Skip to main content

Vulnerability Management

Person working on Windows 11 laptop with hands poised over mouse.

Microsoft Update Reverts Windows 11 Mouse Settings

If you've customized your Windows 11 mouse settings, beware: the latest update, KB5120998, may be reverting them to default, causing frustrating losses in personalization. Microsoft is investigating the issue and asking affected users to report their experiences through the Feedback Hub.

Analyst 207
Windows desktop screen with a blurred notification alert and warning icon.

Microsoft Disregards Defender Alerts as False Positives

If you've recently updated Microsoft Defender Antivirus, you might be seeing annoying false alarms claiming it's turned off - but don't worry, it's still working hard to protect you. These pesky alerts are affecting all supported Windows versions, including Windows 11 26H1 and Windows Server 2025.

Analyst 207
Networked printer sits on cluttered office desk surrounded by papers and computer equipment.

PaperCut Flaws Chained for Remote Code Execution

Researchers have uncovered a vulnerability in PaperCut that allows an unauthenticated attacker to gain remote control, enabling them to execute arbitrary Java code within the application's process. This flaw can be exploited through a clever two-step chaining technique, putting unpatched PaperCut NG and MF instances at risk.

Analyst 207
Cybersecurity team works in a busy operations center with multiple screens and computer equipment.

Vulnerability Management Scrambles to Keep Pace with AI-Driven Discovery

The National Vulnerability Database (NVD) is undergoing a major overhaul as it struggles to keep up with a staggering 30,000 reclassified vulnerabilities, now marked as "Not Scheduled" for further analysis, amid a surge in AI-driven discoveries. This change aims to help manage the overwhelming backlog through selective processing and automation.

Analyst 207
Cluttered software development workspace with laptop, monitor, and papers, overlooking a cityscape.

CISA Warns of Persisting Vulnerabilities

Threat actors are still finding success by exploiting simple, preventable software weaknesses that have been known for years - and it's a problem that CISA says could have been designed out of products from the start. The agency's review reveals that decades-old bugs, like improper input validation, continue to plague the industry.

Analyst 207
Modern tech company's server room with rows of equipment and a single laptop workstation.

ServiceNow Patches Maximum-Severity Vulnerabilities

ServiceNow has released urgent security updates to fix three critical vulnerabilities in its AI Platform, and experts warn customers to act fast to secure their self-hosted instances. Apply the patches now to protect against potential malicious attacks.

Analyst 207
Rows of computer servers and storage units in a shared web hosting server room.

cPanel Flaw Enables Root Code Execution via Domain Functionality

A critical cPanel security flaw, tracked as CVE-2026-65643, allows attackers to execute code as the root user, giving them full control of the server, by exploiting domain parking and addon domain functionality. This vulnerability impacts all supported versions of cPanel & WHM and can be triggered by an authenticated account holder.

Analyst 207
Windows 11 laptop on a desk in a modern office with a blurred background and a generic desktop on the screen.

Microsoft Rolls Out Windows 11 KB5120998 Update With 35 Fixes, Taskbar Overhaul

Microsoft's latest update, KB5120998, is here with 35 fixes and a revamped taskbar, plus a new administrator protection feature that helps shield against elevation-of-privilege attacks by separating profiles. This feature, currently off by default, can be easily enabled through Microsoft Intune or Group Policy.

Analyst 207
Rack-mounted servers sit under ordinary lighting in a data center.

Next.js Patches Flaws Enabling Unauthenticated Remote Code Execution

If your Next.js application is hosted on Windows, upgrade immediately to patch a critical vulnerability that allows unauthenticated remote code execution. This flaw, tracked as CVE-2026-75604, affects apps using both Pages Router and App Router without Cache Components.

Analyst 207
Laptop on a clean desk with notes and a pen, suggesting innovation and tech development.

Omarchy Linux Distro Draws $10 Million Backing

Meet Omarchy, a bold new take on Arch Linux, now backed by $10 million in funding and led by tech visionary David Heinemeier Hansson - but beware, its early releases have raised some red flags about security. The project just rolled out Omarchy 4.0.1, a swift security fix for its mid-August "Quattro" release.

Analyst 207
Cluttered developer workstation with laptop, monitor, and coding screens.

Amazon Kiro Flaw Exposes Sensitive Data Through Prompt Injection

A security flaw in Kiro, known as a prompt injection vulnerability, allowed hackers to tap into sensitive data by manipulating the Kiro agent with malicious repository content. This issue, affecting Kiro IDE 0.7.45 on Windows, could send local information to an external endpoint, putting users at risk.

Analyst 207
Network operations center with analysts monitoring internet traffic and network visualizations on multiple screens.

Federal Agencies Face Shrinking Window to Defend Against Cyber Threats

The threat landscape has drastically changed: cyber attackers can now exploit vulnerabilities in as little as two days, leaving federal agencies with a shrinking window to defend against threats. To stay ahead, they must shift their focus from reacting to attacks to anticipating and preparing for what's next.

Analyst 207
Cluttered home office with Windows 11 laptop, peripherals, and monitor on desk near window.

Microsoft Disables Faulty Driver Behind Windows 11 Gaming Crashes

Microsoft has pinpointed a problematic driver, inpoutx64.sys, as the culprit behind Windows 11 gaming crashes, and has taken swift action to disable it and prevent further system crashes and game failures. This fix aims to put an end to frustrating errors and glitches, ensuring a smoother gaming experience for Windows 11 users.

Analyst 207
Technicians walk through a server room with rows of equipment racks and computer servers.

CISA Mandates Patching of Exploited Citrix NetScaler Flaw

Don't wait until it's too late: CISA has issued a directive requiring all Federal agencies to patch the exploited Citrix NetScaler flaw, CVE-2026-8452, by August 29 to avoid potential security breaches. This critical vulnerability is already being exploited in the wild, making swift action essential.

Analyst 207
Close-up of NVIDIA graphics card in partially disassembled computer on cluttered laboratory desk.

NVIDIA GPUs Vulnerable to GPUThor Rowhammer Attack Bypassing ECC

NVIDIA GPUs are vulnerable to a new type of attack, dubbed GPUThor, which can cause massive corruption - up to 377,552 bit flips per gigabyte - on certain models, including the RTX A5000, when their GDDR6 memory is exploited. This Rowhammer-style attack can bypass ECC protection, putting powerful NVIDIA workstation cards at risk.

Analyst 207
Network equipment rack with modern devices and cables, one device showing an open panel.

Ubiquiti Patches Three Maximum-Severity Flaws in UniFi Line

Ubiquiti has patched three critical vulnerabilities in its UniFi line, with a severity score of 10 out of 10, that could allow hackers to gain control of affected devices. These flaws, along with 19 others, were disclosed in a security bulletin, highlighting the need for immediate updates.

Analyst 207
Cybersecurity professional examining screens and devices in a brightly-lit room.

AI Models Accelerate Vulnerability Discovery

New AI models are revolutionizing vulnerability discovery, condensing a process that once took months into just hours and leaving defenders scrambling to keep up. This acceleration is outpacing traditional patch cycles, with attackers now able to develop working exploit code in as little as a week.

Analyst 207
Cybersecurity team workspace with computers and equipment, featuring a large blank screen.

AI-Driven Vulnerability Discovery Surges, Threatens Software Security

The AI-driven vulnerability discovery surge is alarming, with OpenClaw, a popular AI project, ranking 12th in Q2 for most vulnerabilities discovered and published, with over 200 CVEs registered. This sharp increase in registered vulnerabilities is largely driven by AI adoption in both application development and vulnerability discovery.

Analyst 207
Rows of server racks and networking equipment in a shared data center with technicians in the background.

Unpatched Kaltura Flaws Expose Servers to Remote Code Execution

A pair of unpatched vulnerabilities in Kaltura's mwEmbed HTML5 player library could put servers at risk of remote code execution, allowing attackers to read sensitive files and run malicious code - and affecting not just individual customers, but also every tenant on shared hosting infrastructure. This critical security gap, tracked as CVE-2026-19913 and CVE-2026-19912, remains unpatched, leaving countless systems exposed.

Analyst 207
Network operations room with computer workstations and equipment.

Ubiquiti Disrupts Three Max-Severity Flaws in UniFi Systems

Ubiquiti has just dropped a critical security update to fix three massive vulnerabilities in its UniFi systems that hackers can exploit remotely without needing any special access. If you're using UniFi, now's the time to patch up and keep your network safe!

Analyst 207
Person sitting at desk with laptop open, reaching for keyboard amidst papers and notes.

Marimo Notebook Flaw Exposes Users to Pre-Execution Code Injection

A high-severity flaw in Marimo Notebook software, tracked as CVE-2026-75149, could allow attackers to inject malicious code on a user's machine simply by opening a specially crafted notebook in edit mode. This vulnerability, rated 8.7 out of 10 in severity, requires no authentication - just a click.

Analyst 207
Security professional examines technology equipment on a tablet or laptop.

Vulnerability Management Faces AI-Driven Overhaul

The AI revolution is here, and it's forcing security teams to ask themselves: are their vulnerability programs ready to keep up with the lightning-fast pace of Frontier AI models that can identify zero-day flaws and adapt in real time? For many organisations, the answer is a worrying "no".

Analyst 207
Windows virtual machine terminal in a data center with servers and cables, screen slightly out of focus showing generic…

CISA Mandates Swift Patching for Oracle Flaw

Don't wait - patch now! A critical Oracle flaw, scored 10.0, requires immediate attention to prevent low-complexity attacks that could give hackers complete access to your critical data.

Analyst 207
Power grid control room with industrial systems and monitoring equipment.

Senate Bill Targets Energy Sector's Quantum Cybersecurity Gaps

The clock is ticking: as quantum technology advances, our critical energy systems are vulnerable to devastating cyberattacks - that's why Sen. Chris Coons is pushing for the Quantum-GUARD Act to safeguard our nation's infrastructure. This crucial bill would empower the Federal Regulatory Energy Commission to proactively defend against quantum-enabled threats.

Analyst 207