patch news
306 stories · page 6 of 7
Google AI Supercharges Chrome Security, Fixing 1,072 Bugs
Google's Chrome Security team has reported a significant acceleration in vulnerability detection and patching, attributing the improvement to the integration of artificial intelligence models into their development pipeline. In the last two Chrome releases alone, 1,072 security bugs were fixed, a number exceeding the total fixes across the preceding 23 milestones combined.

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
Recent reports indicate that Google has addressed a significant volume of security vulnerabilities across three recent releases of its Chrome web browser. Specifically, versions 149, 150, and 151 collectively resolved 1,442 security flaws. This figure notably exceeds the total number of vulnerabilities patched in the preceding 23 Chrome updates combined.

Google gives developers an AI bug hunter that also writes patches
Google has introduced CodeMender, an artificial intelligence agent designed to identify security vulnerabilities in code, confirm their exploitability, and generate patches for developer review. The company states that this tool is a direct response to the increasing use of AI by attackers to accelerate their operations, emphasizing the need for automated defensive measures operating at a…

The automotive software vulnerabilities hiding in your dashboard
The increasing reliance on software in modern vehicles has introduced a significant number of known vulnerabilities into automotive systems, according to research conducted by Télécom SudParis. As car manufacturers integrate general-purpose operating systems like Android and Linux into dashboards and control units, they also inherit the accumulated security flaws documented for these platforms.

Don’t swing at everything
Cisco Talos has identified a new Rust-based remote access trojan (RAT) dubbed "msaRAT," which is being deployed by the Chaos ransomware group. This sophisticated malware leverages the Tokio asynchronous runtime and establishes a covert command-and-control (C2) channel by hijacking Chrome or Edge browsers through the Chrome DevTools Protocol (CDP).

Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
A Russian state-sponsored threat group has been exploiting a zero-day vulnerability in Zimbra Collaboration Suite since July 2025, stealing sensitive data from governments and commercial organizations across multiple Western countries. The vulnerability, identified as CVE-2025-66376, was not patched until November 2025, five months after the attacks began. The group, known as Laundry Bear or…

Russian hackers exploit Zimbra zero-click flaw for email theft
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a Russian state-sponsored hacking group, known as Laundry Bear or Void Blizzard, which is actively exploiting a zero-click vulnerability in Zimbra Collaboration email servers. The group is combining phishing attacks with the exploitation of CVE-2025-66376, a cross-site scripting (XSS) flaw in Zimbra…

Oracle drops 1,449 security patches like it's the new normal
Oracle has released a record 1,449 security patches as part of its quarterly update cycle, a number that security experts suggest reflects a growing trend in the industry driven by the increasing use of artificial intelligence in vulnerability detection. This substantial volume of fixes spans Oracle's extensive product portfolio.

Google Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability Hunting
Google DeepMind has unveiled Gemini 3.5 Flash Cyber, an artificial intelligence model specifically engineered for the discovery and remediation of software vulnerabilities. This specialized AI, built upon the existing 3.5 Flash architecture, is designed to identify, validate, and patch security flaws.

Microsoft working to fix Exchange Online mailbox quarantine issue
Microsoft is actively working to resolve an issue within its Exchange Online service that has led to the incorrect quarantining of customer mailboxes since Sunday, July 19. The incident, identified by Microsoft as EX1436407, has resulted in affected users being unable to send or receive emails and experiencing difficulties accessing their calendars.

US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices
Federal agencies have issued an updated advisory warning of Iranian-backed hackers actively targeting Industrial Control Systems (ICS) devices, specifically naming products from Siemens, Schneider Electric, and Rockwell Automation. The advisory details the techniques employed by these threat actors to compromise Programmable Logic Controllers (PLCs), critical components in industrial environments.

Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft
A critical vulnerability, tracked as CVE-2026-48294, in the Adobe Acrobat Chrome extension allowed attackers to silently exfiltrate sensitive WhatsApp Web data, including chat content, contact lists, and profile information. The flaw, which Adobe has since patched, could be exploited simply by a victim visiting a malicious webpage.

Oracle Critical Patch Update, July 2026 Security Update Review
Oracle has released its third quarterly Critical Patch Update for 2026, addressing a total of 1449 security vulnerabilities across its extensive product portfolio. This update, issued on July 22, 2026, includes patches for both Oracle-developed components and third-party open-source components integrated into Oracle products. Approximately 86% of the patches, or 1235 of the 1449, are for…

New InfraTrust report reveals infrastructure flaws admins should patch first
A new report from Eclypsium, titled InfraTrust Pulse, has identified critical vulnerabilities in infrastructure, firmware, networking, and edge devices that organizations should prioritize for patching. The inaugural July 2026 report, part of Eclypsium's new InfraTrust knowledge base, analyzed 61 infrastructure advisories from 14 vendors, highlighting six critical advisories and 26 remotely…

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
Attackers are actively exploiting a critical remote code execution (RCE) vulnerability, CVE-2026-50522, in on-premise Microsoft SharePoint deployments. The primary objective of these attacks is to exfiltrate Internet Information Services (IIS) machine keys, which can grant long-term access to compromised systems.

CISA orders urgent action on actively exploited Langflow RCE flaw
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for U.S. government agencies to patch a critical, actively exploited remote code execution (RCE) vulnerability in the Langflow visual framework for building AI agents. The flaw, identified as CVE-2026-0770, was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on Tuesday, July 22, 2026, with…

Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates
Oracle has released its quarterly Critical Patch Update (CPU) for July 2026, addressing a substantial number of vulnerabilities across its product portfolio. The update includes fixes for over 1,400 distinct security flaws, marking a significant effort in the company's ongoing commitment to product security. A notable aspect of this particular patch cycle is the reported contribution of…

Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522
A critical remote code execution (RCE) vulnerability in Microsoft SharePoint, identified as CVE-2026-50522, is now under active exploitation following the public release of proof-of-concept (PoC) exploit code. The flaw, which carries a CVSS score of 9.8, was addressed by Microsoft in its July 2026 Patch Tuesday updates.

Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
Oracle released its July 2026 Critical Patch Update (CPU), addressing 1,235 unique Common Vulnerabilities and Exposures (CVEs) across 32 product families. This quarterly update, the third for 2026, includes a total of 1,449 security patches, making it the largest CPU release to date.

Critical SharePoint RCE flaw exploited to steal machine keys
Threat actors are actively exploiting a critical remote code execution (RCE) vulnerability in Microsoft SharePoint, designated CVE-2026-50522, to compromise on-premise deployments. The flaw, a deserialization-of-untrusted-data issue, allows unauthenticated attackers to execute arbitrary code over a network.

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Threat actors associated with the Qilin ransomware, also known as Agenda, have reportedly leveraged a high-severity authentication bypass vulnerability in Palo Alto Networks PAN-OS as an initial access vector into victim networks. Security researchers at Arctic Wolf Labs observed multiple intrusions in June 2026 where the exploitation of this specific flaw marked the starting point of the…

Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros
Cybersecurity researchers at SOCRadar have identified a new social engineering campaign, dubbed "ClickFake Interview," targeting Web3 and cryptocurrency professionals. The operation is attributed to the North Korean-aligned hacking group Famous Chollima, also known as Wagemole, and aims to install remote access trojans (RATs) on victims' devices through elaborate fake job interviews.

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Security researchers have identified multiple sandbox escape vulnerabilities across four prominent AI coding agents: Cursor, OpenAI's Codex, Google's Gemini CLI, and Antigravity. The vulnerabilities, discovered by Pillar Security's research team, Eilon Cohen, Dan Lisichkin, and Ariel Fogel, do not involve direct attacks on the sandboxes themselves. Instead, the sandboxed agents manipulate…

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability
A denial-of-service (DoS) vulnerability, dubbed "HollowByte," has reportedly been addressed in OpenSSL. The flaw could allow attackers to exhaust server memory by sending specially crafted payloads that trigger buffer pre-allocations which are not subsequently freed. The fix was implemented silently, indicating a patch was released without a public security advisory detailing the vulnerability…

On Flock License Plate Tracking Cameras
Flock Safety, a company providing automated license plate recognition (ALPR) cameras to law enforcement agencies, has faced scrutiny following an incident where a journalist was mistakenly identified and arrested due to a partial plate match. The incident involved a Jaguar Land Rover (JLR) media fleet vehicle with a New Jersey manufacturer plate, 34 10 DTM, which was flagged as stolen. The…

Microsoft confirms Windows Server Update Services sync delays
Microsoft has confirmed an ongoing issue affecting Windows Server Update Services (WSUS) servers, leading to extended synchronization times and operational timeouts. This problem, which began in recent days with a noticeable increase in impact starting July 13, 2026, prevents IT administrators from deploying the latest Windows updates via WSUS or Configuration Manager.

More alerts are making your team slower, and an outcome-based SOC fixes that
--- Source 2 --- Rapid7 Unveils AI-Powered SOC Platform to Combat Alert Fatigue and Accelerate Threat Response

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
Russian state-sponsored threat actors, identified as UAC-0145, have reportedly been employing a technique dubbed "ClickFix CAPTCHAs" to compromise devices belonging to Ukrainian targets. This activity has led to the self-infection of machines with data-stealing malware. The Computer Emergency Response Team of Ukraine (CERT-UA) has attributed this campaign to UAC-0145, further linking it to…

Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs
Attackers are reportedly bypassing Microsoft Entra ID sign-in logs by spoofing OAuth client IDs during account enumeration against Microsoft cloud tenants. This technique involves manipulating the `client_id` parameter in authentication requests, which Entra ID records as the application ID. The way the system handles unfamiliar identifiers creates a blind spot that threat actors are…

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip has released version 26.02 of its popular archiving utility to address a remote code execution (RCE) vulnerability. The flaw, which could allow attackers to execute malicious code, is triggered when users open specially crafted compressed files.

WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Publicly available exploits have emerged for a pair of critical remote code execution (RCE) vulnerabilities in WordPress Core, collectively dubbed "wp2shell." These flaws, identified as CVE-2026-63030 and CVE-2026-60137, can be chained together to allow pre-authentication RCE on affected WordPress installations. Administrators are strongly advised to update their sites immediately.

Two High-Severity WordPress Vulnerabilities Require Immediate Patching
WordPress has released emergency security updates to address two high-severity vulnerabilities, including a critical SQL injection flaw that could lead to remote code execution. Users are urged to patch their installations immediately.

Multiple Vulnerabilities Found in WolfSSL, GeoVision, and VTK-DICOM
Multiple vulnerabilities have been identified and patched in WolfSSL, GeoVision, and VTK-DICOM, according to a recent disclosure by Cisco Talos. The vulnerabilities, discovered by the Talos Vulnerability Discovery & Research team, have all been addressed by their respective vendors in accordance with Cisco's disclosure policy.

Chrome 150 Update Fixes 27 Security Flaws
Google has released an update for its Chrome browser, version 150, which addresses a total of 27 security vulnerabilities. Among the patched flaws, 13 were identified as use-after-free bugs, with two of these specifically noted as critical in severity. This update is crucial for users to maintain the security posture of their browsing environment.

Ubiquiti warns of new max severity UniFi OS vulnerability
Ubiquiti has issued security updates to address seven critical vulnerabilities affecting its UniFi OS, including a maximum-severity flaw that could allow for command injection attacks. The most severe issue, tracked as CVE-2026-50746, impacts the UniFi Connect Application, specifically versions 3.4.16 and earlier.

CISA orders feds to patch max severity ColdFusion flaw by Friday
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies patch a critical vulnerability in Adobe ColdFusion by Friday. This directive, issued under Binding Operational Directive 26-04, targets a flaw designated CVE-2026-48282, which is actively being exploited by malicious actors.

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure
Security researchers have detected malicious actors actively probing for a critical vulnerability in Gitea Docker images, just thirteen days after the issue was publicly disclosed and patched. The vulnerability, designated CVE-2026-20896, carries a severe CVSS score of 9.8, indicating a high level of risk.

RCS Uses NAPTR Records for DNS Resolution
Rich Communication Services (RCS), a modern messaging protocol intended to succeed SMS, has seen increased adoption over the past year, particularly with recent updates to both iOS and Android operating systems. RCS offers enhanced formatting capabilities and improved security features compared to its predecessor.

Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages
A security vulnerability discovered in the Opera GX browser could allow malicious websites to silently install add-ons and exfiltrate data from visited pages. The flaw, demonstrated by researchers, specifically targets the gaming-oriented version of the Opera browser.

Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
A cybersecurity firm has revealed seven security weaknesses in FatFs, a widely deployed filesystem library. FatFs is used by millions of embedded devices to read and write data on FAT and exFAT formatted storage media, such as USB drives and SD cards. The vulnerabilities were disclosed by the security firm runZero.

New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
A critical vulnerability, dubbed "Bad Epoll" and identified as CVE-2026-46242, has been discovered in the Linux kernel. This flaw allows an unprivileged user to gain complete root-level control over a compromised system. The vulnerability impacts a wide range of Linux-based systems, including desktop and server distributions, as well as the Android mobile operating system. Fortunately, a patch…

Apple Reverses Age-Old Patch Policy to Keep Up With AI
Apple is signaling a shift in its long-standing patching strategy, indicating a move towards more frequent and compressed software updates. This change is a direct response to the evolving threat landscape, particularly the growing use of artificial intelligence by malicious actors to accelerate the process of discovering and exploiting vulnerabilities.

Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.
IBM has launched a significant initiative, codenamed Project Lightwell, involving 20,000 engineers from IBM and Red Hat. This effort is reportedly a response to concerns surrounding the security of the open-source software supply chain, amplified by findings from Anthropic's AI model, Mythos.

And the Winner in Dominant Malware Delivery? ClickFix
A sophisticated social engineering tactic, previously considered an outlier, has become a prevalent method for delivering malware, according to security researchers. This technique, which leverages user interaction to facilitate malicious payloads, is now frequently employed in cyberattacks.

Weekly Update 510: Live From Mallorca with Scott Helme
A website that once aimed to shame organizations for neglecting transport layer security has been found to be running on outdated and vulnerable software. The "Why no HTTPS?" project, launched eight years ago by Scott Helme and another individual, is now itself a target for potential exploitation due to unpatched systems.

Apple Releases June Software Updates
Apple issued software updates on Monday for its iOS/iPadOS and macOS operating systems, along with a refresh for its Safari web browser. These releases mark the latest security and feature patches from the technology giant.

Weekly Update 509
A newly identified vulnerability in certain versions of the Realtek SDK could potentially allow attackers to execute arbitrary code on affected devices. The vulnerability, identified as CVE-2023-32250, was discovered by security researchers at GRIMM.

Weekly Update 508
This week's security update highlights a peculiar vulnerability in a common household item: smart light switches. While the specifics of the exploit are not detailed, the report indicates that certain smart light switches possess a flaw that could potentially be leveraged by malicious actors.