breachcritical
Cisco Patches a Dozen Critical Vulnerabilities
Cisco has released patches addressing a dozen critical vulnerabilities across its product line. These security defects reportedly encompass a range of potential impacts, including unauthorized access, information leaks, privilege escalation, denial-of-service (DoS) attacks, and remote code execution (RCE). The widespread nature of these reported flaws suggests a significant security update…
vulnerabilitycritical
Cisco warns of critical flaws allowing Nexus switch takeover
Cisco has issued a warning regarding five critical vulnerabilities identified in its NX-OS data center network operating system, which could enable attackers to execute arbitrary code with root privileges on Nexus switches. In scenarios where remote code execution is not achievable, exploitation of these flaws could lead to process crashes and device reloads, resulting in denial-of-service…
CVE-2017-20284high
Caucho Resin Path Traversal Flaw Exploited Same Day as Disclosure
CVE-2017-20284, a path traversal vulnerability in Caucho Technology's Resin, was reported as exploited on the same day it was published. VulnCheck lists it as exploited, but CISA and EUVD do not.
CVE-2026-102489critical
Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure
The Dutch Institute for Vulnerability Disclosure (DIVD), a cybersecurity non-profit, recently disclosed that it was compromised in an attack that exploited two zero-day vulnerabilities in its Zammad helpdesk platform. The incident, detected on September 24, involved the use of what DIVD describes as an "agentic AI" to execute the attack.
vulnerability
Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation
Google's Threat Intelligence Group (GTIG) has reported a significant surge in vulnerability disclosures, with monthly totals more than doubling from January to August of this year. The number of disclosures climbed from 5,045 in January to over 10,000 in both July and August, peaking at 10,740 last month. This increase is attributed by GTIG researchers to the growing influence of artificial…
CVE-2026-76461high
Week in review: Cisco patches exploited email gateway 0-day, Revolut breach
Cisco has confirmed that attackers are actively exploiting a zero-day SQL injection vulnerability, tracked as CVE-2026-76461, in its Secure Email Gateway appliances. The company's Product Security Incident Response Team became aware of the exploitation in September 2025 and has since provided indicators of compromise for organizations to check for potential breaches.