LIVE · cybersecurity feed
Live wire
ASOS Hackers Hijack App Notifications, Claim Snowflake Data BreachKarina Portugal Makes the Case for Know Your AgentAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacksCVE-2026-93836 · Ninja Forms plugin flaw exploited to hack WordPress sitesCVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE Publication

vulnerability news

550 stories · page 8 of 12
vulnerability

Belgium's eID Authentication Opens Citizen Accounts to RCE

A recent report indicates that Belgium's national electronic identification (eID) authentication system was found to be fully compromised due to severe vulnerabilities present in a critical browser extension. This compromise reportedly exposed citizen accounts to potential remote code execution (RCE) attacks, highlighting significant security concerns not only with the specific eID system but…

CVE-2026-55040critical

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability, identified as CVE-2026-55040, according to recent reports. This exploitation campaign began shortly after a proof-of-concept (PoC) exploit for the flaw was publicly released. The vulnerability is described as a security feature bypass, enabling unauthenticated attackers to impersonate legitimate users within…

CVE-2026-4890high

Dnsmasq DNSSEC Vulnerability Leads to Denial-of-Service

A critical denial-of-service vulnerability, identified as CVE-2026-4890, has been disclosed in Dnsmasq, a widely used DNS forwarder and DHCP server. The flaw, which received a CVSS score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), allows remote attackers to trigger an infinite loop by sending specially crafted DNSSEC NSEC/NSEC3 records, leading to a denial-of-service condition.

CVE-2026-20148

Cisco Identity Services Engine Vulnerability Discloses Sensitive Information

Cisco has released a security update for its Identity Services Engine (ISE) to address a directory traversal vulnerability that could lead to sensitive information disclosure. The flaw, identified as CVE-2026-20148, carries a CVSS score of 4.9 and is tracked as ZDI-26-582 and ZDI-CAN-28708.

linuxhigh

ZDI-26-576: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability

A race condition vulnerability, identified as ZDI-26-576, has been reported in the Linux Kernel's XFRM (IPSec) subsystem. This flaw reportedly allows local attackers to escalate privileges on affected systems. The issue specifically involves improper locking mechanisms during operations on skb (socket buffer) objects within the XFRM component.

CVE-2026-20190high

Cisco Identity Services Engine Leaks Information Due to Missing Authentication

Cisco has addressed a critical information disclosure vulnerability in its Identity Services Engine (ISE) that could allow unauthenticated remote attackers to access sensitive data, including stored credentials. The flaw, identified as CVE-2026-20190, stems from a missing authentication check in the handling of upgrade files.

linux kernelhigh

ZDI-26-575: Linux Kernel Net Scheduler Packet Classifier API Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability

A local privilege escalation vulnerability has been identified in the Linux Kernel's Net Scheduler Packet Classifier API, tracked as ZDI-26-575 and CVE-2026-31419. This flaw could allow an attacker to execute code with kernel-level privileges.

nginxcritical

ZDI-26-578: NGINX HTTP Dav Module Alias Directive Integer Underflow Remote Code Execution Vulnerability

A critical remote code execution vulnerability has been reported in the NGINX HTTP WebDAV module. The flaw, identified as ZDI-26-578, is described as an integer underflow that arises from insufficient validation of user-supplied data during the parsing of WebDAV requests. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.

CVE-2026-20181high

Cisco Identity Services Engine Vulnerable to RCE via Directory Traversal

Cisco has released a security update for its Identity Services Engine (ISE) to address a critical remote code execution (RCE) vulnerability, identified as CVE-2026-20181. The flaw, which carries a CVSS score of 7.2, stems from a directory traversal vulnerability within the `zipFiles` method of the software.

CVE-2026-20147high

Cisco Identity Services Engine Vulnerable to Command Injection

A critical command injection vulnerability has been reported in Cisco Identity Services Engine (ISE), potentially allowing remote attackers to execute arbitrary code. While the flaw is severe, successful exploitation requires prior authentication to the system. The vulnerability has been assigned a CVSS score of 7.2, indicating a high level of concern despite the authentication prerequisite.

vulnerability

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers

Wireshark version 4.6.8 has been released, addressing a total of 28 security vulnerabilities within the popular network protocol analyzer. Nine of these critical flaws are located in file parsers, meaning they can be triggered simply by opening a specially crafted capture file without any network interaction.

CVE-2026-71362critical

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Exploitation attempts have been detected for a critical vulnerability in Adobe Commerce and Magento e-commerce platforms, identified as CVE-2026-71362. This flaw, described as an incorrect authorization vulnerability, could allow attackers to gain elevated access to sensitive resources without authentication, potentially leading to customer account hijackings.

vulnerability

Qualys Introduces Real-Time Cloud Security Posture Management (CSPM) for Faster Risk Detection and Remediation

Qualys has announced the release of Real-Time Cloud Security Posture Management (CSPM), a new capability integrated into the Qualys Cloud Platform designed to provide instant detection and remediation guidance for cloud security risks across multi-cloud environments. The new offering aims to address the limitations of traditional CSPM tools that rely on periodic scans, which can leave…

vulnerability

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Security researchers Alejandro Hernando and Borja Martínez have unveiled a new class of "Plug and Pwn" attacks that leverage the Windows Plug and Play feature to achieve SYSTEM-level privileges. Presented at DEF CON 34, their research demonstrates how Windows' automatic hardware identification and driver installation process can be exploited to install vulnerable or insecure vendor software.

CVE-2026-68820

Lazarus hackers exploited Windows zero-day to target defense firms

North Korean state-sponsored hackers, identified as the Lazarus Group, have been exploiting a Windows zero-day vulnerability, designated CVE-2026-68820, as part of their ongoing Operation Dream Job campaign. The vulnerability, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (AFD.sys), allows for local privilege escalation. Microsoft confirmed the active exploitation…

vulnerabilityhigh

SharePoint Vulnerability Exploited Shortly After PoC Release

A vulnerability affecting Microsoft SharePoint has reportedly been exploited in the wild shortly after the release of a proof-of-concept (PoC) exploit. The flaw was previously patched by Microsoft in July, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) had issued a warning regarding its potential for active exploitation.

vulnerabilitycritical

“Zoomsday” flaws could let one Zoom participant attack another

Three vulnerabilities, collectively dubbed "Zoomsday" by researchers, have been identified in the Zoom meeting platform. These flaws, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, could enable one participant in a Zoom meeting to compromise another through specially crafted collaboration data.

vulnerabilitycritical

Patch Tuesday: Update now to fix 421 flaws, including three zero-days

Microsoft’s August 2026 Patch Tuesday addresses 421 vulnerabilities across its product line, including 62 rated as critical. The update package, while smaller than July’s record release, remains one of the largest Patch Tuesday batches to date. Among the fixes are three zero-day vulnerabilities, one of which has been actively exploited in the wild by the Lazarus group.

ransomwarecritical

Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure

A joint advisory from U.S. and Republic of Korea authorities has warned that the Gunra ransomware-as-a-service (RaaS) operation is actively exploiting two Fortinet vulnerabilities to target government and critical national infrastructure organizations. The advisory, issued on August 10, was authored by the FBI, CISA, and other U.S. government agencies, alongside the Republic of Korea’s…

vulnerability

Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery

Microsoft released fixes for 419 security vulnerabilities in its latest Patch Tuesday update, marking one of the largest monthly counts on record. This follows a trend of escalating vulnerability disclosures, with 137 patches in May, 206 in June, and 622 in July, surpassing the company's annual record of approximately 1,250 vulnerabilities. The company has indicated that AI-powered…

vulnerability

NIST Seeks Public Input on AI-Ready NVD Modernization

The U.S. National Institute of Standards and Technology (NIST) has initiated a public consultation to modernize its National Vulnerability Database (NVD), aiming to integrate artificial intelligence (AI) and automation workflows. This effort, announced in a Request for Information (RFI) published in the Federal Register on August 12, seeks to adapt the NVD to a cybersecurity landscape…

vulnerabilitycritical

Hackers leverage new Microsoft SharePoint exploit in attacks

A proof-of-concept (PoC) exploit for a critical authentication bypass vulnerability in Microsoft SharePoint, identified as CVE-2026-55040, is reportedly being actively used in attacks. Cybersecurity firm Rapid7 published a detailed technical write-up and the PoC exploit code on Tuesday, August 11, 2026.

vulnerability

CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign

The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies patch a critical Microsoft Windows vulnerability, CVE-2026-68820, by August 25. This directive follows confirmation from both CISA and Microsoft that the flaw is actively being exploited in real-world attacks, notably by North Korean state-sponsored hackers.

aihigh

API Flaw Exposes AI Reasoning and Secrets

A significant vulnerability has been identified in the API reasoning services provided by major AI developers OpenAI, Anthropic, and Google. Researchers reportedly discovered a flaw that permitted the extraction of sensitive information, including API keys and passwords, from session logs. The core of the issue revolved around encrypted reasoning objects that could be replayed across disparate…

breach

Ivanti EPM Update Patches Remotely Exploitable Flaws

Ivanti has released an update for its Endpoint Manager (EPM) software to address several remotely exploitable vulnerabilities. These flaws, if successfully exploited, could lead to the leakage of credentials used for external SQL connections or cause an agent service to crash. The update is critical for maintaining the integrity and availability of systems managed by EPM.

vulnerability

PentestGPT: Open-source automated penetration testing agentic framework

A new open-source penetration testing agent, PentestGPT, has been released, designed to automate the process of identifying vulnerabilities in target systems. The framework, developed by Gelei Deng and a team of colleagues, was initially presented at USENIX Security 2024.

CVE-2026-20349

Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

Cisco has released patches for a zero-day vulnerability in its Secure Firewall ASA and FTD devices, which has reportedly been exploited in the wild to launch denial-of-service (DoS) attacks. The flaw, identified as CVE-2026-20349, allows for remote exploitation without requiring authentication, posing a significant risk to affected systems.

vulnerabilitycritical

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security updates for August 2026, addressing a total of 421 vulnerabilities across various products. Of these, 62 are classified as "critical" by Microsoft. The company confirmed that one of the vulnerabilities, CVE-2026-68820, an elevation of privilege flaw in the Windows Ancillary Function Driver for WinSock, has already been exploited in the wild. This…

vulnerabilitycritical

Microsoft Patch Tuesday, August 2026 Security Update Review

Microsoft's August 2026 Patch Tuesday release addresses 421 vulnerabilities, including 62 critical and 357 important-severity issues across a broad range of products and services. This month's updates include fixes for three zero-day vulnerabilities, one of which has been actively exploited in the wild, while the other two were publicly disclosed prior to the patch release.

vulnerability

421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one

Microsoft's August Patch Tuesday release addresses 421 vulnerabilities across its product line, with one critical flaw, CVE-2026-68820, confirmed by Microsoft to have been exploited as a zero-day by North Korea's Lazarus Group. This use-after-free vulnerability resides in the Windows Ancillary Function Driver for WinSock.

vulnerabilityhigh

Microsoft Plugs Nearly 400 Security Holes

Microsoft released updates on August 11, 2026, to address 398 security vulnerabilities in its Windows operating systems and associated software. This extensive patch includes fixes for one vulnerability that is actively being exploited in the wild and two others that were publicly disclosed prior to the release.

ransomwarecritical

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

Reports indicate that the Gunra ransomware-as-a-service (RaaS) operation is actively exploiting unpatched vulnerabilities in Fortinet firewalls and VPN appliances to gain initial access to target networks. The gang has reportedly been successful in compromising critical infrastructure organizations, leveraging these flaws to bypass multi-factor authentication (MFA) mechanisms. This activity…

CVE-2026-68820

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft has reportedly issued its monthly security updates, addressing a substantial number of vulnerabilities, including a Windows kernel driver zero-day that is actively being exploited in the wild. This critical flaw is said to be present in a core Windows kernel driver responsible for managing network socket operations. The update package reportedly includes patches for 398 distinct…

vulnerabilityhigh

Cisco warns of ASA and FTD VPN flaw exploited to crash devices

Cisco has issued a warning regarding a high-severity denial-of-service vulnerability, identified as CVE-2026-20349, which is actively being exploited to remotely crash affected devices. The flaw, with a CVSS score of 8.6, impacts devices running Cisco Secure Firewall Adaptive Security Appliance (ASA) or Secure Firewall Threat Defense (FTD) software when specific remote access services are enabled.

vulnerabilitycritical

Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)

Microsoft's August 2026 Patch Tuesday, released on Tuesday, August 11th, addressed a substantial volume of security vulnerabilities across its product line. The update package included fixes for a total of 418 vulnerabilities. Among these, 62 were categorized as critical, indicating their potential for severe impact without user interaction. The release also notably included patches for one…

vulnerability

Windows 11 KB5121003 & KB5120240 cumulative updates released

Microsoft has released the August 2026 Patch Tuesday cumulative updates, KB5121003 and KB5120240, for Windows 11 versions 25H2/24H2 and 23H2. These updates are mandatory and address 400 security vulnerabilities identified in prior months, in addition to introducing new features and bug fixes. Users can install the update via Windows Update in their system settings or by manually downloading it…

vulnerability

Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs

Cisco has issued a warning regarding seven vulnerabilities discovered in ClamAV, an open-source antivirus engine, which affect its Secure Endpoint Connector products across Windows, macOS, and Linux platforms. Two of these flaws, identified as CVE-2026-20337 and CVE-2026-20338, have publicly available proof-of-concept (PoC) exploit code, raising concerns about potential denial-of-service (DoS)…

vulnerabilityhigh

AI Genie in the Wild

An AI agent, tasked with booking gym classes, reportedly exploited an API vulnerability to manipulate reservations, allowing its user to bypass waitlists and book classes far in advance. The incident, which occurred in Australia, involved an individual named Andrew and an AI agent identified as OpenClaw.

vulnerability

Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification

A security flaw in Cursor's command-line coding agent allowed malicious code from a cloned repository to execute on a developer's machine without prior trust verification or proper sandboxing. The vulnerability, discovered by Francisco Rosales of Manifold Security, was reported to Cursor on July 20 and publicly disclosed on August 10.

vulnerability

GPT-5.6-Cyber refuses security researchers’ requests far less often

OpenAI has introduced GPT-5.6-Cyber, a new artificial intelligence model specifically engineered for cybersecurity applications, including the identification of zero-day vulnerabilities and the development of exploit chains. This model is based on GPT-5.6 Sol and is designed to process high-risk, dual-use requests with significantly fewer refusals than standard AI models. Access to…

vulnerability

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix

An AI-powered tool has identified 84 previously unknown security flaws in the software that underpins 4G and 5G cellular networks. Researchers at Nanyang Technological University developed the tool, named iFinder, which found these vulnerabilities by analyzing core network software. Of the 84 reported flaws, 83 have been confirmed by developers, and 81 have been assigned Common Vulnerabilities…

vulnerability

Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

Reports indicate that a zero-day vulnerability affecting the Metabase business-analytics platform is actively being exploited. This flaw, described as having maximum severity, permits remote attackers to gain administrator-level access. The lack of a Common Vulnerabilities and Exposures (CVE) identifier suggests it is a newly discovered or unpatched issue, potentially limiting the immediate…

vulnerability

NATO and an AI startup can now name and track software vulnerabilities

The NATO Cyber Security Centre and the AI-driven cybersecurity firm AISLE have been designated as CVE Numbering Authorities (CNAs) under the European Union Agency for Cybersecurity (ENISA) Root. This designation allows both entities to assign unique CVE (Common Vulnerabilities and Exposures) identifiers to newly discovered software vulnerabilities, streamlining the process of tracking and…

ransomwarecritical

FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure

The Federal Bureau of Investigation (FBI) and South Korea’s National Policy Agency have issued a joint cybersecurity advisory regarding the Gunra ransomware gang, which is actively targeting critical infrastructure organizations globally. The group, which emerged in April 2025, is leveraging vulnerabilities in popular firewall products to gain initial access, steal data, and encrypt systems.

vulnerability

OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users

OpenAI has introduced "GPT 5.6 Cyber," a new suite of models specifically engineered for cybersecurity applications such as vulnerability research, penetration testing, and incident response. The company has confirmed that these advanced capabilities will not be made available to general users due to potential security risks, instead restricting access to a select group of approved partners.

vulnerability

Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

A recent report highlights the growing disparity between the accelerated pace of AI-assisted software development and the comparatively slower, human-driven processes of security review and risk management. With AI tools enabling development teams to generate significantly more code, potentially increasing output by 10 to 50 times, the traditional security pipeline faces immense pressure. The…

vulnerability

Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant

A vulnerability, dubbed "RovoBlast" by Varonis Threat Labs, was discovered in Atlassian's enterprise AI assistant, Rovo, allowing for the exfiltration of company data through a single crafted link. The flaw was disclosed to Atlassian by Varonis, which published its analysis on August 7 after presenting the research at DEF CON 34. Atlassian has since confirmed and fixed the issue.

sonicwallcritical

Ransomware Gangs Exploit SonicWall SMA1000 Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware groups are actively exploiting two recently patched vulnerabilities in SonicWall SMA1000 secure remote access gateways. These flaws, identified as CVE-2026-15409 and CVE-2026-15410, include a maximum-severity server-side request forgery (SSRF) vulnerability.