Tag: vulnerability
-
U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the KeV catalog: CVE-2025-68686 is an…
-
LegacyHive Exploit Abuses Windows Profile Loading to Hijack User Registry Hives
LegacyHive is a newly discovered proof-of-concept (PoC) for Windows that exploits profile initialization and offline registry hive manipulation to redirect user-level registry paths, potentially allowing access to resources associated with another account. This technique was published by the Nightmare-Eclipse disclosure actor shortly after Microsoft’s July 2026 Patch Tuesday. Unlike traditional software vulnerabilities, LegacyHive chains legitimate…
-
Eine Million offengelegte Datensätze: Was der Merkur-Datenleak über API-Sicherheit verrät
Bild: magnific.com/rajibcpcs1986 Ein massiver Sicherheitsvorfall bei Plattformen der bekannten Glücksspiel-Marke zeigt erneut die kritischen Schwachstellen moderner API-Architekturen auf. Über eine Million Datensätze darunter hochsensible KYC-Dokumente, Finanztransaktionen und Spielverhaltensprofile waren über ungesicherte Schnittstellen frei im Netz abrufbar. Der Fall illustriert eindringlich, warum API-Sicherheit längst zur Chefsache werden muss und welche Lehren IT-Verantwortliche daraus… First seen…
-
Multiple FFmpeg Flaws Allow Arbitrary Memory Corruption via Malicious Videos
Multiple high-severity vulnerabilities in FFmpeg could allow attackers to corrupt memory, disclose process data, or exhaust system resources. This can happen if users or automated media-processing services are manipulated into handling specially crafted video, audio, image, or subtitle files. The vulnerabilities affect FFmpeg versions up to 8.1.28. Organizations operating transcoding pipelines, media upload platforms, streaming…
-
Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness.The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved First seen…
-
Apple iOS 26.6 Update Fixes Flaws Allowing Kernel-Level Code Execution and Root Access
Apple has released iOS 26.6 and iPadOS 26.6, a significant security update that addresses numerous vulnerabilities across core operating system components, media frameworks, WebKit, wireless services, and application frameworks. Released on July 27, 2026, this update is available for iPhone 11 and later models, as well as supported iPads. It should be prioritized for deployment…
-
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild.The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution.”VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue First…
-
Hackers target US firms in FastJson RCE zero-day attacks
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/
-
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/
-
New Certighost PoC exploit lets attackers hijack Windows domains
A proof-of-concept exploit for “Certighost,” a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-certighost-poc-exploit-lets-attackers-hijack-windows-domains/
-
‘Confused Deputy’ Flaws Persist in Google Cloud, Microsoft Azure
This category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers’ access controls. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/confused-deputy-flaws-google-cloud-microsoft-azure
-
Microsoft unveils MAI1-Flash, promises cybersecurity AI at half the cost
Microsoft has introduced MAI-Cyber-1-Flash, a security-focused AI model built into MDASH, the company’s multi-agent vulnerability identification and remediation system. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/27/microsoft-mai-cyber-1-flash-ai-model/
-
Using LLMs to Find & Prioritize Vulnerabilities Is No Easy Task
The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/finding-and-prioritizing-vulnerabilities-no-easy-task
-
Using LLMs to Find & Prioritize Vulnerabilities Is No Easy Task
The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/finding-and-prioritizing-vulnerabilities-no-easy-task
-
Anyone With a Browser Could Access 700,000 Vatican Prayer App Accounts
A critical access control vulnerability in the Vatican’s official “Click to Pray” platform has exposed the personal data of more than 700,000 users, highlighting once again how basic web security misconfigurations continue to put large-scale user bases at risk. The service, operated by the Pope’s Worldwide Prayer Network, is widely used across the globe to…
-
PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)
Security researchers who discovered and reported CVE-2026-54121 (aka >>Certighost<<), a critical privilege elevation vulnerability in Active Directory Certificate … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/27/certighost-cve-2026-54121-poc-exploit-released/
-
Claude Opus 5 Finds Software Vulnerabilities While Blocking Exploit Generation
Claude Opus 5, the latest flagship AI model from Anthropic, represents a significant shift in how advanced systems can be safely utilized in cybersecurity. This model can proactively identify software vulnerabilities while specifically preventing the generation of exploits and offensive usage. Announced on July 24, 2026, Opus 5 is positioned as a high-end, general-purpose intelligence…
-
Two Old Oj Flaws Chained to Trigger GitLab Remote Code Execution
A newly disclosed GitLab vulnerability has revealed how two long-standing memory-safety flaws in the widely used Ruby JSON parsing library, Oj, can be combined to achieve remote code execution on default GitLab installations. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/gitlab-vulnerability-oj-parser-rce/
-
Europol Launches Project COMPASS to Disrupt ‘The Com’ Cybercrime Network Targeting Minors
Europol has launched Project COMPASS, a coordinated transnational initiative aimed at disrupting >>The Com,<< a highly dangerous cybercrime and nihilistic extremist network that systematically targets minors and vulnerable young people across digital platforms. The Com operates as a sprawling transnational virtual network (TVN), utilizing social media, messaging apps, music platforms, and online games to recruit,…
-
vBulletin Pre-Auth RCE Flaw Allows Remote PHP Code Execution
A critical pre-authentication remote code execution vulnerability in vBulletin, tracked as CVE-2026-61511, could allow unauthenticated attackers to execute arbitrary PHP code on vulnerable forum servers. This issue affects vBulletin versions 6.2.1 and earlier, as well as 6.1.6 and earlier, according to a July 27, 2026, disclosure from SSD Secure Disclosure. If exploited successfully, this vulnerability…
-
Windows WalletService Flaw Lets Standard Users Gain SYSTEM Privileges
Microsoft Windows WalletService is affected by a local privilege escalation vulnerability tracked as CVE-2026-49176. This flaw could allow a standard authenticated user to obtain SYSTEM-level privileges. The vulnerability arises from WalletService’s handling of user-controlled file paths during initialization. An attacker can exploit this by redirecting the service to a maliciously crafted Extensible Storage Engine (ESE)…
-
95 % der Sicherheitsteams entdecken schwerwiegende oder kritische Schwachstellen außerhalb geplanter Tests
Ganze 79 % ergreifen keine Maßnahmen aufgrund KI-generierter Ergebnisse ohne menschliche Validierung. Nur 15 % bezeichnen ihre Programme für Sicherheitstests und -validierung als kontinuierlich. Synack, Anbieter des ersten KI-gestützten, kontinuierlichen Penetrationstests für Unternehmen, hat die Studie »The State of Continuous Security Validation« veröffentlicht [1]. Sie basiert auf einer Befragung von Führungskräften und Fachleuten im… First…
-
Angreifer konnten verdeckte KI-Agenten in ChatGPT einschleusen
Zenity Labs entdeckte die Schwachstelle AgentForger in ChatGPT Workspace Agents. OpenAI hat den Fehler kurz nach der Meldung behoben. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ki-agenten-in-chatgpt-einschleusen
-
GitLab RCE Flaws Allow Attackers to Execute Commands via Malicious Jupyter Notebooks
A critical remote code execution (RCE) vulnerability chain in GitLab’s Jupyter Notebook diff renderer. This issue is rooted in two long-standing memory safety vulnerabilities within the Oj Ruby JSON parser. The vulnerabilities impact both GitLab Community Edition and Enterprise Edition releases from version 15.2.0 through 19.0.1. They allow an authenticated project member to execute commands…
-
Inside the violent online network coercing children to self-harm – podcast
This year the FBI issued urgent warnings to parents about 764, a global online community where children are manipulated into acts of violence.<br><br>With hundreds of investigations under way worldwide, including in Australia, 764 and groups like it are accused of using coercion to turn vulnerable minors into victims and, in some cases, predators.<strong>Nour Haydar</strong> speaks…
-
macOS Gatekeeper vulnerability allows app replacement
First seen on scworld.com Jump to article: www.scworld.com/brief/macos-gatekeeper-vulnerability-allows-app-replacement
-
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process.Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain requires…
-
Russian Espionage Hackers Hit Zimbra With Half-Click Attacks
Tags: attack, cyberespionage, cybersecurity, data, email, espionage, hacker, malicious, russia, update, vulnerabilityViewing Malicious Email in Vulnerable Webmail Client Triggers Data-Stealing Attack. Russian cyberespionage hackers are targeting a vulnerability in Zimbra Collaboration Suite – a patch is available – that enables them to execute a malicious, data- and email-stealing script simply if a user of a vulnerable client opens their email, warn Western cybersecurity agencies. First seen…
-
Zero-day flaw in Check Point SmartConsole is under exploitation
Researchers warned the vulnerability offers an attacker the ability to make key changes to security configurations. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/zero-day-flaw-check-point-smartconsole-exploitation/826149/

