vulnerabilities

Cisco Patches Nine Flaws in Crosswork and Secure Workload Software
Cisco has released security updates addressing nine vulnerabilities affecting its Crosswork platforms and Secure Workload Software. Five of these flaws have received a critical CVSS score of 10.0. The vulnerabilities impact Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, irrespective of device configuration.

Critical Chrome Update Fixes Two Buffer Overflow Vulnerabilities
Google has released an update for Chrome's desktop versions, addressing 15 security flaws. Two of these are critical buffer overflow vulnerabilities, one in WebGL (CVE-2026-76034) and another in the Dawn library used for WebGPU (CVE-2026-76036). These issues could allow remote attackers to execute arbitrary code. Users are urged to update to version 151.0.7922.169/.170 to protect themselves.

Enterprise Software Has 4.31x More Critical Vulnerabilities
A recent analysis indicates that enterprise software applications are now exhibiting a 4.31 times higher rate of critical and high-severity vulnerabilities. This trend coincides with an overall acceleration in the development of enterprise software.

17th August – Threat Intelligence Report
Several significant cyber incidents were reported this week, including a ransomware attack on Colombia's Ministry of Justice and a data breach affecting Poland's primary healthcare platform, MyDr, potentially exposing data of 19 million citizens. Additionally, Levi Strauss & Co. and IEH Corporation reported cyberattacks involving social engineering and phishing, respectively, with no consumer data compromised in the former. In the realm of AI threats, researchers detailed a suspected China-linked campaign using autonomous AI agents against Taiwanese government systems and noted North Korea-linked Kimsuky's efforts to build an offline AI environment for cyberespionage. Microsoft, Apple, Adobe

Crooks Buy Expired Domains for Malware Delivery, Other Threats Detailed
Cybercriminals are exploiting expired domain names to distribute malware, a tactic highlighted in a recent security newsletter. The newsletter also covers a range of other threats including zero-day exploits in macOS and GeoServer, a data leak affecting Chess.com users, and attacks targeting Adobe Commerce and SharePoint.

Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI
The increasing volume of software vulnerabilities, partly fueled by AI-powered discovery tools, has prompted NIST to explore the potential of AI in managing and mitigating these risks. This includes investigating how AI can aid in vulnerability analysis and response.

Black Hat USA 2026: AI is racing ahead of cybersecurity controls
Black Hat USA 2026 highlighted the rapid advancement of AI and its increasing role in cybersecurity, while also raising critical questions about accountability. Discussions focused on the challenges of regulating AI due to its swift evolution and the difficulty in assigning responsibility when AI-driven incidents occur. Experts emphasized the need for human oversight, robust governance, and a collaborative approach to ensure AI is developed and deployed safely and responsibly.

Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws
Adobe has released urgent security updates for critical vulnerabilities affecting its ColdFusion and Campaign Classic products. Exploitation of these flaws could lead to arbitrary code execution or denial-of-service attacks.

When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers
Researchers have discovered five vulnerabilities in workerd, the open-source runtime powering Cloudflare Code Mode and Cloudflare Workers. Two of these vulnerabilities have been classified as critical by Cloudflare. The flaws could allow for sandbox escapes and cross-tenant data exposure, impacting millions of developers and requests served by Cloudflare Workers. Cloudflare has addressed the issues in its managed environment, while self-hosted deployments require an update to workerd version v1.20260619.1.

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
Researchers have identified a significant class of 84 previously unknown vulnerabilities, dubbed 'iTrue' flaws, affecting the core networks of 4G and 5G mobile systems. These vulnerabilities stem from implicit trust errors between network functions, exacerbated by the shift to cloud-native deployments. Exploitation could lead to denial-of-service attacks and session hijacking, where an attacker seizes control of a user's network session.

AI to Drive More Windows Security Updates, Microsoft Says
Microsoft anticipates a rise in security updates for Windows due to its growing use of artificial intelligence. The company is leveraging AI to proactively identify vulnerabilities within its software, aiming to enhance overall system security.

Summer Staffing Shortages Expose IT Security Risks
Reduced IT staffing during summer vacation periods can create significant security vulnerabilities. Organizations are advised to leverage AI-driven automation to maintain consistent security operations and minimize reliance on manual processes, ensuring protection remains robust even with fewer personnel.

Chrome 150 Update Fixes 27 Security Flaws
Google has released an update for its Chrome browser, version 150, addressing a total of 27 vulnerabilities. The patch includes fixes for 13 use-after-free bugs, two of which were identified as critical severity.

Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation
Ubiquiti has released security updates to address seven vulnerabilities in its UniFi OS, including several critical flaws. One critical vulnerability, CVE-2026-50746, allows for command injection in the UniFi Connect Application, impacting systems that manage building infrastructure like smart lighting and EV chargers. Other patched issues include SQL injection, improper input validation, and SSRF vulnerabilities across various UniFi applications, potentially leading to privilege escalation.

Cybersecurity and the Gap Between Skill and Ability
The increasing capability of AI models to autonomously perform cyberattacks is widening the gap between skill and ability, lowering the barrier to entry for malicious actors. While traditional cybersecurity advice remains relevant, the speed of AI development necessitates a more urgent and adaptive approach. Harnessing AI for defense is seen as a crucial countermeasure, though challenges remain in preventing misuse of powerful AI tools.

OpenClaw: risks for the users and how to mitigate them
OpenClaw, an AI agent ecosystem formerly known as Clawdbot and Moltbot, offers flexibility and task automation but introduces security risks to users and organizations. The system's 'skills' feature, which allows for natural language instructions and easy creation of extensions, can be exploited by attackers. The article aims to explore these security aspects, known vulnerabilities, and mitigation strategies.

AI Creates 457 Million Security Issues for Organizations
A recent 30-day analysis revealed over 457 million AI-related security issues across more than 7,000 organizations, averaging 62,000 exposures per company. These issues are largely due to misconfigurations and unmanaged dependencies, rather than traditional CVEs. The findings highlight the need for comprehensive exposure management programs to address the growing risks posed by both approved and unapproved AI tools.

Oracle Releases June Patch Update Addressing 243 Vulnerabilities
Oracle has issued its June Critical Security Patch Update, resolving 243 unique CVEs with 245 security patches. A significant portion, 122 patches, are rated as critical severity. The Oracle Fusion Middleware product family received the largest number of fixes, with 106 patches.