LIVE · cybersecurity feed
Live wire
CVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

patch news

306 stories · page 5 of 7
patch

Microsoft's Patch Tuesday Deluge Continues With August Updates

Microsoft's August Patch Tuesday updates have been released, with security experts advising that the primary focus for organizations should be on prioritizing the application of these patches rather than being overwhelmed by the sheer volume of Common Vulnerabilities and Exposures (CVEs) addressed. This guidance suggests that some vulnerabilities may pose a more immediate or severe risk than…

vulnerability

421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one

Microsoft's August Patch Tuesday release addresses 421 vulnerabilities across its product line, with one critical flaw, CVE-2026-68820, confirmed by Microsoft to have been exploited as a zero-day by North Korea's Lazarus Group. This use-after-free vulnerability resides in the Windows Ancillary Function Driver for WinSock.

vulnerabilityhigh

Microsoft Plugs Nearly 400 Security Holes

Microsoft released updates on August 11, 2026, to address 398 security vulnerabilities in its Windows operating systems and associated software. This extensive patch includes fixes for one vulnerability that is actively being exploited in the wild and two others that were publicly disclosed prior to the release.

CVE-2026-68820

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft has reportedly issued its monthly security updates, addressing a substantial number of vulnerabilities, including a Windows kernel driver zero-day that is actively being exploited in the wild. This critical flaw is said to be present in a core Windows kernel driver responsible for managing network socket operations. The update package reportedly includes patches for 398 distinct…

zero-day

August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

Microsoft's August 2026 Patch Tuesday release addressed a significant number of vulnerabilities, with 421 Common Vulnerabilities and Exposures (CVEs) receiving fixes. Among these, one zero-day vulnerability was specifically highlighted as having been actively exploited in the wild. This exploited flaw is a local privilege escalation issue affecting the Windows operating system.

vulnerabilitycritical

Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)

Microsoft's August 2026 Patch Tuesday, released on Tuesday, August 11th, addressed a substantial volume of security vulnerabilities across its product line. The update package included fixes for a total of 418 vulnerabilities. Among these, 62 were categorized as critical, indicating their potential for severe impact without user interaction. The release also notably included patches for one…

vulnerability

Windows 11 KB5121003 & KB5120240 cumulative updates released

Microsoft has released the August 2026 Patch Tuesday cumulative updates, KB5121003 and KB5120240, for Windows 11 versions 25H2/24H2 and 23H2. These updates are mandatory and address 400 security vulnerabilities identified in prior months, in addition to introducing new features and bug fixes. Users can install the update via Windows Update in their system settings or by manually downloading it…

vulnerability

Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification

A security flaw in Cursor's command-line coding agent allowed malicious code from a cloned repository to execute on a developer's machine without prior trust verification or proper sandboxing. The vulnerability, discovered by Francisco Rosales of Manifold Security, was reported to Cursor on July 20 and publicly disclosed on August 10.

breach

Mozilla updates GPG signing key for Firefox releases after exposure

Mozilla has updated the GPG signing key used for Firefox and Thunderbird releases after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository. The organization announced the key rotation on August 11, 2026, stating that the exposed key was used to sign Linux tarballs, RPM packages, and checksum files for both applications.

patch

Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

Mozilla has revoked a cryptographic key used to sign releases of its Firefox browser and Thunderbird email client after an unencrypted copy of the private key was inadvertently committed to a GitHub repository. The company confirmed the incident on Monday, stating that the GPG private subkey was placed in a private GitHub repository accessible to a limited number of Mozilla employees, all of…

patch

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

Security researchers have demonstrated a method to achieve SYSTEM-level access on a fully updated Windows 11 machine by exploiting the operating system's Plug and Play (PnP) functionality. The attack leverages the automatic installation of signed vendor software for emulated USB devices, chaining this process to escalate privileges. This technique reportedly allows for a complete system takeover.

vulnerability

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix

An AI-powered tool has identified 84 previously unknown security flaws in the software that underpins 4G and 5G cellular networks. Researchers at Nanyang Technological University developed the tool, named iFinder, which found these vulnerabilities by analyzing core network software. Of the 84 reported flaws, 83 have been confirmed by developers, and 81 have been assigned Common Vulnerabilities…

vulnerability

Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

A recent report highlights the growing disparity between the accelerated pace of AI-assisted software development and the comparatively slower, human-driven processes of security review and risk management. With AI tools enabling development teams to generate significantly more code, potentially increasing output by 10 to 50 times, the traditional security pipeline faces immense pressure. The…

vulnerability

Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant

A vulnerability, dubbed "RovoBlast" by Varonis Threat Labs, was discovered in Atlassian's enterprise AI assistant, Rovo, allowing for the exfiltration of company data through a single crafted link. The flaw was disclosed to Atlassian by Varonis, which published its analysis on August 7 after presenting the research at DEF CON 34. Atlassian has since confirmed and fixed the issue.

CVE-2026-18577

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

N-able has released a second security hotfix for its N-central remote monitoring and management (RMM) solution, urging all partners to update immediately. This new hotfix, version 2026.3.1.10 (2026.3 Hotfix 2), provides additional hardening measures to protect against ongoing exploitation of CVE-2026-18577, an authentication bypass vulnerability. The company recommends upgrading agents on…

vulnerability

Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026

Attackers have exploited a critical authentication bypass vulnerability, identified as CVE-2026-18577, in N-able N-central, a remote monitoring and management solution. This flaw allows unauthorized access to managed endpoints.

breach

Hackers breach TrueConf to trojanize client installers with backdoors

Hackers are exploiting vulnerabilities in TrueConf video conferencing servers to distribute malicious client installers containing backdoors, according to research from Kaspersky. The attacks, attributed to a group named Head Mare, leverage two specific flaws, internally tracked as KLCERT-26-057 and KLCERT-26-058, to achieve arbitrary code execution and privilege escalation, ultimately leading…

vulnerabilityhigh

Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data

Attackers have exploited a zero-day vulnerability in Metabase, an open-source business intelligence and data analytics platform, to gain administrative access and steal sensitive data. The flaw, which carries a maximum CVSS score of 10.0, allowed unauthenticated attackers to inject arbitrary SQL into the Metabase application database.

vulnerability

More than half of AI-generated patches are broken

New research indicates that large language models (LLMs) are more likely to introduce new vulnerabilities or create exploitable patches than to fully resolve security flaws. Two independent studies found that AI-generated security patches often fail to completely remediate vulnerabilities, with success rates falling below 50% in some tests.

vulnerability

WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover

A critical vulnerability chain, dubbed "XSS2Shell" by researchers at Pwn, has been discovered in WordPress that could allow an unauthenticated attacker to achieve full server takeover. The exploit chain begins with a seemingly minor cross-site scripting (XSS) flaw on the login page and culminates in remote code execution (RCE) on the web server.

vulnerability

AI-Generated Patches Fail Half the Time

A recent study examining over 6,000 AI-generated software patches has revealed a significant failure rate, with approximately half of these automated fixes either failing to resolve the original issue, introducing new vulnerabilities, breaking existing functionality, or being susceptible to bypass. This finding suggests that while AI holds promise for accelerating the patching process, its…

vulnerability

N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands

N-able has confirmed that attackers exploiting a critical zero-day vulnerability in its N-central remote monitoring and management (RMM) platform successfully infiltrated customer networks. The vendor has subsequently released a second mandatory hotfix, version 2026.3.1.10, just days after an initial emergency patch.

patch

Announcing Cloudflare Ambassadors, Community Engineers, and another $1M in open-source funding

Cloudflare has announced a new initiative to foster its open-source community, introducing a Cloudflare Ambassadors program and a Community Engineers program, alongside an additional $1 million in funding for open-source projects. This new funding brings Cloudflare's total commitment to open-source initiatives to $3.5 million.

CVE-2026-64638high

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

A newly discovered pre-authentication reflected cross-site scripting (XSS) vulnerability has been identified in the login screen of WordPress, affecting all versions of the content management system. This high-severity flaw, tracked as CVE-2026-64638 with a CVSS score of 8.9, requires no prior attacker privileges and can, under specific additional conditions, be chained to achieve PHP code…

breachcritical

Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026

At Black Hat USA 2026, nearly 100 cybersecurity practitioners participated in a 48-hour event called SWARM, hosted by Tenable and sponsored by AWS, with technical staff from Anthropic serving as judges. The event focused on leveraging agentic AI to develop open-source defensive cybersecurity tools, which are now available on the CyberAgents Exchange. The initiative aimed to address the growing…

vulnerability

Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

A recent analysis by the National Motor Freight Traffic Association (NMFTA) has revealed that a safety recall issued for the Bendix EC80 brake controller also contained patches for significant security vulnerabilities. The recall, initially presented to address safety concerns, implicitly remediated issues that could have allowed for remote code execution and denial-of-service attacks against…

vulnerabilitycritical

Microsoft, Apple Release Fresh Security Updates

Microsoft and Apple have both released new security updates addressing a range of vulnerabilities in their respective products. Microsoft's patches target critical flaws in Azure, Entra, and SharePoint, while Apple's update addresses a high-severity authentication bypass.

patch

OpenAI drops ChatGPT text chat limits for free users, adds new safeguards for teens

OpenAI has announced significant updates to its ChatGPT service, including the removal of text chat rate limits for free users and the introduction of enhanced safeguards for younger individuals. The company is rolling out new models, GPT-5.6 Sol and GPT-5.6 Luna, which aim to improve accuracy and provide more focused responses.

vulnerabilitycritical

Critical Vulnerabilities Patched With Chrome 151 Update

Google has released an update for its Chrome browser, version 151, which addresses a significant number of security vulnerabilities. The update is reported to patch more than two dozen memory safety bugs, a category of flaw that often leads to severe security issues. Among these, several critical use-after-free vulnerabilities were specifically highlighted as being resolved.

zero-day

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?

Microsoft's July 2026 Patch Tuesday saw an unprecedented volume of security updates, with over 600 Common Vulnerabilities and Exposures (CVEs) addressed across nearly all products in its portfolio. Windows 11 and Server 2025 accounted for 405 CVEs, while Windows 10 and its server counterparts had 337. Record numbers of CVEs were also reported for Microsoft SharePoint and Office, alongside…

malware

ClickFix attack pushes macOS infostealer for crypto theft attacks

A new macOS infostealer, delivered through "ClickFix" attacks, is targeting cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. The malware, written in Go, has the capability to intercept and redirect cryptocurrency transactions, either fully draining wallets or diverting a percentage of funds to the attacker.

vulnerability

AI struggles to patch vulns without adult supervision

Autonomous patching of software vulnerabilities using large language models (LLMs) currently demonstrates a low success rate and often introduces new issues, according to research conducted by 1Password's Off-by-1 Labs. The study, which involved generating over 6,000 patches for six recently disclosed CVEs using ChatGPT 5.5 and Claude Opus 4.8, found that only 26.0 percent of the LLM-generated…

breach

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

A new CPU attack technique, dubbed TONTOU (Time-of-Neutralization to Time-of-Use), has been discovered that can bypass existing Spectre v2 mitigations on both AMD and Intel processors. This method allows an unprivileged attacker to leak sensitive data from the kernel, including password hashes from the `/etc/shadow` file on Linux systems.

vulnerabilitycritical

Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs

Cisco has released patches for a dozen security vulnerabilities affecting its Catalyst SD-WAN and IOS XE Software, including three critical flaws rated 9.8 on the CVSS scale. The updates are the result of an internal security review conducted by Cisco, aimed at identifying and remediating potential weaknesses across its product lines. The affected software is widely deployed in enterprise and…

patch

Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts

Zenity researchers have reported a zero-click browser hacking technique targeting AI models, specifically Claude and ChatGPT Atlas. The method reportedly leverages emails and X posts to compromise user sessions without requiring direct interaction from the victim. The researchers claim to have disclosed these findings to Anthropic and OpenAI in late 2025 and early 2026, respectively, but the…

vulnerability

Three in four AI-generated vulnerability patches leave something broken

New research indicates that large language models (LLMs) tasked with patching software vulnerabilities frequently produce fixes that are incomplete, introduce new flaws, or alter expected program behavior. A study by Off-by-1 Labs, a security research group within 1Password, found that roughly three out of four AI-generated patches for real-world vulnerabilities left something broken.

vulnerability

AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking

A new report indicates that AI-powered browsers are susceptible to a novel zero-click agent hijacking technique dubbed "PleaseFix." This method reportedly allows attackers to seize control of AI agents by embedding malicious instructions within content that the AI browser processes. The report suggests that a straightforward solution to this particular threat is not readily apparent.

vulnerability

Flaws in Google APK for Python Unlock Agent-to-Agent Attack

Recent reports indicate that Google has addressed a series of vulnerabilities found within its APK for Python, which could have enabled an agent-to-agent attack scenario. The core of the issue reportedly lay in the exploitation of a trust boundary between two distinct AI agents operating with differing privilege levels. This trust boundary bypass could then trigger automated actions with…

vulnerabilitycritical

IBM's agentic AI platform is under active attack - patch now

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory regarding active exploitation of a critical vulnerability, CVE-2026-9198, in IBM's Langflow platform. The flaw, which has been added to CISA's Known Exploited Vulnerabilities catalog, allows unauthenticated remote code execution (RCE) on default deployments of the low-code AI builder. Organizations are…

breach

TP-Link patches Omada ZTP flaws allowing hackers to breach networks

TP-Link has addressed 15 vulnerabilities within the zero-touch provisioning (ZTP) mechanism of its Omada networking devices. These flaws, when chained with previously identified vulnerabilities, could lead to remote code execution (RCE) on affected systems. The vulnerabilities were discovered by researchers at Forescout's Vedere Labs, who presented their findings at the Black Hat USA security…

vulnerability

COLDCARD Seed Generation Flaw Linked to Nearly $89 Million Bitcoin Theft

A recent report by Galaxy Research has linked a suspected theft of approximately 1,367.05 Bitcoin, valued at nearly $89 million, to a weakness in the seed generation process of COLDCARD hardware wallets. The research suggests that seeds generated on these devices may have been susceptible to compromise, leading to the significant loss of funds.

patch

AI is 'both the weapon and the target' in latest wave of cyberattacks

Cybersecurity firm CrowdStrike reports an 89 percent increase in AI-enabled cyberattacks in 2025, noting that artificial intelligence is being utilized by adversaries as both a weapon and a target. The company's annual Threat Hunting Report indicates that both criminal organizations and state-sponsored groups are integrating AI across the entire attack chain. Attackers are also specifically…

vulnerability

CrowdStrike: AI is now both the weapon and the target in cyberattacks

Artificial intelligence has become both a primary tool for cyber attackers and a significant target for their operations, according to a recent report by CrowdStrike. The cybersecurity firm's analysis, covering the year leading up to June, indicates a substantial increase in AI-driven malicious activity, with AI agents generating more than twice the number of potentially malicious signals…

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework of the Rails web application framework, identified as CVE-2026-66066, could allow an unauthenticated attacker to read arbitrary files and potentially achieve remote code execution (RCE). Rails, an open-source Ruby-based framework, uses Active Storage for handling file uploads and attachments.

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe has released a security update for its enterprise marketing automation platform, Campaign Classic, addressing a critical vulnerability that could allow attackers to execute arbitrary code remotely without user interaction. The flaw, identified as CVE-2026-48449, carries a maximum CVSS score of 10.0, indicating its severe potential impact.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

Ruby on Rails has released patches addressing a critical vulnerability that could allow unauthenticated attackers to read arbitrary files and potentially achieve remote code execution. The flaw impacts installations of the popular web application framework, posing a significant risk to affected systems.

CVE-2026-48449

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has issued security updates to address a critical vulnerability in its enterprise marketing automation platform, Campaign Classic (ACC). The flaw, identified as CVE-2026-48449, has been assigned a maximum severity score of 10.0 on the CVSS scale. This vulnerability could potentially allow for arbitrary code execution without requiring user interaction.

patch

In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research

A recent report highlighted several security incidents and developments that may have received less widespread attention. Among these were a reported hack impacting the parcel delivery company OnTrac, a series of patches released by Adobe, and a data loss incident at the UK Department for Education involving a significant number of records.