Vulnerabilities
103 stories

Google releases Chrome security update for actively exploited V8 vulnerability
Google has patched a high-severity V8 type confusion vulnerability in Chrome that is currently being exploited in the wild.

F5 Patches Critical BIG-IP APM Zero-Day Vulnerability
F5 has released hotfixes for a critical remote code execution vulnerability in its BIG-IP Access Policy Manager.

Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution
A critical vulnerability in the Next.js ImageResponse feature allows attackers to achieve remote code execution via specially crafted SVG inputs.

Apache Syncope vulnerability enables arbitrary SQL command execution
Rapid7 released a public proof-of-concept script for a critical authentication bypass vulnerability in Check Point SmartConsole that allows unauthenticated attackers to gain administrative privileges.

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution
WordPress released a security update for a critical flaw that allows unauthorized code execution on certain server configurations.

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
A critical vulnerability in the Bifrost AI gateway allows unauthenticated remote command execution.

Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
A researcher has released a proof-of-concept tool named BigDiskBuster that prevents Microsoft Defender from updating by exhausting system disk space.

Attackers exploit critical Fastjson vulnerability despite lack of security patches
Security firms report active exploitation of a critical Fastjson RCE vulnerability with no patched version currently available.

SharePoint Vulnerability Allows Authenticated Remote Code Execution
Researcher Dinh Ho Anh Khoa identified that a SharePoint Server vulnerability previously misclassified by Microsoft as a spoofing flaw allows for authenticated remote code execution.

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access
A vulnerability in the Linux kernel's ARM64 KVM virtualization code allows guest virtual machines to access and manipulate host memory if nested virtualization is enabled.

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
Security agencies and firms report active exploitation of vulnerabilities in Zyxel switches and Veeam software.

Hidden Setting in Meta Muse Allows Attackers to Create Backdoors
Security researcher Patrick Wardle discovered a vulnerability in the macOS version of Meta's Muse AI assistant that allows attackers to hijack user dictation and bypass system access restrictions.

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
WordPress released a patch for the Click2Shell vulnerability that could allow forced theme installation and potential remote code execution when chained with other flaws.

Cisco Secure Email Gateway Flaw Exploited in the Wild
A critical vulnerability in Cisco Secure Email Gateway is being actively exploited, prompting emergency patching requirements.

Indian Army to establish six cyber labs for military system security
The Indian Army is establishing six AASHVAST cyber laboratories to detect vulnerabilities in drones and military electronic systems.

Researchers exploit ChatGPT using Anthropic tool to expose security vulnerabilities
Cybersecurity researchers discovered a vulnerability in ChatGPT by using an Anthropic tool to exploit a security flaw.

Researchers Use Claude Opus 5 to Chain Flaws Into OpenAI Access
Researchers exploited chained flaws in Discourse and OpenAI's login system to gain unauthorized access to internal staff accounts.

SolarWinds Patches Access Rights Manager Flaw Enabling Unauthenticated RCE
SolarWinds patched a high-severity hard-coded credential vulnerability in its Access Rights Manager software that could allow remote code execution.
Researchers Use AI Tools To Exploit Vulnerabilities In OpenAI Systems
Three Indian-origin researchers successfully identified and exploited security vulnerabilities in OpenAI's systems using AI tools including Claude.

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited
A critical pre-authentication remote code execution vulnerability in the Orkes Conductor workflow platform is being actively exploited in the wild.

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
Researcher Asim Manizada has released proof-of-concept exploits for four memory-safety vulnerabilities in the Linux kernel that allow local privilege escalation to root.

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
A vulnerability in four AI coding agents allows malicious plugin code to be swapped despite version pinning.

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw
Microsoft has patched several critical vulnerabilities across its products, including a maximum-severity flaw in Azure AI Foundry.

Critical vulnerability discovered in Cisco Secure Firewall Management Center software
CISA added a newly disclosed zero-day vulnerability in Cisco Secure Firewall Management Center to its Known Exploited Vulnerabilities catalog following reports of active exploitation.

Docker Sandboxes Flaw Allows Guest Code to Access macOS Host Files
Docker has fixed a critical sandbox escape vulnerability in Docker Sandboxes for macOS that allowed malicious guest code to access host files.

BIND 9 Update Fixes 14 Flaws Including Unauthenticated DoH Crash
Internet Systems Consortium released BIND 9 updates to address fourteen distinct security vulnerabilities.

Critical Unbound DNSSEC Validator Flaw Could Allow RCE
NLnet Labs has released Unbound version 1.26.1 to address nine security vulnerabilities, including two that could potentially lead to remote code execution.

Attackers exploit critical JFrog Artifactory vulnerability to create administrator tokens
Threat actors are exploiting a newly patched critical security flaw in JFrog Artifactory to mint administrator tokens shortly after the vulnerability was disclosed.

Hackers exploit PaperCut software vulnerabilities to steal credentials from educational institutions
Threat actors are exploiting PaperCut software vulnerabilities to conduct credential theft at educational institutions in the U.S. and Europe.

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab has patched multiple critical vulnerabilities, including a path traversal flaw being actively exploited in the wild.