LIVE · cybersecurity feed
Live wire
CVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

patch news

306 stories · page 4 of 7
patch

Brinqa acquires PlexTrac to bring validated remediation to exposure management

Brinqa has announced its acquisition of PlexTrac, a move that integrates validated remediation capabilities into its exposure management platform. This acquisition aims to provide enterprises with a comprehensive solution for identifying, prioritizing, and verifying the resolution of security exposures, effectively closing the Cyber Threat Exposure Management (CTEM) loop.

vulnerability

943 Patches Rolled Out With Oracle’s August 2026 Security Update

Oracle has released its August 2026 Critical Patch Update (CPU), which includes 943 security fixes addressing a wide array of vulnerabilities across its product portfolio. This extensive update resolves over 1,000 individual vulnerabilities, with a significant portion of these issues being remotely exploitable.

patch

Windows 11 24H2 Home and Pro reach end of support in 2 months

Microsoft has issued a reminder that Home and Pro editions of Windows 11 version 24H2 will reach their end-of-life for updates on October 13, 2026. After this date, devices running these specific editions will no longer receive monthly security or non-security preview updates, leaving them vulnerable to new security threats.

patch

Prison for data analyst who tried to extort $2.5 million from his employer

A former data analyst for Brightly Software, Cameron Curry, has been sentenced to 24 months in federal prison for attempting to extort $2.5 million from his employer after learning his contract would not be renewed. Curry, 27, of Charlotte, North Carolina, was convicted on six counts of transmitting interstate communications with intent to extort. In addition to his prison sentence, he will…

vulnerabilitycritical

Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs

Oracle has released its August 2026 Critical Security Patch Update (CSPU), addressing 925 unique Common Vulnerabilities and Exposures (CVEs) through 943 security updates across 23 of its product families. This update includes 154 critical severity patches, accounting for 16.3% of the total fixes.

CVE-2026-68820high

CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now

A critical use-after-free vulnerability, identified as CVE-2026-68820, in the Windows Ancillary Function Driver for WinSock (afd.sys) is currently under active exploitation and has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability allows a low-privilege local attacker to escalate privileges to SYSTEM without requiring user interaction.

ransomwarecritical

More than 200 victims of Medusa ransomware identified over the last year, CISA says

Federal cybersecurity agencies have identified over 200 new victims of the Medusa ransomware group in the past year, bringing the total confirmed victim count to more than 500 as of April 2026. This updated figure comes from an advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI, which was initially released in March 2025 and previously reported 300…

ransomware

Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics

The Medusa ransomware-as-a-service group has expanded its victim count to over 500 organizations, an increase of more than 200 since March 2025, according to an updated advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Department of Health and Human Services (HHS). The group, first identified in 2021, has also refined its tactics for initial…

phishinghigh

CISA gives feds 3 days to fix actively exploited Ray RCE bug

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for federal agencies to patch a critical vulnerability in the open-source Ray framework within three days. The flaw, identified as CVE-2025-62593, is actively being exploited and carries a CVSS v4 score of 9.4, indicating a severe risk of remote code execution (RCE).

patch

Apple plugs image-processing hole ripe for spyware abuse

Apple has issued a series of security updates for its iPhones, iPads, and Macs, addressing a critical image-processing vulnerability that security experts believe could be exploited for spyware delivery. The most significant fix, identified as CVE-2026-65346, is an integer-overflow bug found within Apple's ImageIO framework, which is responsible for parsing image files.

CVE-2026-19478critical

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

GitLab has issued patches for a critical code injection vulnerability, CVE-2026-19478, which could allow unauthenticated attackers to modify or delete public projects and user data. The flaw, rated with a CVSS score of 9.4, affects both GitLab Community Edition (CE) and Enterprise Edition (EE).

vulnerabilitycritical

GitLab Patches Critical Code Injection Vulnerability

GitLab has released a patch for a critical code injection vulnerability that could allow unauthenticated attackers to modify or delete user data and public projects. The flaw was described as critical, indicating a high potential impact and ease of exploitation.

breach

Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates

Apple has released security updates for macOS and iOS that address dozens of vulnerabilities in WebKit, the browser engine powering Safari and other applications. These updates are critical as the reported flaws could lead to a range of severe security issues, including application crashes, memory corruption, sensitive data leakage, sandbox escapes, and data exfiltration. Users are strongly…

ransomware

Weekly Update 517: Cyber Ransoms

A recent report indicates a complex and evolving landscape within the realm of cyber ransoms, highlighting a significant disconnect between the technical execution of attacks and the subsequent financial operations. The situation is characterized by a high volume of successful extortion attempts, often lacking traditional malware components, and a notable challenge for perpetrators in…

CVE-2026-19478critical

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

GitLab has issued security updates to address a critical vulnerability in its Community Edition (CE) and Enterprise Edition (EE) software. The flaw, identified as CVE-2026-19478 and rated with a CVSS score of 9.4, reportedly allows an unauthenticated attacker to remotely modify or delete public projects and associated user data under specific conditions.

vulnerability

Apple Patches iOS and macOS, (Mon, Aug 17th)

Apple has released significant security updates for its iOS/iPadOS and macOS operating systems, addressing a substantial number of vulnerabilities. The updates, released on Monday, August 17th, include iOS/iPadOS versions 26 and 18, and macOS version 26. This release follows a smaller macOS-specific update approximately two weeks prior that targeted a single screen-sharing vulnerability.

vulnerability

Microsoft blames AI for delayed Exchange update, can’t say when it will arrive

Microsoft has acknowledged a delay in the release of Cumulative Update 1 (CU1) for Exchange Server Subscription Edition (SE), attributing the setback to an increased volume of security vulnerabilities identified by artificial intelligence tools. The company’s Exchange team addressed customer inquiries in a post titled “Where is Exchange SE CU1 anyway?” published last Thursday, confirming that…

malware

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

A new information-stealing malware, dubbed AmnesiaStealer, is targeting macOS users through "ClickFix" campaigns, according to research from Jamf. The malware's notable capability is its "stream_module," which allows attackers to remotely control a victim's web browser through a hidden, headless instance, effectively hijacking authenticated sessions.

patch

APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2

A newly discovered espionage campaign, dubbed PATCHCORD, has been observed targeting Afghan telecommunications providers and critical infrastructure organizations in South Asia. Security researchers at Acronis identified a custom C/C++ backdoor, PATCHCORD, being delivered through highly specific lures, including fake VPN installers designed to impersonate legitimate tools from Afghan Telecom…

CVE-2026-58231critical

SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild

A critical vulnerability in SAP Commerce Cloud, identified as CVE-2026-58231, is being actively exploited in the wild just days after a patch was released. The flaw, which carries a maximum CVSS score of 10.0, allows for unauthenticated arbitrary code execution and compromise of internal components.

breach

GeoServer Zero-Day Is Already Being Probed. That’s the Problem

A newly disclosed zero-day vulnerability in GeoServer, an open-source geospatial platform, is already being actively probed by attackers, with no patch currently available. The flaw, publicly revealed on August 12, 2026, by a security researcher identified as q1uf3ng, allows for unauthorized SQL injection through the `jsonArrayContains` functionality. In specific configurations where GeoServer…

vulnerability

Max severity SAP Commerce Cloud flaw now targeted in attacks

A critical remote code execution vulnerability in SAP Commerce Cloud, identified as CVE-2026-58231, is reportedly being exploited in active attacks just three days after a patch was released. The flaw, which carries a maximum severity rating, affects the core Data Hub Adapter extension of the e-commerce platform, formerly known as SAP Hybris.

patch

Novel macOS Infostealer AmnesiaStealer Spread via ClickFix

A new macOS infostealer, dubbed AmnesiaStealer, is being distributed through social engineering attacks that trick users into executing malicious commands, according to research published by Jamf on August 13. The Rust-based malware employs a multi-stage infection process to harvest credentials, browser data, and live user sessions.

patch

AmnesiaStealer Gives Attackers Live Control of Victims’ macOS Browsers

Jamf Threat Labs researchers have uncovered AmnesiaStealer, a new Rust-based macOS infostealer that provides attackers with live, hidden control over a victim's web browser. The multi-stage malware, first observed on August 14, 2026, spreads through convincing fake GitHub download pages that employ the "ClickFix" technique.

vulnerability

Microsoft patches LegacyHive Windows zero-day vulnerability

Microsoft has issued security patches to address a Windows zero-day vulnerability, identified as "LegacyHive," which was publicly disclosed following the July 2026 Patch Tuesday. The vulnerability, now tracked as CVE-2026-62832, was patched as part of Microsoft's August Patch Tuesday updates.

CVE-2026-59310critical

Critical VMware vCenter RCE flaw exploited for reverse SSH access

A critical remote code execution (RCE) vulnerability in VMware vCenter Syslog Server, identified as CVE-2026-59310, is actively being exploited to establish persistent remote access through a reverse SSH tool. Broadcom, the vendor, confirmed the flaw on July 29 and released emergency patches, describing it as a directory traversal vulnerability that allows unauthenticated attackers with…

CVE-2026-71362

Adobe Commerce Bug Targeted Immediately After Disclosure

Exploitation attempts targeting a recently disclosed vulnerability in Adobe Commerce, identified as CVE-2026-71362, were observed almost immediately following the release of patches by Adobe. This rapid move from disclosure to active targeting highlights a recurring challenge in software security, where threat actors quickly weaponize newly public vulnerability information.

CVE-2026-55040critical

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)

Attackers are actively exploiting a critical vulnerability in Microsoft SharePoint, tracked as CVE-2026-55040, following the public release of proof-of-concept (PoC) exploit code. The flaw, which allows for authentication bypass and impersonation, was addressed by Microsoft in its July 2026 Patch Tuesday updates.

vulnerability

WordPress 7.0.4 Patches Remote Code Execution Vulnerability

WordPress has released version 7.0.4, which includes a patch for a remote code execution (RCE) vulnerability. The flaw reportedly allowed attackers with Author-level user permissions or higher to execute arbitrary code on affected systems. The vulnerability was exploitable through the use of malicious Postscript files.

vulnerability

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

Fortinet has released patches addressing authentication vulnerabilities in its FortiWeb Web Application Firewall (WAF) and FortiManager centralized management solution. The reported flaws could potentially enable unauthorized access, allowing attackers to log in using arbitrary usernames and passwords or to impersonate FortiGate appliances.

zero-day

Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’

A new Windows zero-day exploit, dubbed "ShieldBreak," has reportedly been released, allowing any user to elevate their privileges to System-level. The exploit was made public on a recent Patch Tuesday, a day typically associated with the release of security updates from Microsoft. This timing suggests the exploit was either intentionally released to coincide with a presumed patching cycle or…

breach

ICO Reprimands Criminal Records Office After 2023 Breach

The UK's Information Commissioner's Office (ICO) has issued a reprimand to the Criminal Records Office (ACRO) following a 2023 data breach that compromised the personal information of over 10,000 individuals. The ICO's investigation identified significant security failures, including inadequate patch management and insufficient security monitoring, as contributing factors to the incident.

CVE-2026-20349high

Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)

Cisco has confirmed that a high-severity vulnerability, identified as CVE-2026-20349, is actively being exploited to cause denial-of-service (DoS) conditions on its firewall products. The company's Product Security Incident Response Team (PSIRT) became aware of active exploitation in August 2026.

vulnerability

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers

Wireshark version 4.6.8 has been released, addressing a total of 28 security vulnerabilities within the popular network protocol analyzer. Nine of these critical flaws are located in file parsers, meaning they can be triggered simply by opening a specially crafted capture file without any network interaction.

vulnerabilityhigh

SharePoint Vulnerability Exploited Shortly After PoC Release

A vulnerability affecting Microsoft SharePoint has reportedly been exploited in the wild shortly after the release of a proof-of-concept (PoC) exploit. The flaw was previously patched by Microsoft in July, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) had issued a warning regarding its potential for active exploitation.

vulnerabilitycritical

“Zoomsday” flaws could let one Zoom participant attack another

Three vulnerabilities, collectively dubbed "Zoomsday" by researchers, have been identified in the Zoom meeting platform. These flaws, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, could enable one participant in a Zoom meeting to compromise another through specially crafted collaboration data.

vulnerabilitycritical

Patch Tuesday: Update now to fix 421 flaws, including three zero-days

Microsoft’s August 2026 Patch Tuesday addresses 421 vulnerabilities across its product line, including 62 rated as critical. The update package, while smaller than July’s record release, remains one of the largest Patch Tuesday batches to date. Among the fixes are three zero-day vulnerabilities, one of which has been actively exploited in the wild by the Lazarus group.

breach

Exposed: Woeful security at UK criminal records office that led to sensitive data leak

The UK's criminal records office, ACRO, has received a regulatory reprimand from the Information Commissioner's Office (ICO) following security failures that potentially exposed sensitive data belonging to nearly 11,000 individuals. The incident, initially disclosed by ACRO in April 2023, involved persistent attacker access to their website and content management system for over seven months,…

breach

Three intrusions at UK criminal records office went undetected for two years

The UK's ACRO Criminal Records Office, a national policing unit responsible for sensitive data on the Police National Computer, was subjected to three separate security intrusions over a period of nearly two years, exposing the personal data of thousands of individuals. The incidents, which occurred between July 2021 and June 2023, went largely undetected due to a series of fundamental…

patchcritical

AI is Working in the SOC. So Why are Security Executives More Worried Than Ever?

Artificial intelligence has become a foundational element in security operations centers (SOCs) over the past two years, moving beyond pilot programs to become a core strategy. A recent survey of 500 security professionals, conducted by Omdia and commissioned by Rapid7, indicates widespread positive outcomes from this shift.

vulnerability

Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery

Microsoft released fixes for 419 security vulnerabilities in its latest Patch Tuesday update, marking one of the largest monthly counts on record. This follows a trend of escalating vulnerability disclosures, with 137 patches in May, 206 in June, and 622 in July, surpassing the company's annual record of approximately 1,250 vulnerabilities. The company has indicated that AI-powered…

vulnerability

CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign

The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies patch a critical Microsoft Windows vulnerability, CVE-2026-68820, by August 25. This directive follows confirmation from both CISA and Microsoft that the flaw is actively being exploited in real-world attacks, notably by North Korean state-sponsored hackers.

zero-day

New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges

A security researcher known as Nightmare Eclipse has released a new zero-day exploit, dubbed "ShieldBreak," affecting Microsoft Defender. The exploit, disclosed on August 12, 2026, after Microsoft's August Patch Tuesday updates, is described as a bypass for a previously identified privilege escalation flaw in Defender, CVE-2026-50656, known as "RoguePlanet."

patch

Weekly Update 516: Live From Vietnam

This week's report from Vietnam highlighted a technical curiosity concerning Brinks Home's frequently asked questions (FAQ) section. The report noted that the company appeared to have authored its own FAQ, yet seemingly failed to adhere to or properly implement the information contained within it. This observation was made amidst minor technical difficulties during the report's transmission,…

breach

Ivanti EPM Update Patches Remotely Exploitable Flaws

Ivanti has released an update for its Endpoint Manager (EPM) software to address several remotely exploitable vulnerabilities. These flaws, if successfully exploited, could lead to the leakage of credentials used for external SQL connections or cause an agent service to crash. The update is critical for maintaining the integrity and availability of systems managed by EPM.

CVE-2026-20349

Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

Cisco has released patches for a zero-day vulnerability in its Secure Firewall ASA and FTD devices, which has reportedly been exploited in the wild to launch denial-of-service (DoS) attacks. The flaw, identified as CVE-2026-20349, allows for remote exploitation without requiring authentication, posing a significant risk to affected systems.

vulnerabilitycritical

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security updates for August 2026, addressing a total of 421 vulnerabilities across various products. Of these, 62 are classified as "critical" by Microsoft. The company confirmed that one of the vulnerabilities, CVE-2026-68820, an elevation of privilege flaw in the Windows Ancillary Function Driver for WinSock, has already been exploited in the wild. This…

vulnerabilitycritical

Microsoft Patch Tuesday, August 2026 Security Update Review

Microsoft's August 2026 Patch Tuesday release addresses 421 vulnerabilities, including 62 critical and 357 important-severity issues across a broad range of products and services. This month's updates include fixes for three zero-day vulnerabilities, one of which has been actively exploited in the wild, while the other two were publicly disclosed prior to the patch release.