents such as T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, and Nebula lower the barriers to vulnerability identification and exploitation. The analysis also explores why AI is being repurposed for real attacks and…
-
Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay
Cursor has patched a high-severity Windows vulnerability that allowed malicious Git repositories to execute code, highlighting security risks in AI coding environments. The post Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-cursor-git-code-execution-vulnerability-cve-2026-63093/
-
OpenAI models used Artifactory zero-days to escape to the internet
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/openai-models-used-artifactory-zero-days-to-escape-to-the-internet/
-
Many More Bugs But Exploits Stay Steady
Data Shows Hackers Not Using More Exploits, But They Are Exploiting Flaws Quicker. The coming of the vulnocalypse – our artificial intelligence-instigated moment of drastically accelerating flaw discovery – has yet to be matched with an equivalent rise in exploits, shows analysis of common vulnerabilities and exposure data from the first half of this year.…
-
vBulletin fixes critical pre-auth RCE flaw with public exploit
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/vbulletin-fixes-critical-pre-auth-rce-flaw-with-public-exploit/
-
‘Certighost’ Flaw Haunts Microsoft Active Directory Certificates
Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/certighost-flaw-microsoft-active-directory-certificates
-
AI-assisted security tools are finding more bugs, but the threat level has not changed
Analysis from vulnerability intelligence firm VulnCheck shows AI-discovered flaws aren’t being exploited any faster than traditional ones. First seen on cyberscoop.com Jump to article: cyberscoop.com/ai-assisted-security-tools-are-finding-more-bugs-but-the-threat-level-has-not-changed/
-
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/over-24-000-exposed-server-bmcs-leak-password-hash-via-decades-old-flaw/
-
JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover
JetBrains patched a critical TeamCity flaw (CVE-2026-63077) enabling unauthenticated code execution on affected on-premise servers. JetBrains has released security updates for TeamCity On-Premises after discovering a critical vulnerability, tracked as CVE-2026-63077 (CVSS score of 9.8). The flaw could allow unauthenticated attackers to execute arbitrary commands on affected servers. All on-premise versions are impacted, while TeamCity…
-
JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)
JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/28/teamcity-rce-cve-2026-63077-fixed/
-
Critical TeamCity Flaw Lets Unauthenticated Attackers Execute System Commands
JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077. This vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands on affected servers. The issue impacts every version of the self-hosted continuous integration and continuous delivery platform, making it urgent for organizations that expose TeamCity instances over HTTP or HTTPS to…
-
AI-Discovered Linux Kernel Zero-Day Enables Root Privilege Escalation
A researcher recently disclosed an AI-assisted Linux kernel zero-day vulnerability, tracked as CVE-2026-53264, which allows local privilege escalation to root on affected systems. This flaw is found in the Linux packet scheduling subsystem (net/sched) and arises from a use-after-free condition involving traffic-control action objects. AI-Discovered Linux Kernel Zero-Day Star Labs researcher developed a reliable exploit…
-
Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness.The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved First seen…
-
Arista VeloCloud: Maximale Schwachstelle wird aktiv ausgenutzt
Eine kritische Schwachstelle in Arista VeloCloud Orchestrator wird aktiv ausgenutzt. CISA setzt die Lücke mit Höchstwert 10.0 auf die KEV-Liste. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/arista-velocloud-schwachstelle
-
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution.The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already…

