LIVE · cybersecurity feed
Live wire
Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainHow an Emerging Industrial Protocol Family Could Put OT at Risk14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentials

vulnerabilities

ciscocritical

Cisco Patches Nine Flaws in Crosswork and Secure Workload Software

Cisco has released security updates addressing nine vulnerabilities affecting its Crosswork platforms and Secure Workload Software. Five of these flaws have received a critical CVSS score of 10.0. The vulnerabilities impact Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, irrespective of device configuration.

CVE-2026-76034critical

Critical Chrome Update Fixes Two Buffer Overflow Vulnerabilities

Google has released an update for Chrome's desktop versions, addressing 15 security flaws. Two of these are critical buffer overflow vulnerabilities, one in WebGL (CVE-2026-76034) and another in the Dawn library used for WebGPU (CVE-2026-76036). These issues could allow remote attackers to execute arbitrary code. Users are urged to update to version 151.0.7922.169/.170 to protect themselves.

vulnerabilitieshigh

Enterprise Software Has 4.31x More Critical Vulnerabilities

A recent analysis indicates that enterprise software applications are now exhibiting a 4.31 times higher rate of critical and high-severity vulnerabilities. This trend coincides with an overall acceleration in the development of enterprise software.

CVE-2026-68820high

17th August – Threat Intelligence Report

Several significant cyber incidents were reported this week, including a ransomware attack on Colombia's Ministry of Justice and a data breach affecting Poland's primary healthcare platform, MyDr, potentially exposing data of 19 million citizens. Additionally, Levi Strauss & Co. and IEH Corporation reported cyberattacks involving social engineering and phishing, respectively, with no consumer data compromised in the former. In the realm of AI threats, researchers detailed a suspected China-linked campaign using autonomous AI agents against Taiwanese government systems and noted North Korea-linked Kimsuky's efforts to build an offline AI environment for cyberespionage. Microsoft, Apple, Adobe

CVE-2026-58231high

Crooks Buy Expired Domains for Malware Delivery, Other Threats Detailed

Cybercriminals are exploiting expired domain names to distribute malware, a tactic highlighted in a recent security newsletter. The newsletter also covers a range of other threats including zero-day exploits in macOS and GeoServer, a data leak affecting Chess.com users, and attacks targeting Adobe Commerce and SharePoint.

nist

Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI

The increasing volume of software vulnerabilities, partly fueled by AI-powered discovery tools, has prompted NIST to explore the potential of AI in managing and mitigating these risks. This includes investigating how AI can aid in vulnerability analysis and response.

artificial intelligence

Black Hat USA 2026: AI is racing ahead of cybersecurity controls

Black Hat USA 2026 highlighted the rapid advancement of AI and its increasing role in cybersecurity, while also raising critical questions about accountability. Discussions focused on the challenges of regulating AI due to its swift evolution and the difficulty in assigning responsibility when AI-driven incidents occur. Experts emphasized the need for human oversight, robust governance, and a collaborative approach to ensure AI is developed and deployed safely and responsibly.

adobecritical

Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws

Adobe has released urgent security updates for critical vulnerabilities affecting its ColdFusion and Campaign Classic products. Exploitation of these flaws could lead to arbitrary code execution or denial-of-service attacks.

cloud computingcritical

When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers

Researchers have discovered five vulnerabilities in workerd, the open-source runtime powering Cloudflare Code Mode and Cloudflare Workers. Two of these vulnerabilities have been classified as critical by Cloudflare. The flaws could allow for sandbox escapes and cross-tenant data exposure, impacting millions of developers and requests served by Cloudflare Workers. Cloudflare has addressed the issues in its managed environment, while self-hosted deployments require an update to workerd version v1.20260619.1.

CVE-2026-8233high

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

Researchers have identified a significant class of 84 previously unknown vulnerabilities, dubbed 'iTrue' flaws, affecting the core networks of 4G and 5G mobile systems. These vulnerabilities stem from implicit trust errors between network functions, exacerbated by the shift to cloud-native deployments. Exploitation could lead to denial-of-service attacks and session hijacking, where an attacker seizes control of a user's network session.

microsoft

AI to Drive More Windows Security Updates, Microsoft Says

Microsoft anticipates a rise in security updates for Windows due to its growing use of artificial intelligence. The company is leveraging AI to proactively identify vulnerabilities within its software, aiming to enhance overall system security.

it security

Summer Staffing Shortages Expose IT Security Risks

Reduced IT staffing during summer vacation periods can create significant security vulnerabilities. Organizations are advised to leverage AI-driven automation to maintain consistent security operations and minimize reliance on manual processes, ensuring protection remains robust even with fewer personnel.

chromecritical

Chrome 150 Update Fixes 27 Security Flaws

Google has released an update for its Chrome browser, version 150, addressing a total of 27 vulnerabilities. The patch includes fixes for 13 use-after-free bugs, two of which were identified as critical severity.

CVE-2026-50746critical

Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation

Ubiquiti has released security updates to address seven vulnerabilities in its UniFi OS, including several critical flaws. One critical vulnerability, CVE-2026-50746, allows for command injection in the UniFi Connect Application, impacting systems that manage building infrastructure like smart lighting and EV chargers. Other patched issues include SQL injection, improper input validation, and SSRF vulnerabilities across various UniFi applications, potentially leading to privilege escalation.

aihigh

Cybersecurity and the Gap Between Skill and Ability

The increasing capability of AI models to autonomously perform cyberattacks is widening the gap between skill and ability, lowering the barrier to entry for malicious actors. While traditional cybersecurity advice remains relevant, the speed of AI development necessitates a more urgent and adaptive approach. Harnessing AI for defense is seen as a crucial countermeasure, though challenges remain in preventing misuse of powerful AI tools.

ai

OpenClaw: risks for the users and how to mitigate them

OpenClaw, an AI agent ecosystem formerly known as Clawdbot and Moltbot, offers flexibility and task automation but introduces security risks to users and organizations. The system's 'skills' feature, which allows for natural language instructions and easy creation of extensions, can be exploited by attackers. The article aims to explore these security aspects, known vulnerabilities, and mitigation strategies.

CVE-2024-21762high

AI Creates 457 Million Security Issues for Organizations

A recent 30-day analysis revealed over 457 million AI-related security issues across more than 7,000 organizations, averaging 62,000 exposures per company. These issues are largely due to misconfigurations and unmanaged dependencies, rather than traditional CVEs. The findings highlight the need for comprehensive exposure management programs to address the growing risks posed by both approved and unapproved AI tools.

CVE-2026-35273critical

Oracle Releases June Patch Update Addressing 243 Vulnerabilities

Oracle has issued its June Critical Security Patch Update, resolving 243 unique CVEs with 245 security patches. A significant portion, 122 patches, are rated as critical severity. The Oracle Fusion Middleware product family received the largest number of fixes, with 106 patches.