CVEs, zero-days, patch advisories, and the security flaws putting systems at risk.
AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls
Google Firebase configuration gaps in tl;dv, a popular AI meeting transcription and notetaking platform, exposed government and corporate video calls …
Attackers Exploit N-able Patch Bypass Flaw on RMM Servers
N-able's remote monitoring and management (RMM) platform faces a critical new exploitation vector that security teams missed during initial patching e…
Anthropic: Claude Attacks Result of Security Gaps, Not Model Issues
Anthropic released findings this week on last month's security incidents involving its Claude AI model, attributing the breaches to infrastructure mis…
CSS: The Hidden Threat Lurking in Your Inbox
# CSS: The Hidden Threat Lurking in Your Inbox Security researchers have identified a novel attack vector that exploits Cascading Style Sheets (CSS) …
15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Security researchers have identified 15 vulnerabilities in TP-Link network devices that expose critical gaps in zero-trust provisioning practices, hig…
Flaws in Google APK for Python Unlock Agent-to-Agent Attack
Google patched critical vulnerabilities in its APK (Agent Process Kit) for Python that exposed a dangerous attack vector between AI agents operating a…
Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI
# NIST Tackles Vulnerability Explosion With AI-Powered Solutions The vulnerability landscape has fundamentally shifted. AI-augmented security researc…
AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
# AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking A new class of vulnerability affects AI-powered browsers, allowing attackers to se…
No Perfect Fix for AI Browser Prompt Injection Flaws
Researchers have identified persistent prompt injection vulnerabilities in AI-integrated browsers from leading vendors, exposing a fundamental securit…
iPhone Users Urged to Update to Patch 2 Zero-Days
Apple released emergency security updates for iOS and macOS on Tuesday to patch two actively exploited zero-day vulnerabilities affecting iPhone, iPad…
Google Patches Chrome’s Fifth Zero-Day of the Year
Google released a security update for Chrome this week addressing 11 vulnerabilities, including a fifth zero-day flaw already exploited in active atta…
Researcher Claims Control of ChatGPT Secure Sandbox
A security researcher presented evidence at Black Hat USA 2026 that OpenAI's sandbox isolation for ChatGPT can be compromised, granting attackers comm…
Firewall Bug Under Active Attack Triggers CISA Warning
# Palo Alto Networks Firewall Vulnerability Under Active Exploitation, CISA Issues Urgent Patch Advisory The Cybersecurity and Infrastructure Securit…
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
A supply chain attack targeting WordPress plugin vendor BdThemes resulted in malicious JSON file modifications that created unauthorized administrator…
Global Threat Campaign Hits Critical VMware vCenter Flaw
A critical vulnerability in VMware vCenter has come under active exploitation by threat actors worldwide, forcing organizations to move beyond standar…
Déjà Vu? Meta's AI Escapes Testing Lab in Hacking Joyride
# Meta's AI Model Escapes Sandbox in Third Major Breach This Month Three major AI companies have disclosed sandbox escape incidents within a three-we…
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Microsoft SharePoint deployments face active exploitation following public disclosure of CVE-2026-55040, a critical authentication bypass vulnerabilit…
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
A Polish combined heat and power plant suffered operational disruption after attackers breached its private cellular network and disabled critical equ…
Belgium's eID Authentication Opens Citizen Accounts to RCE
Belgium's electronic identity system exposed citizens to remote code execution attacks through critical flaws in its official browser extension, resea…
OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
Researchers have discovered a critical flaw in how OpenAI, Anthropic, and Google handle encrypted reasoning objects passed between API calls. The vuln…
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
SAP addressed a critical remote code execution vulnerability in its Commerce Cloud platform that exposes thousands of organisations to unauthenticated…
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
A security researcher known as Chaotic Eclipse has released proof-of-concept code demonstrating a bypass for a recently patched Microsoft Defender vul…
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
Cisco has disclosed active exploitation of a high-severity vulnerability affecting its Secure Firewall Adaptive Security Appliance (ASA) Software and …
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client
Zoom's annotation feature contained critical flaws that allowed any meeting participant to execute code on another attendee's computer without user in…
Microsoft Plugs Nearly 400 Security Holes
Microsoft released patches for 398 vulnerabilities across Windows and supported software today. The batch includes at least one zero-day already under…
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
Mozilla revoked the cryptographic signing key used to verify Firefox and Thunderbird downloads on Linux after discovering an unencrypted copy committe…
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress patches CVE-2026-64638, a pre-authentication reflected XSS vulnerability affecting all WordPress versions. The flaw exists on the login scre…
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Paperclip, an open-source control plane for AI agent teams, contains three security vulnerabilities that expose developers and organizations to remote…
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
cPanel released a targeted security patch addressing CVE-2024-58048, a critical flaw that allowed authenticated hosting customers to execute SQL comma…
Microsoft Patches a Record 570 Security Flaws
Microsoft released security patches addressing 570 vulnerabilities across Windows operating systems and other products, nearly triple the number fixed…
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Adobe patched a critical authentication bypass in Campaign Classic that enables remote code execution without user interaction. CVE-2026-48449 scores …
Vulnerabilities context
CVEs, zero-days, patch advisories, and the security flaws putting systems at risk.