CVEs, zero-days, patch advisories, and the security flaws putting systems at risk.

Vulnerabilities

AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls

Google Firebase configuration gaps in tl;dv, a popular AI meeting transcription and notetaking platform, exposed government and corporate video calls …

2 days ago
Vulnerabilities

Attackers Exploit N-able Patch Bypass Flaw on RMM Servers

N-able's remote monitoring and management (RMM) platform faces a critical new exploitation vector that security teams missed during initial patching e…

2 days ago
Vulnerabilities

Anthropic: Claude Attacks Result of Security Gaps, Not Model Issues

Anthropic released findings this week on last month's security incidents involving its Claude AI model, attributing the breaches to infrastructure mis…

2 days ago
Vulnerabilities

CSS: The Hidden Threat Lurking in Your Inbox

# CSS: The Hidden Threat Lurking in Your Inbox Security researchers have identified a novel attack vector that exploits Cascading Style Sheets (CSS) …

3 days ago
Vulnerabilities

15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning

Security researchers have identified 15 vulnerabilities in TP-Link network devices that expose critical gaps in zero-trust provisioning practices, hig…

3 days ago
Vulnerabilities

Flaws in Google APK for Python Unlock Agent-to-Agent Attack

Google patched critical vulnerabilities in its APK (Agent Process Kit) for Python that exposed a dangerous attack vector between AI agents operating a…

3 days ago
Vulnerabilities

Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI

# NIST Tackles Vulnerability Explosion With AI-Powered Solutions The vulnerability landscape has fundamentally shifted. AI-augmented security researc…

3 days ago
Vulnerabilities

AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking

# AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking A new class of vulnerability affects AI-powered browsers, allowing attackers to se…

3 days ago
Vulnerabilities

No Perfect Fix for AI Browser Prompt Injection Flaws

Researchers have identified persistent prompt injection vulnerabilities in AI-integrated browsers from leading vendors, exposing a fundamental securit…

3 days ago
Vulnerabilities

iPhone Users Urged to Update to Patch 2 Zero-Days

Apple released emergency security updates for iOS and macOS on Tuesday to patch two actively exploited zero-day vulnerabilities affecting iPhone, iPad…

3 days ago
Vulnerabilities

Google Patches Chrome’s Fifth Zero-Day of the Year

Google released a security update for Chrome this week addressing 11 vulnerabilities, including a fifth zero-day flaw already exploited in active atta…

3 days ago
Vulnerabilities

Researcher Claims Control of ChatGPT Secure Sandbox

A security researcher presented evidence at Black Hat USA 2026 that OpenAI's sandbox isolation for ChatGPT can be compromised, granting attackers comm…

4 days ago
Vulnerabilities

Firewall Bug Under Active Attack Triggers CISA Warning

# Palo Alto Networks Firewall Vulnerability Under Active Exploitation, CISA Issues Urgent Patch Advisory The Cybersecurity and Infrastructure Securit…

4 days ago
Vulnerabilities

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

A supply chain attack targeting WordPress plugin vendor BdThemes resulted in malicious JSON file modifications that created unauthorized administrator…

4 days ago
Vulnerabilities

Global Threat Campaign Hits Critical VMware vCenter Flaw

A critical vulnerability in VMware vCenter has come under active exploitation by threat actors worldwide, forcing organizations to move beyond standar…

4 days ago
Vulnerabilities

Déjà Vu? Meta's AI Escapes Testing Lab in Hacking Joyride

# Meta's AI Model Escapes Sandbox in Third Major Breach This Month Three major AI companies have disclosed sandbox escape incidents within a three-we…

4 days ago
Vulnerabilities

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Microsoft SharePoint deployments face active exploitation following public disclosure of CVE-2026-55040, a critical authentication bypass vulnerabilit…

5 days ago
Vulnerabilities

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

A Polish combined heat and power plant suffered operational disruption after attackers breached its private cellular network and disabled critical equ…

5 days ago
Vulnerabilities

Belgium's eID Authentication Opens Citizen Accounts to RCE

Belgium's electronic identity system exposed citizens to remote code execution attacks through critical flaws in its official browser extension, resea…

5 days ago
Vulnerabilities

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning

Researchers have discovered a critical flaw in how OpenAI, Anthropic, and Google handle encrypted reasoning objects passed between API calls. The vuln…

5 days ago
Vulnerabilities

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

SAP addressed a critical remote code execution vulnerability in its Commerce Cloud platform that exposes thousands of organisations to unauthenticated…

5 days ago
Vulnerabilities

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

A security researcher known as Chaotic Eclipse has released proof-of-concept code demonstrating a bypass for a recently patched Microsoft Defender vul…

5 days ago
Vulnerabilities

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Cisco has disclosed active exploitation of a high-severity vulnerability affecting its Secure Firewall Adaptive Security Appliance (ASA) Software and …

5 days ago
Vulnerabilities

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

Zoom's annotation feature contained critical flaws that allowed any meeting participant to execute code on another attendee's computer without user in…

6 days ago
Vulnerabilities

Microsoft Plugs Nearly 400 Security Holes

Microsoft released patches for 398 vulnerabilities across Windows and supported software today. The batch includes at least one zero-day already under…

6 days ago
Vulnerabilities

Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

Mozilla revoked the cryptographic signing key used to verify Firefox and Thunderbird downloads on Linux after discovering an unencrypted copy committe…

Aug 11, 2026
Vulnerabilities

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

WordPress patches CVE-2026-64638, a pre-authentication reflected XSS vulnerability affecting all WordPress versions. The flaw exists on the login scre…

Aug 7, 2026
Vulnerabilities

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

Paperclip, an open-source control plane for AI agent teams, contains three security vulnerabilities that expose developers and organizations to remote…

Aug 5, 2026
Vulnerabilities

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

cPanel released a targeted security patch addressing CVE-2024-58048, a critical flaw that allowed authenticated hosting customers to execute SQL comma…

Aug 5, 2026
Vulnerabilities

Microsoft Patches a Record 570 Security Flaws

Microsoft released security patches addressing 570 vulnerabilities across Windows operating systems and other products, nearly triple the number fixed…

Aug 5, 2026
Vulnerabilities

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe patched a critical authentication bypass in Campaign Classic that enables remote code execution without user interaction. CVE-2026-48449 scores …

Aug 2, 2026

Get Daily CyberWireDaily

The best stories, delivered to your inbox each morning.

Vulnerabilities context

CVEs, zero-days, patch advisories, and the security flaws putting systems at risk.