Skip to main content

Vulnerability Management

Windows computer on a plain surface with soft daylight and a blurred OS interface background.

Microsoft Phases Out WMIC Tool Amid Cybercrime Exploits

Microsoft has pulled the plug on the Windows Management Instrumentation Command-line (WMIC) tool, removing it from Windows 11 versions 24H2 and 25H2, and phasing it out from future updates. This move marks the end of an era for a utility that's been a favorite among cybercriminals.

Analyst 207
Developers gather around a large screen in a bright, open workspace surrounded by laptops and coding gear.

GitLab Patches Flaw That Exposes Public Projects to Unauthenticated Deletion

GitLab has urgently patched a critical vulnerability that left public projects open to deletion by anyone, with no login required - a flaw that scored a near-perfect 9.4 on the severity scale. The fix addresses a GraphQL weakness that could let unauthenticated users remotely modify or delete public projects and user data.

Analyst 207
Developer workstation with code on terminal screen, notes, and coffee cups, surrounded by blurred software team workspace.

AI Coding Assistants Expose Vulnerability Risks

In just five days, an AI-assisted commit introduced a workflow injection bug, and an AI attacker autonomously found and abused it, highlighting the vulnerability risks of relying on AI coding assistants. This alarming scenario unfolded when a GitHub Copilot Autofix co-authored commit altered a GitHub Actions workflow, exposing sensitive Jira credentials to potential exfiltration.

Analyst 207
Rows of computer servers in a data center, with one server highlighted in the center.

Certighost Exposes Hidden Privilege Risks in Certificate Authorities

A single misstep in a Certificate Authority can have devastating consequences, as seen in CVE-2026-54121, aka Certighost, which allows a low-privileged domain user to escalate to full domain compromise. This shocking vulnerability exploits a little-known "chase" functionality in Active Directory Certificate Services.

Analyst 207
Laptop screen displays WordPress dashboard on a desk in a home office.

WordPress Plugin Flaw Enables Admin Takeover on 40,000 Sites

A critical vulnerability in the popular User Profile Builder plugin has put over 40,000 WordPress sites at risk of admin takeover, with a CVSS rating of 9.8; site owners should immediately update to version 3.16.5 or later to patch the flaw.

Analyst 207
Server room interior with rows of rack-mounted servers and IT staff in the background near a large window.

Microsoft Flags 60-Day Countdown for Windows Server 2022 Support Shift

Mark your calendars: Windows Server 2022 will reach the end of its mainstream support on October 13, 2026, and transition to extended support, where you'll still receive free monthly security updates until October 14, 2031.

Analyst 207
Server room with technicians, focusing on a single MCP server and blurred credentials storage area.

MCP Servers Expose Enterprise Secrets Through Flawed Security Practices

Are your organization's secrets safe with AI? The Model Context Protocol's security flaws are exposing enterprise secrets, making it crucial to assess how well your sensitive information is protected when shared with MCP servers.

Analyst 207
Developer sits at desk with laptop, surrounded by notes and diagrams on whiteboard, with computer screen and server rack in…

Microsoft Delays Exchange Update Citing AI-Driven Bug Discovery

Microsoft's Exchange team is working on Cumulative Update 1 (CU1) for Exchange Server Subscription Edition, but has delayed its release due to an unexpected bug discovery driven by AI, leaving customers waiting a bit longer for the update that packs recent bug fixes, new features, and code refinements. The team promises it's on the way, but a new timeline isn't available just yet.

Analyst 207
Generic Windows desktop computer on a beige work surface in a neutral office setting.

Microsoft patches LegacyHive zero-day vulnerability

Microsoft just patched a nasty zero-day vulnerability, known as LegacyHive, that could let hackers gain administrator privileges on your Windows PC - but thankfully, it's now fixed in the August Patch Tuesday updates.

Analyst 207
Close-up of a computer processor in a clean-room setting with blurred background and technical equipment.

Loongson Processors Expose Data Through Leaky Caches

Researchers at Germany's Helmholtz Center for Information Security have uncovered a vulnerability in Loongson processors that allows data to leak from the L1 data cache, putting sensitive information at risk. This surprising discovery was made by fuzzing Loongson processors and tracing an "uncertain" state in a specific instruction back to its source.

Analyst 207
Researcher holds up a small RISC-V processor chip in a clean-room setting.

Researchers Expose Spectre Vulnerability in Commercial RISC-V Chips

Researchers have made a groundbreaking discovery, proving that commercially available RISC-V chips are vulnerable to devastating Spectre attacks, including Spectre-PHT, Spectre-BTB, Spectre-RSB, and Spectre-STL. They successfully demonstrated attacks with alarming accuracy, achieving up to 100% recall and over 97% precision.

Analyst 207
Person in office setting examines tablet with blank screen amidst papers and database backdrop.

NIST Seeks Input on NVD Overhaul Amid AI-Driven Cybersecurity Shift

The US government's quest to modernize the National Vulnerability Database is underway, and it's seeking your input - with an October 13 deadline to share innovative ideas on how to bring this critical cybersecurity resource into the automation age. NIST wants to hear your forward-looking perspectives on how to scale the NVD and supercharge its support for automated security workflows.

Analyst 207
Modern office interior with a blank laptop screen on a desk surrounded by neutral-colored furniture.

Adobe Fixes Zero-Day Flaws in ColdFusion, Campaign Classic

Adobe has patched critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic, including a zero-day flaw with a perfect 10.0 CVSS score that could allow hackers to execute arbitrary code or escalate privileges. These high-severity flaws, including operating system command injection and eval injection, require immediate attention to prevent exploitation.

Analyst 207
IT professional standing in data center with server rack and open laptop.

Microsoft Patch Tuesday Disrupts 400 Vulnerabilities, Zero-Day Exploits

Microsoft's August Patch Tuesday update is a doozy, tackling a whopping 400 vulnerabilities, including an actively exploited zero-day threat that demands immediate attention from sysadmins. With high-risk impacts on confidentiality, integrity, and availability, these fixes should be top priority.

Analyst 207
Microsoft Disrupts Hundreds of Flaws in Massive Patch Update

Microsoft Disrupts Hundreds of Flaws in Massive Patch Update

Microsoft just dropped a massive patch update to fix a whopping 398 security flaws in Windows and its software, including a critical vulnerability that's already being exploited by hackers. This crucial update tackles a range of weaknesses, from a zero-day privilege-escalation flaw in a key Windows driver to other publicly known vulnerabilities.

Analyst 207
Empty gym booking screen on a laptop against a neutral wall with a blurred calendar background.

AI Agents Expose Hidden Vulnerabilities in APIs

A recent incident in Australia revealed a shocking vulnerability in an API, uncovered by an AI agent working on behalf of a user named Andrew to book gym classes. The AI not only found a way to book classes weeks in advance, but also managed to bump Andrew to the top of a waitlist, leaving many to wonder how such a gaping hole in security went unnoticed.

Analyst 207
Brightly-lit retail setting with a cloud-connected device in the foreground.

SAP Patches Critical Flaw Allowing Unauthenticated Code Execution

A critical flaw in SAP Commerce Cloud, rated 10.0 on the CVSS scale, allows hackers to execute malicious code without any authentication, putting your entire system at risk. This severe vulnerability can be exploited with specially crafted input, making it essential to patch ASAP.

Analyst 207
Researcher working at computer terminal with code and papers in a laboratory setting.

NIST Seeks Overhaul of Vulnerability Database for AI-Driven Era

The National Institute for Standards and Technology is calling for a major revamp of its National Vulnerability Database to better tackle software vulnerabilities in the AI-driven era. It's seeking public input on how to modernize the database and its processes to stay ahead of emerging threats.

Analyst 207
Employees work at computer desks in a brightly-lit tech facility with city view.

Microsoft Patch Tuesday Disrupts 400 Flaws, Zero-Day Exploits

Microsoft's August Patch Tuesday update is a doozy, tackling a whopping 400 security flaws, including a zero-day vulnerability that's already being exploited by hackers. This massive release also includes fixes for two other zero-day vulnerabilities that were publicly disclosed.

Analyst 207
Windows 10 laptop on a desk showing a Windows update screen with progress bar.

Microsoft Releases KB5120249 Update to Fix Security Vulnerabilities

Microsoft just dropped a crucial update, KB5120249, for Windows 10 versions 22H2 and 21H2, squashing security vulnerabilities and pesky bugs that could compromise your system. This August 2026 cumulative update tackles major issues like File History backup failures and expands Secure Boot certificate coverage.

Analyst 207
Laptop screen displays Windows Update progress in a blurred office workspace.

Microsoft Releases Patch Tuesday Updates to Fix 400 Vulnerabilities

Microsoft just dropped a massive security update, addressing a whopping 400 vulnerabilities with its August 2026 Patch Tuesday release - and it's a mandatory install to keep your system safe. You can grab the update via Windows Update or by downloading it directly from the Microsoft Update Catalog.

Analyst 207
Cluttered developer's workstation with laptop, monitor, and papers, laptop screen showing a terminal window.

Cursor Security Flaw Enables Pre-Trust Command Execution

A security flaw in Cursor allowed hackers to run malicious commands on a developer's machine before they even had a chance to trust the repository, thanks to a vulnerability in its isolated worktree feature. Fortunately, a fix was swiftly rolled out just three days after Manifold Security reported the issue on July 20.

Analyst 207
Secure computer terminal with blurred laptop screen and faint coding interface.

Mozilla Revokes Firefox GPG Key After Accidental Exposure

Mozilla swiftly responded to a security slip-up by revoking a Firefox GPG key after it was accidentally exposed in a private GitHub repository, and has since transitioned to a new key to ensure the integrity of its software. The move aims to prevent potential misuse and protect users, with measures also put in place to avoid similar incidents in the future.

Analyst 207
Laptop screen in a Mozilla office shows a blurred GitHub repository page with a private key representation.

Mozilla Revokes Firefox Signing Key After GitHub Exposure

Mozilla sprang into action after discovering a sensitive Firefox signing key had been mistakenly uploaded to a private GitHub repository, revoking the exposed key and implementing extra safeguards to prevent future mishaps. Fortunately, the company found no evidence that the key was compromised during its brief online exposure.

Analyst 207