Researchers have disclosed several vulnerabilities affecting WolfSSL, GeoVision, and VTK-DICOM. The issues include improper input validation and integer underflow in WolfSSL, and a range of problems in GeoVision such as memory corruption, OS command injection, buffer overflows, and privilege escalation. These vulnerabilities have been addressed by the respective vendors.

Multiple vulnerabilities have been identified and patched in WolfSSL, GeoVision, and VTK-DICOM, according to a recent disclosure by Cisco Talos. The vulnerabilities, discovered by the Talos Vulnerability Discovery & Research team, have all been addressed by their respective vendors in accordance with Cisco's disclosure policy.
WolfSSL, an open-source product providing lightweight and embedded security solutions for secure data transfer, was found to have three vulnerabilities. Ankur Tyagi of Cisco Talos discovered two improper input validation flaws, tracked as TALOS-2026-2409 (CVE-2026-28739) and TALOS-2026-2410 (CVE-2026-25106). Additionally, an integer underflow vulnerability, TALOS-2026-2408 (CVE-2026-33091), was also identified.
GeoVision, a company specializing in security technologies including cameras, monitoring solutions, access control, and machine identification, had the largest number of reported issues. Philippe Laulheret of Cisco Talos uncovered fourteen advisories covering a total of 37 CVEs across GeoVision products. These include memory corruption vulnerabilities (TALOS-2026-2411, CVE-2026-12488), multiple OS command injection vulnerabilities (TALOS-2026-2379 covering CVE-2026-12486, CVE-2026-12849, CVE-2026-12850, CVE-2026-12851, and TALOS-2025-2326 covering CVE-2026-42364), and several buffer overflow vulnerabilities (TALOS-2026-2377 covering CVE-2026-12485, CVE-2026-12846, CVE-2026-12847, CVE-2026-12848).
Further GeoVision vulnerabilities include stack overflow issues (TALOS-2026-2369 for CVE-2026-42370, and TALOS-2026-2333 for CVE-2026-7372, CVE-2026-42369), and privilege escalation vulnerabilities (TALOS-2026-2329 for CVE-2026-42368, and TALOS-2026-2328 for CVE-2026-42367). Reflected cross-site scripting (XSS) vulnerabilities were also found (TALOS-2026-2327 covering CVE-2026-7371, CVE-2026-42366).
Other issues in GeoVision products include a guessable session cookie vulnerability (TALOS-2025-2332, CVE-2026-42365) and an insufficient encryption vulnerability (TALOS-2025-2322, CVE-2026-7161). A series of stack-based buffer overflow vulnerabilities were grouped under TALOS-2026-2375 (CVE-2026-57273 through CVE-2026-57278). Out-of-bounds read vulnerabilities were identified under TALOS-2026-2373 (CVE-2026-13131, CVE-2026-13132, and CVE-2026-57264 through CVE-2026-57272). Finally, a lack of authentication vulnerability was reported as TALOS-2026-2370 (CVE-2026-13125).
The Virtualization Toolkit (VTK), an open-source software solution for scientific data handling and 3D rendering, also had a vulnerability in its DICOM API. This API allows VTK users to parse Digital Imaging and Communications in Medicine (DICOM) medical data. Emmanuel Tacheau of Cisco Talos discovered a heap-based buffer overflow vulnerability, identified as TALOS-2026-2366 (CVE-2026-22879), in VTK-DICOM.
Users of these products are advised to ensure their systems are updated with the latest patches provided by the respective vendors. Snort coverage to detect exploitation attempts for these vulnerabilities is available through the latest rule sets from Snort.org, and additional vulnerability advisories are posted on Talos Intelligence's website.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a