LIVE · cybersecurity feed
Live wire
CVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

vulnerability news

549 stories · page 12 of 12
ransomware

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

This week's security landscape highlights vulnerabilities across a range of technologies, from web browsers and botnets to artificial intelligence systems and email infrastructure. Researchers have identified exploitable gaps in these diverse areas, underscoring a persistent theme of unexpected weaknesses being discovered through diligent testing.

vulnerability

New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos

A new Remote Access Trojan (RAT) named ChocoPoC is being distributed through deceptive proof-of-concept (PoC) exploit repositories on GitHub, specifically targeting vulnerability researchers. These malicious repositories masquerade as legitimate sources for code demonstrating newly discovered vulnerabilities, aiming to trick security professionals into downloading and executing the malware.

CVE-2026-48558critical

'Djinn' Stealer Targets Cloud, AI Credentials

A newly identified information-stealing malware, dubbed "Djinn," is actively targeting credentials that bridge cloud environments, artificial intelligence platforms, and broader enterprise systems. The malware's initial distribution vector exploits a critical authentication bypass vulnerability, identified as CVE-2026-48558, present in the remote support software SimpleHelp.

vulnerabilitycritical

Vulnerabilities Expose Private Data in Indian Government Systems

A security researcher has identified significant vulnerabilities within Indian government systems, one of which could have granted unauthorized access to a national government portal. The researcher, who has not been publicly named, disclosed that a critical flaw could have enabled any individual to gain complete control over the portal.

vulnerabilityhigh

Factoring RSA Keys with Many Zeros

Researchers have identified a new class of weak RSA encryption keys that contain numerous zeros in their structure. These keys, found in real-world deployments, could potentially be factored more easily than standard RSA keys. The discovery was made by analyzing a large dataset of public keys collected from various sources, including Certificate Transparency logs, internet-wide scans for TLS…

vulnerability

Amazon Q VS Extension Flaw Leads to Cloud Credential Theft

A security flaw has been discovered that could allow attackers to steal cloud credentials by planting a malicious repository. This vulnerability affects Amazon's Q, a generative AI assistant, and highlights the increasing risks associated with multi-cloud platform (MCP) environments.

ciscocritical

In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw

A critical vulnerability in Cisco Unified Communications Manager (CUCM) and CUCM Small and Medium Edition (SME) has been actively exploited by attackers less than a day after its public disclosure. The flaw allows for server-side request forgery (SSRF) and enables attackers to escalate their privileges to root access on affected systems.

supply chainhigh

OpenClaw Skill Marketplace Faces AI Supply Chain Threat

OpenClaw, a platform for AI agents that execute third-party skills from its dedicated marketplace, ClawHub, has been targeted by persistent and evolving malicious campaigns. These attacks leverage the unique architecture of AI agent ecosystems, where skills, defined by markdown-driven packages, possess broad access to local systems, making ClawHub a critical vulnerability in the agentic…

vulnerability

Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its June 2026 security update, addressing a total of 206 vulnerabilities across its product range, with 32 of these classified as "critical." The update includes fixes for numerous remote code execution (RCE) and elevation of privilege vulnerabilities affecting core Windows components, as well as products like Microsoft Office, SQL Server, and Azure Kubernetes Service.

vulnerability

Smashing Security podcast #470: This AI security flaw might be impossible to fix

A website that purported to assist travelers with UK visa applications has been found to have collected sensitive personal data, including passport scans and selfies, from thousands of users. The data was reportedly stored in an unsecured Amazon storage bucket, making it accessible to unauthorized individuals. When a journalist attempted to alert the company operating the website, they were…

iothigh

Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO

FortiGuard Labs has identified a new variant of the Gafgyt botnet, dubbed C0XMO, which exhibits cross-platform propagation capabilities by exploiting a vulnerability in DD-WRT router firmware. The malware, discovered in March, utilizes CVE-2021-27137 to gain initial access. A notable characteristic of C0XMO is its separation of lateral movement functions into a distinct Python script, allowing…

vulnerability

DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heap

Researchers have detailed a heap overflow vulnerability affecting systems that process DICOM (Digital Imaging and Communications in Medicine) files, a standard widely used in medical imaging. The vulnerability can be triggered during the image upload process, potentially leading to an out-of-bounds write on an Orthanc server, a popular open-source PACS (Picture Archiving and Communication…

CVE-2025-54957critical

A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens

Researchers have developed a two-exploit chain that can achieve root access on the Google Pixel 10, starting from a zero-click attack vector. This chain builds upon previous work that demonstrated a similar exploit for the Pixel 9.

vulnerability

On the Effectiveness of Mutational Grammar Fuzzing

Mutational grammar fuzzing, a technique that uses predefined grammars to guide sample mutation while preserving structural integrity, faces significant challenges that can hinder bug discovery despite its proven effectiveness. While the approach ensures generated samples adhere to structural rules, leading to the discovery of complex issues in areas like XSLT implementations and JIT engines,…

CVE-2023-41772

A Deep Dive into the GetProcessHandleFromHwnd API

The GetProcessHandleFromHwnd API, a Windows function that allows an application to obtain a handle to the process owning a specific window handle (HWND), has undergone significant changes since its introduction, with its original documentation containing several inaccuracies. Initially believed to be a convenience function relying on window hooks, its implementation and security properties…

breach

Bypassing Administrator Protection by Abusing UI Access

A security researcher has detailed multiple vulnerabilities in Windows' User Account Control (UAC) system, specifically concerning the "UI Access" feature, which were present even before the introduction of Administrator Protection. These bypasses, totaling nine discovered by James Forshaw, have since been addressed by Microsoft. This article focuses on five of these issues, stemming from the…

CVE-2024-54529critical

Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529

A type confusion vulnerability in Apple's CoreAudio framework, identified as CVE-2024-54529, has been successfully exploited by a Google security engineer. The vulnerability resides within the `coreaudiod` system daemon, specifically in the `com.apple.audio.audiohald` Mach service. Researchers discovered that certain message handlers within this service would retrieve an object from an…

vulnerability

Bypassing Windows Administrator Protection

Microsoft's Administrator Protection feature, intended to replace User Account Control (UAC) with a more secure system for granting administrator privileges in Windows 11, has been found to be bypassable. The feature, introduced in Windows 11 version 25H2, aims to allow local users to access administrative rights only when necessary, creating a more robust security boundary. However, security…

CVE-2025-54957critical

A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here?

The Android ecosystem faces significant challenges in mitigating zero-click exploit chains, particularly concerning audio processing components and device drivers, according to recent research. While specific vulnerabilities in the Dolby UDC (Universal Decode Component) and a BigWave driver were identified and exploited, the broader implications highlight systemic issues in attack surface…

breach

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave

A security researcher has identified a critical vulnerability in the Linux kernel used by Google Pixel devices, specifically affecting the BigWave hardware accelerator. This flaw, if exploited, could allow an attacker to escape the restricted "mediacodec" sandbox and gain arbitrary read and write capabilities within the kernel. The vulnerability was discovered by Seth Jenkins, who detailed his…

CVE-2025-49415high

A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby

Google's Pixel 9 devices are susceptible to a zero-click exploit chain that targets the Dolby Unified Decoder (UDC), a component responsible for processing Dolby Digital and Dolby Digital Plus audio formats. This vulnerability allows for arbitrary code execution within the mediacodec context of the device, forming the first stage of a more complex attack. The exploit chain was developed by…