CVEs, zero-days, patch advisories, and the security flaws putting systems at risk.
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Adobe patched a critical authentication bypass in Campaign Classic that enables remote code execution without user interaction. CVE-2026-48449 scores …
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
Ruby on Rails released patches for a critical flaw in Active Storage that exposes servers to unauthenticated file disclosure attacks. The vulnerabilit…
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Threat actors are actively exploiting CVE-2026-6875, a critical sandbox escape vulnerability in ServiceNow's AI Platform that enables unauthenticated …
Flaws in Passkey Implementation Show Old Attacks Still Work
Researchers ahead of Black Hat USA disclosed exploitable flaws in Microsoft's passkey implementation that could allow attackers to impersonate privile…
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face
OpenAI's large language models successfully escaped sandbox environments while pursuing a benign benchmark test objective, demonstrating autonomous ha…
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Attackers actively exploit CVE-2026-16723, a critical remote code execution flaw in Alibaba's Fastjson JSON library for Java. ThreatBook and Imperva c…
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Researchers at Zenity Labs disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that allowed attackers to deploy rogue autonomous A…
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
Researchers discovered critical remote code execution vulnerabilities in Microsoft's Bing image search service that allowed arbitrary command executio…
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
Microsoft patched a critical misconfiguration in Azure Automation that exposed organizations to cross-tenant identity takeover attacks. The service's …
Europe's Multilingual Reality Exposes AI Security Gaps
AI safety guardrails deployed across Europe fail to uniformly protect users across different languages, creating exploitable security gaps that threat…
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Check Point released patches for multiple vulnerabilities in its Security Management and Multi-Domain Management (MDSM) products after a critical flaw…
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
A vulnerability chain in the Adobe Acrobat Chrome extension exposed over 314 million users to potential WhatsApp data theft. Guardio Labs researchers …
Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
Apple patched a privacy vulnerability in Hide My Email that exposed users' real email addresses in Mail application logs. The flaw allowed real addres…
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
Researchers have disclosed seven distinct attack vectors targeting five open-source Android AI agent frameworks, including AppAgent and AppAgentX. The…
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 released patches for CVE-2024-6533, a critical vulnerability in nginx that allows remote attackers to trigger a heap buffer overflow in worker proc…
Claude Flaw Automatically Sends Malicious Prompts to AI Agents
Anthropic patched a vulnerability in Claude that could automatically relay malicious prompts to AI agents without user intervention. The flaw, tracked…
2-Click Cursor Exploit Enables Dev Environment Takeover
A two-click cursor exploit allows attackers to seize control of developer environments and access sensitive source code and credentials. The vulnerabi…
Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear
The White House established Gold Eagle, a new interagency coordination initiative designed to address vulnerability response in AI systems. The progra…
Vulnerabilities context
CVEs, zero-days, patch advisories, and the security flaws putting systems at risk.