LIVE · cybersecurity feed
Live wire
ASOS Hackers Hijack App Notifications, Claim Snowflake Data BreachKarina Portugal Makes the Case for Know Your AgentAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacksCVE-2026-93836 · Ninja Forms plugin flaw exploited to hack WordPress sitesCVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE Publication

vulnerability news

550 stories · page 6 of 12
supply chain attackhigh

Hackers poison arrayref Rust crate to push infostealer malware

A widely used Rust library, arrayref, was compromised through its maintainer account to distribute infostealer malware during compilation, affecting developers' systems. The attack, which occurred on August 20, also impacted two other crates, append-only-vec and internment, within a 23-minute window.

vulnerability

N-able Bug Exposes Password Vault Master Keys

A recently disclosed vulnerability in N-able's Passportal password manager reportedly exposed master keys for password vaults. The flaw, which affects a product widely used by Managed Service Providers (MSPs) and Small and Medium Businesses (SMBs), raises concerns about the security of cloud-based password management solutions even after a patch has been applied.

malwarehigh

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More

This week's cybersecurity reporting highlights a diverse array of threats and developments, including the exploitation of legitimate signed drivers for malicious kernel operations, a significant cyber espionage campaign attributed to an Iran-based threat actor targeting academic institutions, and the proliferation of malware leveraging DLL sideloading techniques. The landscape also includes…

CVE-2026-73570

Hackers Target Zimbra Servers in Active Exploitation Campaign

CERT Polska has reported an active exploitation campaign targeting Zimbra Collaboration servers. The campaign specifically leverages a vulnerability identified as CVE-2026-73570. Details surrounding the nature of the attacks and the specific impact on affected systems are currently emerging, with CERT Polska providing the initial public alert.

vulnerabilitycritical

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

A critical remote code execution (RCE) vulnerability, identified as CVE-2026-32475, has been discovered in the Elementor Pro WordPress plugin, potentially allowing attackers to upload executable files to affected websites. The flaw impacts Elementor Pro versions prior to 4.2.2.

vulnerability

JFrog Artifactory Flaws Enable Software Supply Chain Attacks

Two vulnerabilities in JFrog Artifactory have been identified that could enable anonymous or low-privileged users to manipulate package metadata without altering the underlying artifacts, potentially leading to software supply chain compromises. The flaws, reported by Oligo Security to JFrog on June 25 and publicly detailed on August 20, have since been patched by JFrog.

CVE-2026-69414

CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

A new zero-day vulnerability, dubbed ShieldBreak and tracked as CVE-2026-69414, has been identified in the Microsoft Malware Protection Engine, a core component of Microsoft Defender. This elevation-of-privilege flaw allows a local attacker with low privileges to escalate their access to SYSTEM level on affected Windows systems.

breachcritical

Frequently asked questions about the active threat to Siemens S7 Series PLCs

Multiple U.S. government agencies have issued a joint cybersecurity advisory warning of active threats targeting Siemens S7 Series programmable logic controllers (PLCs) across critical infrastructure sectors. The advisory, designated AA26-231A, was released on August 19, 2026, by the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau…

javascriptcritical

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

A significant security vulnerability has been identified in the isolated-vm Node.js library, which could allow sandboxed JavaScript code to escape its intended isolation and potentially achieve arbitrary code execution on the host system. The flaw specifically impacts the ExternalCopy component of the library.

CVE-2026-19489critical

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

Citrix has issued urgent security updates for its NetScaler ADC and NetScaler Gateway products to remediate two significant vulnerabilities. The more critical of these, tracked as CVE-2026-19490, carries a CVSS score of 9.3 and enables an authentication bypass. This flaw specifically impacts certain configurations, particularly those where the NetScaler appliance functions as a Gateway or an…

CVE-2026-73570critical

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

Attackers are reportedly exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS) that enables unauthenticated remote code execution. The flaw, tracked as CVE-2026-73570 and assigned a CVSS score of 8.9, is attributed to insufficient input sanitization within the Simple Network Management Protocol (SNMP) notification processing component of ZCS.

vulnerability

BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive

A security research firm has identified a method to repurpose a legitimate, Microsoft-signed Windows Defender component, BTR.sys, into a kernel operation primitive, potentially allowing attackers to execute arbitrary file and registry operations from Ring 0. This technique, dubbed "BTR Reforged," does not rely on traditional exploits, vulnerabilities, or memory corruption, but rather on the…

vulnerabilitycritical

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities

Atlassian and Splunk have released patches addressing numerous critical and high-severity vulnerabilities across their product lines. The reported flaws could potentially be exploited by attackers to achieve arbitrary code execution, gain unauthorized access to sensitive data, and escalate privileges within affected systems. Users of Atlassian and Splunk products are strongly advised to apply…

vulnerability

Citrix urges admins to patch new NetScaler flaws as soon as possible

Citrix has issued an urgent advisory to customers, recommending immediate action to secure systems against two newly disclosed vulnerabilities impacting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. The company confirmed these flaws affect supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including specific FIPS and NDcPP…

vulnerabilitycritical

MLflow Vulnerability Exploited for Cloud Credential Theft

A critical-severity vulnerability in MLflow has reportedly been exploited to facilitate the theft of cloud credentials. The flaw, described as allowing attackers to send HTTP requests to internal endpoints, was observed in active exploitation, leading to the extraction of sensitive information.

nfchigh

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

Researchers have reportedly developed a novel attack, dubbed "Zombie Card," capable of reactivating expired Visa contactless payment cards for in-store transactions. This method reportedly allows an attacker to bypass the expiration date check during a transaction, effectively enabling the use of otherwise invalid cards.

vulnerabilitycritical

Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities

Cisco has released patches addressing critical vulnerabilities in its Crosswork Network Automation and Secure Workload (formerly Tetration) products. These security flaws have been reported to potentially enable remote code execution, authentication bypasses, and path traversal attacks against affected systems. The patches are intended to mitigate the risk posed by these vulnerabilities.

vulnerabilitycritical

CISA warns of hackers exploiting critical MLflow vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to federal agencies regarding active exploitation of a critical vulnerability in MLflow, an open-source AI engineering platform. The flaw, identified as CVE-2026-64849, is a DNS-rebinding server-side request forgery (SSRF) bypass that affects MLflow's outbound webhook delivery.

vulnerability

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

Security researchers at Cycode have reported a chain of vulnerabilities in AIT-GUI, a browser-based operator console developed by NASA/JPL. These flaws reportedly allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrument command bus. The vulnerabilities are tracked under the identifier GHSA-p9r8-2q67-fp86 and have been assigned a CVSS v3.1 score…

vulnerability

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

Cisco Talos researchers have identified a Chinese-speaking cybercrime group, tracked as UAT-10147, that is integrating agentic artificial intelligence (AI) into its post-compromise operations. The group targets Windows and Linux web servers globally, affecting organizations in government, education, media, technology, and gaming sectors. This activity was first observed in early 2026.

vulnerabilitycritical

Critical Zimbra RCE flaw now actively exploited in attacks

A critical remote code execution (RCE) vulnerability in Zimbra Collaboration Suite (ZCS), identified as CVE-2026-73570, is now being actively exploited by attackers. CERT Polska, the Polish Computer Emergency Response Team, issued a warning on Monday, August 17, 2026, confirming the in-the-wild exploitation of this flaw.

CVE-2026-64849critical

U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical server-side request forgery (SSRF) vulnerability in MLflow, tracked as CVE-2026-64849, to its Known Exploited Vulnerabilities (KEV) catalog. This designation indicates that the flaw is actively being exploited in the wild.

vulnerabilitycritical

Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler

A critical authentication bypass vulnerability has been reported in Citrix NetScaler, with exploitation anticipated by security researchers. The flaw allows remote, unauthenticated attackers to compromise affected systems without requiring any user interaction. This type of vulnerability is particularly severe due to its low complexity of exploitation and high potential impact.

CVE-2026-19478critical

Critical GitLab Flaw Exploited Shortly After Disclosure

A critical vulnerability in GitLab, identified as CVE-2026-19478, has reportedly been exploited in the wild shortly after its public disclosure. This flaw is particularly severe as it allows unauthenticated attackers to modify or delete public projects and associated user data within affected GitLab instances. The rapid exploitation highlights the urgency for organizations to address this…

CVE-2026-32475critical

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Cybersecurity researchers have reported a critical vulnerability in the Elementor Pro WordPress plugin that could enable unauthenticated attackers to upload PHP files and achieve remote code execution. The flaw, identified as CVE-2026-32475, has been assigned a CVSS score of 9.0, indicating a high level of severity.

vulnerabilitycritical

8,539 reasons to rethink how vulnerabilities get patched

The volume of high- and critical-severity vulnerability disclosures has doubled in the past year, with 8,539 recorded in Q2 2026, according to a recent industry report. This surge is intensifying pressure on security teams, who must prioritize which flaws to address immediately, often contending with a rapidly shrinking window between disclosure and exploit weaponization.

spectrehigh

Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

Cybersecurity researchers have reportedly demonstrated a refined Spectre attack targeting Cloudflare Workers, successfully exfiltrating a JSON Web Token (JWT) from a co-located Worker. The attack achieved a data leakage rate of 12 bits per second, which is described as a significant improvement in speed over prior iterations of similar attacks.

vulnerabilitycritical

NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology

Federal agencies have issued an urgent warning regarding an active threat targeting critical infrastructure organizations, noting an evolution in attacker capabilities driven by the use of AI-generated exploit scripts. The National Security Agency (NSA) and the FBI, among other federal bodies, advised organizations to prioritize response efforts, particularly concerning programmable logic…

CVE-2024-39943high

Operation CameraSwarm Compromised 14,000+ Dahua Cameras

An exposed operator directory has revealed details of "Operation CameraSwarm," an attack that compromised over 14,000 Dahua cameras, primarily in Ukraine and Russia, between June 17 and July 22, 2026. The operation was reconstructed by Hunt.io researchers after their AttackCapture system discovered an open HTTP directory on a server at 154.86[.]119.60 on July 23, exposing 407 MB of the…

CVE-2026-19490critical

CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway

Citrix has issued an urgent security advisory concerning CVE-2026-19490, a critical authentication bypass vulnerability affecting its NetScaler ADC and NetScaler Gateway products. The flaw, which carries a CVSS v4.0 base score of 9.3, allows an unauthenticated attacker to remotely exploit affected systems over a network without requiring user interaction or elevated privileges.

vulnerability

Exclusive: Linux Foundation's Akrites to Go Live in September

Akrites, a major industry coalition established by the Linux Foundation and the Open Source Security Foundation (OpenSSF) to protect critical open-source software from AI-enabled cyber threats, is expected to launch its vulnerability disclosure and remediation platform in September 2026. The initiative, announced in late June 2026, aims to coordinate AI-enabled vulnerability reports and…

vulnerabilitycritical

The long tail of Clop’s PTC hack is just beginning to emerge

A cybercrime group known as Clop has reportedly exploited a critical zero-day vulnerability in PTC's Windchill and FlexPLM software, leading to claims of data theft from numerous organizations. The vulnerability, identified as CVE-2026-12569, allows unauthenticated attackers to execute code remotely.

vulnerabilitycritical

Oracle Critical Patch Update, August 2026 Security Update Review

Oracle has released its August 2026 Critical Patch Update, addressing a total of 943 security vulnerabilities across its diverse product portfolio. The update includes patches for various product families, with some vulnerabilities impacting multiple products and incorporating fixes for third-party components.

CVE-2021-33044high

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Cybersecurity researchers have reported a campaign, identified as Operation CameraSwarm, that led to the compromise of more than 14,500 Dahua devices. The activity was observed between June and July 2026. The attackers reportedly leveraged a combination of credential-based attacks, specific authentication bypass vulnerabilities, and a peer-to-peer (P2P) relay method to achieve unauthorized…

vulnerability

Microsoft fixes known issue causing Windows Defender crashes

Microsoft has confirmed and resolved a bug that caused its Defender antivirus software to crash on some Windows 10 and Windows 11 systems. The issue, which began on Tuesday afternoon, August 19, 2026, manifested as "Threat service has stopped. Restart it now" error messages and 0xc0000005 access violation errors.

CVE-2026-65400critical

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding four critical vulnerabilities that are reportedly under active exploitation. These flaws affect Apple macOS, Microsoft SharePoint, VMware vCenter Server, and Microsoft Internet Key Exchange (IKE). CISA has added these vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating…

vulnerability

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for organizations to immediately patch several exploited vulnerabilities affecting products from Microsoft, VMware, and Apple. These security flaws are reportedly being actively leveraged in the wild, posing significant risks to affected systems and data. The agency's alert emphasizes the critical need…

vulnerabilitycritical

Critical RCE flaw in Windows IKE Extension now actively exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding active exploitation of a critical remote code execution (RCE) vulnerability within the Windows Internet Key Exchange (IKE) Service Extensions component. This flaw, identified as CVE-2026-33824, affects all supported versions of Windows 10, Windows 11, and Windows Server.

vulnerability

943 Patches Rolled Out With Oracle’s August 2026 Security Update

Oracle has released its August 2026 Critical Patch Update (CPU), which includes 943 security fixes addressing a wide array of vulnerabilities across its product portfolio. This extensive update resolves over 1,000 individual vulnerabilities, with a significant portion of these issues being remotely exploitable.

vulnerabilitycritical

Google’s AI security agents found 100+ critical software vulnerabilities in just two days

Google's Mandiant security division has revealed an internal AI-driven tool designed to identify software vulnerabilities, which successfully uncovered over 100 verified, high-severity flaws in just two days during a live investigation of stolen corporate code repositories. The tool, named the Agentic Vulnerability Discovery Harness (AVDH), has been operational within Mandiant for ten months,…

CVE-2026-33824

U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies patch them by August 21, 2026. The newly cataloged flaws affect Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft Internet Key Exchange (IKE) Service Extensions.

vulnerabilitycritical

Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs

Oracle has released its August 2026 Critical Security Patch Update (CSPU), addressing 925 unique Common Vulnerabilities and Exposures (CVEs) through 943 security updates across 23 of its product families. This update includes 154 critical severity patches, accounting for 16.3% of the total fixes.

CVE-2026-68820high

CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now

A critical use-after-free vulnerability, identified as CVE-2026-68820, in the Windows Ancillary Function Driver for WinSock (afd.sys) is currently under active exploitation and has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability allows a low-privilege local attacker to escalate privileges to SYSTEM without requiring user interaction.

vulnerability

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Varonis Threat Labs has reported the discovery of three vulnerabilities in Microsoft Copilot Personal. These flaws, collectively dubbed "CoSnitch" by the researchers, reportedly enable data exfiltration from connected applications and other information accessible within a victim's Copilot session through a single click on a specially crafted link. The researchers indicated that one aspect of…

vulnerabilitycritical

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Recent reports indicate active exploitation attempts targeting a Server-Side Request Forgery (SSRF) vulnerability within MLflow, an open-source artificial intelligence platform. Attackers are reportedly leveraging this flaw to exfiltrate cloud credentials and other sensitive secrets. This activity highlights the ongoing risk associated with critical vulnerabilities in widely adopted platforms,…

vulnerabilitycritical

Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed

Security researchers at Wiz, a cloud security company, have identified a critical script injection vulnerability in a public GitHub repository maintained by Snowflake. The flaw, found in the `snowflakedb/snowflake-connector-net` repository, specifically affected its GitHub Actions workflows.

phishinghigh

CISA gives feds 3 days to fix actively exploited Ray RCE bug

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for federal agencies to patch a critical vulnerability in the open-source Ray framework within three days. The flaw, identified as CVE-2025-62593, is actively being exploited and carries a CVSS v4 score of 9.4, indicating a severe risk of remote code execution (RCE).

vulnerabilitycritical

NASA Ground Control Software Flaw Enables Unauthenticated Commands

A critical vulnerability has been discovered in NASA's open-source AMMOS Instrument Toolkit (AIT)-GUI ground software, which could allow unauthenticated attackers to issue commands to spacecraft and instruments, execute server-side scripts, and run command sequences. The flaw, identified as GHSA-p9r8-2q67-fp86, carries a CVSS rating of 9.4 and affects AIT-GUI versions up to and including…