LIVE · cybersecurity feed
Live wire
CVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

patch news

306 stories · page 7 of 7
breach

Weekly Update 507

A cybersecurity data breach tracking initiative has surpassed a significant milestone, having now documented over 1,000 separate data breaches. This achievement represents not only the collection and verification of breach data but also the extensive operational efforts required to maintain the service.

patchcritical

A Record-Breaking Patch Tuesday for June 2026

Microsoft has released a record-breaking set of software updates for June 2026, addressing nearly 200 security vulnerabilities across its Windows operating systems and related software. This significant number of patches, with close to three dozen classified as critical, reflects an increasing trend in vulnerability discovery, potentially driven by the growing use of artificial intelligence…

vulnerability

Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its June 2026 security update, addressing a total of 206 vulnerabilities across its product range, with 32 of these classified as "critical." The update includes fixes for numerous remote code execution (RCE) and elevation of privilege vulnerabilities affecting core Windows components, as well as products like Microsoft Office, SQL Server, and Azure Kubernetes Service.

vulnerability

Smashing Security podcast #470: This AI security flaw might be impossible to fix

A website that purported to assist travelers with UK visa applications has been found to have collected sensitive personal data, including passport scans and selfies, from thousands of users. The data was reportedly stored in an unsecured Amazon storage bucket, making it accessible to unauthorized individuals. When a journalist attempted to alert the company operating the website, they were…

breach

Weekly Update 506

A recent wave of data breaches attributed to the threat actor group ShinyHunters has brought renewed attention to the challenges organizations face in responding to and disclosing such incidents. While the criminal nature of these attacks is evident, the varying degrees of organizational response, including instances of non-disclosure, highlight ongoing issues in cybersecurity incident…

patch

Less panic patching, more precision

Security teams are being urged to re-evaluate their vulnerability management strategies to better prepare for an anticipated surge in patching requirements. The current default practice of prioritizing vulnerabilities based solely on the Common Vulnerability Scoring System (CVSS) is insufficient, as CVSS measures theoretical severity rather than actual risk.

patch

Weekly Update 505

A significant data breach impacting Instructure, the company behind the Canvas learning management system, appears to have been averted or mitigated shortly after it was discovered. The threat actor group ShinyHunters, which had claimed responsibility for the incident, ceased its activity shortly after the initial reports of the breach.

breach

Weekly Update 504

The debate surrounding whether to pay ransoms to cybercriminals to prevent data leaks continues to be a significant concern for organizations. In a recent development, Grafana, a popular open-source analytics and monitoring solution, reportedly chose not to pay a ransom demand. This decision comes amidst ongoing discussions about the efficacy and ethical implications of ransom payments in the…

CVE-2025-54957critical

A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens

Researchers have developed a two-exploit chain that can achieve root access on the Google Pixel 10, starting from a zero-click attack vector. This chain builds upon previous work that demonstrated a similar exploit for the Pixel 9.

breach

Weekly Update 503

Instructure, the company behind the Canvas learning management system, has not yet publicly addressed a potential data breach, despite a deadline set by a ransomware group known as ShinyHunters. The group had threatened to leak data allegedly stolen from Instructure by November 20th.

vulnerability

On the Effectiveness of Mutational Grammar Fuzzing

Mutational grammar fuzzing, a technique that uses predefined grammars to guide sample mutation while preserving structural integrity, faces significant challenges that can hinder bug discovery despite its proven effectiveness. While the approach ensures generated samples adhere to structural rules, leading to the discovery of complex issues in areas like XSLT implementations and JIT engines,…

CVE-2023-41772

A Deep Dive into the GetProcessHandleFromHwnd API

The GetProcessHandleFromHwnd API, a Windows function that allows an application to obtain a handle to the process owning a specific window handle (HWND), has undergone significant changes since its introduction, with its original documentation containing several inaccuracies. Initially believed to be a convenience function relying on window hooks, its implementation and security properties…

breach

Bypassing Administrator Protection by Abusing UI Access

A security researcher has detailed multiple vulnerabilities in Windows' User Account Control (UAC) system, specifically concerning the "UI Access" feature, which were present even before the introduction of Administrator Protection. These bypasses, totaling nine discovered by James Forshaw, have since been addressed by Microsoft. This article focuses on five of these issues, stemming from the…

CVE-2024-54529critical

Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529

A type confusion vulnerability in Apple's CoreAudio framework, identified as CVE-2024-54529, has been successfully exploited by a Google security engineer. The vulnerability resides within the `coreaudiod` system daemon, specifically in the `com.apple.audio.audiohald` Mach service. Researchers discovered that certain message handlers within this service would retrieve an object from an…

vulnerability

Bypassing Windows Administrator Protection

Microsoft's Administrator Protection feature, intended to replace User Account Control (UAC) with a more secure system for granting administrator privileges in Windows 11, has been found to be bypassable. The feature, introduced in Windows 11 version 25H2, aims to allow local users to access administrative rights only when necessary, creating a more robust security boundary. However, security…

CVE-2025-54957critical

A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here?

The Android ecosystem faces significant challenges in mitigating zero-click exploit chains, particularly concerning audio processing components and device drivers, according to recent research. While specific vulnerabilities in the Dolby UDC (Universal Decode Component) and a BigWave driver were identified and exploited, the broader implications highlight systemic issues in attack surface…

breach

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave

A security researcher has identified a critical vulnerability in the Linux kernel used by Google Pixel devices, specifically affecting the BigWave hardware accelerator. This flaw, if exploited, could allow an attacker to escape the restricted "mediacodec" sandbox and gain arbitrary read and write capabilities within the kernel. The vulnerability was discovered by Seth Jenkins, who detailed his…

CVE-2025-49415high

A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby

Google's Pixel 9 devices are susceptible to a zero-click exploit chain that targets the Dolby Unified Decoder (UDC), a component responsible for processing Dolby Digital and Dolby Digital Plus audio formats. This vulnerability allows for arbitrary code execution within the mediacodec context of the device, forming the first stage of a more complex attack. The exploit chain was developed by…