vulnerability news
550 stories · page 6 of 12
Hackers poison arrayref Rust crate to push infostealer malware
A widely used Rust library, arrayref, was compromised through its maintainer account to distribute infostealer malware during compilation, affecting developers' systems. The attack, which occurred on August 20, also impacted two other crates, append-only-vec and internment, within a 23-minute window.

N-able Bug Exposes Password Vault Master Keys
A recently disclosed vulnerability in N-able's Passportal password manager reportedly exposed master keys for password vaults. The flaw, which affects a product widely used by Managed Service Providers (MSPs) and Small and Medium Businesses (SMBs), raises concerns about the security of cloud-based password management solutions even after a patch has been applied.

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More
This week's cybersecurity reporting highlights a diverse array of threats and developments, including the exploitation of legitimate signed drivers for malicious kernel operations, a significant cyber espionage campaign attributed to an Iran-based threat actor targeting academic institutions, and the proliferation of malware leveraging DLL sideloading techniques. The landscape also includes…

Hackers Target Zimbra Servers in Active Exploitation Campaign
CERT Polska has reported an active exploitation campaign targeting Zimbra Collaboration servers. The campaign specifically leverages a vulnerability identified as CVE-2026-73570. Details surrounding the nature of the attacks and the specific impact on affected systems are currently emerging, with CERT Polska providing the initial public alert.

Critical Elementor Pro bug exposes WordPress sites to RCE attacks
A critical remote code execution (RCE) vulnerability, identified as CVE-2026-32475, has been discovered in the Elementor Pro WordPress plugin, potentially allowing attackers to upload executable files to affected websites. The flaw impacts Elementor Pro versions prior to 4.2.2.

JFrog Artifactory Flaws Enable Software Supply Chain Attacks
Two vulnerabilities in JFrog Artifactory have been identified that could enable anonymous or low-privileged users to manipulate package metadata without altering the underlying artifacts, potentially leading to software supply chain compromises. The flaws, reported by Oligo Security to JFrog on June 25 and publicly detailed on August 20, have since been patched by JFrog.

CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days
A new zero-day vulnerability, dubbed ShieldBreak and tracked as CVE-2026-69414, has been identified in the Microsoft Malware Protection Engine, a core component of Microsoft Defender. This elevation-of-privilege flaw allows a local attacker with low privileges to escalate their access to SYSTEM level on affected Windows systems.

Frequently asked questions about the active threat to Siemens S7 Series PLCs
Multiple U.S. government agencies have issued a joint cybersecurity advisory warning of active threats targeting Siemens S7 Series programmable logic controllers (PLCs) across critical infrastructure sectors. The advisory, designated AA26-231A, was released on August 19, 2026, by the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau…

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
A significant security vulnerability has been identified in the isolated-vm Node.js library, which could allow sandboxed JavaScript code to escape its intended isolation and potentially achieve arbitrary code execution on the host system. The flaw specifically impacts the ExternalCopy component of the library.

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Citrix has issued urgent security updates for its NetScaler ADC and NetScaler Gateway products to remediate two significant vulnerabilities. The more critical of these, tracked as CVE-2026-19490, carries a CVSS score of 9.3 and enables an authentication bypass. This flaw specifically impacts certain configurations, particularly those where the NetScaler appliance functions as a Gateway or an…

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
Attackers are reportedly exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS) that enables unauthenticated remote code execution. The flaw, tracked as CVE-2026-73570 and assigned a CVSS score of 8.9, is attributed to insufficient input sanitization within the Simple Network Management Protocol (SNMP) notification processing component of ZCS.

BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
A security research firm has identified a method to repurpose a legitimate, Microsoft-signed Windows Defender component, BTR.sys, into a kernel operation primitive, potentially allowing attackers to execute arbitrary file and registry operations from Ring 0. This technique, dubbed "BTR Reforged," does not rely on traditional exploits, vulnerabilities, or memory corruption, but rather on the…

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities
Atlassian and Splunk have released patches addressing numerous critical and high-severity vulnerabilities across their product lines. The reported flaws could potentially be exploited by attackers to achieve arbitrary code execution, gain unauthorized access to sensitive data, and escalate privileges within affected systems. Users of Atlassian and Splunk products are strongly advised to apply…

Citrix urges admins to patch new NetScaler flaws as soon as possible
Citrix has issued an urgent advisory to customers, recommending immediate action to secure systems against two newly disclosed vulnerabilities impacting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. The company confirmed these flaws affect supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including specific FIPS and NDcPP…

MLflow Vulnerability Exploited for Cloud Credential Theft
A critical-severity vulnerability in MLflow has reportedly been exploited to facilitate the theft of cloud credentials. The flaw, described as allowing attackers to send HTTP requests to internal endpoints, was observed in active exploitation, leading to the extraction of sensitive information.

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
Researchers have reportedly developed a novel attack, dubbed "Zombie Card," capable of reactivating expired Visa contactless payment cards for in-store transactions. This method reportedly allows an attacker to bypass the expiration date check during a transaction, effectively enabling the use of otherwise invalid cards.

Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
Cisco has released patches addressing critical vulnerabilities in its Crosswork Network Automation and Secure Workload (formerly Tetration) products. These security flaws have been reported to potentially enable remote code execution, authentication bypasses, and path traversal attacks against affected systems. The patches are intended to mitigate the risk posed by these vulnerabilities.

CISA warns of hackers exploiting critical MLflow vulnerability
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to federal agencies regarding active exploitation of a critical vulnerability in MLflow, an open-source AI engineering platform. The flaw, identified as CVE-2026-64849, is a DNS-rebinding server-side request forgery (SSRF) bypass that affects MLflow's outbound webhook delivery.

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
Security researchers at Cycode have reported a chain of vulnerabilities in AIT-GUI, a browser-based operator console developed by NASA/JPL. These flaws reportedly allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrument command bus. The vulnerabilities are tracked under the identifier GHSA-p9r8-2q67-fp86 and have been assigned a CVSS v3.1 score…

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Cisco Talos researchers have identified a Chinese-speaking cybercrime group, tracked as UAT-10147, that is integrating agentic artificial intelligence (AI) into its post-compromise operations. The group targets Windows and Linux web servers globally, affecting organizations in government, education, media, technology, and gaming sectors. This activity was first observed in early 2026.

Critical Zimbra RCE flaw now actively exploited in attacks
A critical remote code execution (RCE) vulnerability in Zimbra Collaboration Suite (ZCS), identified as CVE-2026-73570, is now being actively exploited by attackers. CERT Polska, the Polish Computer Emergency Response Team, issued a warning on Monday, August 17, 2026, confirming the in-the-wild exploitation of this flaw.

U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical server-side request forgery (SSRF) vulnerability in MLflow, tracked as CVE-2026-64849, to its Known Exploited Vulnerabilities (KEV) catalog. This designation indicates that the flaw is actively being exploited in the wild.

Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler
A critical authentication bypass vulnerability has been reported in Citrix NetScaler, with exploitation anticipated by security researchers. The flaw allows remote, unauthenticated attackers to compromise affected systems without requiring any user interaction. This type of vulnerability is particularly severe due to its low complexity of exploitation and high potential impact.

Critical GitLab Flaw Exploited Shortly After Disclosure
A critical vulnerability in GitLab, identified as CVE-2026-19478, has reportedly been exploited in the wild shortly after its public disclosure. This flaw is particularly severe as it allows unauthenticated attackers to modify or delete public projects and associated user data within affected GitLab instances. The rapid exploitation highlights the urgency for organizations to address this…

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
Cybersecurity researchers have reported a critical vulnerability in the Elementor Pro WordPress plugin that could enable unauthenticated attackers to upload PHP files and achieve remote code execution. The flaw, identified as CVE-2026-32475, has been assigned a CVSS score of 9.0, indicating a high level of severity.

8,539 reasons to rethink how vulnerabilities get patched
The volume of high- and critical-severity vulnerability disclosures has doubled in the past year, with 8,539 recorded in Q2 2026, according to a recent industry report. This surge is intensifying pressure on security teams, who must prioritize which flaws to address immediately, often contending with a rapidly shrinking window between disclosure and exploit weaponization.

Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
Cybersecurity researchers have reportedly demonstrated a refined Spectre attack targeting Cloudflare Workers, successfully exfiltrating a JSON Web Token (JWT) from a co-located Worker. The attack achieved a data leakage rate of 12 bits per second, which is described as a significant improvement in speed over prior iterations of similar attacks.

NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology
Federal agencies have issued an urgent warning regarding an active threat targeting critical infrastructure organizations, noting an evolution in attacker capabilities driven by the use of AI-generated exploit scripts. The National Security Agency (NSA) and the FBI, among other federal bodies, advised organizations to prioritize response efforts, particularly concerning programmable logic…

Operation CameraSwarm Compromised 14,000+ Dahua Cameras
An exposed operator directory has revealed details of "Operation CameraSwarm," an attack that compromised over 14,000 Dahua cameras, primarily in Ukraine and Russia, between June 17 and July 22, 2026. The operation was reconstructed by Hunt.io researchers after their AttackCapture system discovered an open HTTP directory on a server at 154.86[.]119.60 on July 23, exposing 407 MB of the…

CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
Citrix has issued an urgent security advisory concerning CVE-2026-19490, a critical authentication bypass vulnerability affecting its NetScaler ADC and NetScaler Gateway products. The flaw, which carries a CVSS v4.0 base score of 9.3, allows an unauthenticated attacker to remotely exploit affected systems over a network without requiring user interaction or elevated privileges.

Exclusive: Linux Foundation's Akrites to Go Live in September
Akrites, a major industry coalition established by the Linux Foundation and the Open Source Security Foundation (OpenSSF) to protect critical open-source software from AI-enabled cyber threats, is expected to launch its vulnerability disclosure and remediation platform in September 2026. The initiative, announced in late June 2026, aims to coordinate AI-enabled vulnerability reports and…

The long tail of Clop’s PTC hack is just beginning to emerge
A cybercrime group known as Clop has reportedly exploited a critical zero-day vulnerability in PTC's Windchill and FlexPLM software, leading to claims of data theft from numerous organizations. The vulnerability, identified as CVE-2026-12569, allows unauthenticated attackers to execute code remotely.

Oracle Critical Patch Update, August 2026 Security Update Review
Oracle has released its August 2026 Critical Patch Update, addressing a total of 943 security vulnerabilities across its diverse product portfolio. The update includes patches for various product families, with some vulnerabilities impacting multiple products and incorporating fixes for third-party components.

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Cybersecurity researchers have reported a campaign, identified as Operation CameraSwarm, that led to the compromise of more than 14,500 Dahua devices. The activity was observed between June and July 2026. The attackers reportedly leveraged a combination of credential-based attacks, specific authentication bypass vulnerabilities, and a peer-to-peer (P2P) relay method to achieve unauthorized…

Microsoft fixes known issue causing Windows Defender crashes
Microsoft has confirmed and resolved a bug that caused its Defender antivirus software to crash on some Windows 10 and Windows 11 systems. The issue, which began on Tuesday afternoon, August 19, 2026, manifested as "Threat service has stopped. Restart it now" error messages and 0xc0000005 access violation errors.

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding four critical vulnerabilities that are reportedly under active exploitation. These flaws affect Apple macOS, Microsoft SharePoint, VMware vCenter Server, and Microsoft Internet Key Exchange (IKE). CISA has added these vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating…

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for organizations to immediately patch several exploited vulnerabilities affecting products from Microsoft, VMware, and Apple. These security flaws are reportedly being actively leveraged in the wild, posing significant risks to affected systems and data. The agency's alert emphasizes the critical need…

Critical RCE flaw in Windows IKE Extension now actively exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding active exploitation of a critical remote code execution (RCE) vulnerability within the Windows Internet Key Exchange (IKE) Service Extensions component. This flaw, identified as CVE-2026-33824, affects all supported versions of Windows 10, Windows 11, and Windows Server.

943 Patches Rolled Out With Oracle’s August 2026 Security Update
Oracle has released its August 2026 Critical Patch Update (CPU), which includes 943 security fixes addressing a wide array of vulnerabilities across its product portfolio. This extensive update resolves over 1,000 individual vulnerabilities, with a significant portion of these issues being remotely exploitable.

Google’s AI security agents found 100+ critical software vulnerabilities in just two days
Google's Mandiant security division has revealed an internal AI-driven tool designed to identify software vulnerabilities, which successfully uncovered over 100 verified, high-severity flaws in just two days during a live investigation of stolen corporate code repositories. The tool, named the Agentic Vulnerability Discovery Harness (AVDH), has been operational within Mandiant for ten months,…

U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies patch them by August 21, 2026. The newly cataloged flaws affect Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft Internet Key Exchange (IKE) Service Extensions.

Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs
Oracle has released its August 2026 Critical Security Patch Update (CSPU), addressing 925 unique Common Vulnerabilities and Exposures (CVEs) through 943 security updates across 23 of its product families. This update includes 154 critical severity patches, accounting for 16.3% of the total fixes.

CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now
A critical use-after-free vulnerability, identified as CVE-2026-68820, in the Windows Ancillary Function Driver for WinSock (afd.sys) is currently under active exploitation and has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability allows a low-privilege local attacker to escalate privileges to SYSTEM without requiring user interaction.
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Varonis Threat Labs has reported the discovery of three vulnerabilities in Microsoft Copilot Personal. These flaws, collectively dubbed "CoSnitch" by the researchers, reportedly enable data exfiltration from connected applications and other information accessible within a victim's Copilot session through a single click on a specially crafted link. The researchers indicated that one aspect of…

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Recent reports indicate active exploitation attempts targeting a Server-Side Request Forgery (SSRF) vulnerability within MLflow, an open-source artificial intelligence platform. Attackers are reportedly leveraging this flaw to exfiltrate cloud credentials and other sensitive secrets. This activity highlights the ongoing risk associated with critical vulnerabilities in widely adopted platforms,…

Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed
Security researchers at Wiz, a cloud security company, have identified a critical script injection vulnerability in a public GitHub repository maintained by Snowflake. The flaw, found in the `snowflakedb/snowflake-connector-net` repository, specifically affected its GitHub Actions workflows.

CISA gives feds 3 days to fix actively exploited Ray RCE bug
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for federal agencies to patch a critical vulnerability in the open-source Ray framework within three days. The flaw, identified as CVE-2025-62593, is actively being exploited and carries a CVSS v4 score of 9.4, indicating a severe risk of remote code execution (RCE).

NASA Ground Control Software Flaw Enables Unauthenticated Commands
A critical vulnerability has been discovered in NASA's open-source AMMOS Instrument Toolkit (AIT)-GUI ground software, which could allow unauthenticated attackers to issue commands to spacecraft and instruments, execute server-side scripts, and run command sequences. The flaw, identified as GHSA-p9r8-2q67-fp86, carries a CVSS rating of 9.4 and affects AIT-GUI versions up to and including…