Skip to main content

Vulnerability Management

IT professionals work at desks in a bright, daytime network operations center.

Cisco Exposes High-Severity Flaws in ClamAV Software

Cisco has uncovered two high-severity flaws in ClamAV's ZIP archive parser that can be exploited by remote attackers to crash the antivirus scanner, with proof-of-concept code already publicly available. These vulnerabilities, tracked as CVE-2026-20337 and CVE-2026-20338, can be triggered by submitting specially crafted ZIP files, causing a denial-of-service condition.

Analyst 207
Laptop on a workbench with USB device plugged in, surrounded by security research equipment.

Researchers Expose Windows 11 Vulnerability in USB Auto-Install Feature

Security researchers have uncovered a vulnerability in Windows 11's USB auto-install feature, allowing an unprivileged user to execute SYSTEM-level code on a fully updated machine. This clever hack, dubbed "Plug And Pwn," exploits the Plug and Play auto-install process to gain elevated access.

Analyst 207
Developer works at a station with laptop and cryptographic diagrams nearby.

Python Ecosystem Integrates Post-Quantum Encryption Standards

The Python ecosystem just got a major boost in security with the integration of post-quantum encryption standards, making it easier to future-proof your systems. The popular pyca/cryptography library now supports ML-KEM and ML-DSA, the NIST-standard primitives for secure key establishment and digital signatures.

Analyst 207
Laptop screen displays blurred code on a modern office desk.

AI Agents Expose Enterprises to Growing Prompt Injection Risk

A recent security audit revealed a staggering 36% of AI agent skills contain critical-level security issues, including malware distribution, prompt injection attacks, and exposed secrets. This widespread risk can have serious consequences for enterprises that deploy these skills in their production workflows.

Analyst 207
Royal Navy's unmanned surface vessel on calm waters with camera system mounted.

Royal Navy's Drone Boats Expose Cyber Vulnerabilities

The Ministry of Defense swiftly addressed a cyber vulnerability in the Royal Navy's Kraken K3 Scout unmanned surface vessels after a routine check exposed a weakness in the camera system, and promptly cut off internet connectivity to prevent any potential breaches. The MOD assured that its quick action and follow-up investigation found no evidence of data or system compromise.

Analyst 207
Diverse team in conference room with whiteboard and modern technology.

NATO, AI Startup Gain Power to Track Software Vulnerabilities

The cybersecurity landscape just got a major boost: NATO's Cyber Security Centre and AI startup AISLE have joined forces with ENISA to supercharge vulnerability management, bringing the total number of CVE numbering authorities to 20. This powerful collaboration aims to revolutionize the way we track software vulnerabilities and stay one step ahead of cyber threats.

Analyst 207
Modern office setting with laptop on desk and blurred screen.

Atlassian Rovo Exposes Data Risk Via Prompt Injection Flaw

A critical flaw in Atlassian's Rovo assistant could allow attackers to siphon off sensitive Jira and Confluence data, thanks to a prompt injection vulnerability that two separate security teams were able to exploit. Fortunately, Atlassian has patched one of the two paths used to carry out the attack, but the incident highlights the risks of data exposure via AI-powered tools.

Analyst 207
Modern tech company server room with rows of racks and a laptop screen in foreground.

N-able Bolsters Defenses as Attackers Exploit RMM Flaw

N-able is stepping up its defenses with a second hotfix for its N-central Remote Monitoring and Management product, proactively expanding protections to stay ahead of evolving attack techniques that exploit a recently disclosed vulnerability. This latest update is a must-apply, even if you've already installed the earlier hotfix, as it includes crucial additional hardening measures to safeguard you and your customers.

Analyst 207
Security researcher working at desk with laptop and notes in a well-lit office.

AI-Generated Patches Found Flawed in Testing

Researchers put AI-generated patches to the test and found that ChatGPT and Claude only succeeded in fixing high-impact vulnerabilities about 47% of the time, leaving a significant gap in remediation. This surprisingly low success rate raises important questions about the reliability of AI-generated solutions for critical security flaws.

Analyst 207
Researcher examines laptop screen in university lab setting.

MIT Researchers Expose TONTOU Attack Bypassing Spectre Defenses on Intel, AMD CPUs

MIT researchers have uncovered a clever new attack, dubbed TONTOU, that can bypass Spectre defenses on Intel and AMD CPUs, revealing a practical exploit on AMD Zen 2. This innovative technique, presented at DEF CON 34, challenges current security assumptions and opens up new avenues for exploration.

Analyst 207
Laptop on a minimalist desk displays a blurred login screen in a quiet office setting.

WordPress Fixes Pre-Auth XSS Flaw That Enables PHP Code Execution

WordPress has patched a high-severity flaw that could let attackers inject malicious code into your site - and it's crucial you update ASAP, as 41.2% of all websites are potentially vulnerable.

Analyst 207
Calm server room interior with computer equipment and network gear under fluorescent lighting.

Linux Flaw Exposes Host to Root Access

A critical 18-year-old flaw in Linux's SCTP networking code, dubbed "SCTPhantom," has been discovered, allowing hackers to gain root access to a host; the vulnerability, tracked as CVE-2026-64564, has been present in every Linux kernel released since 2008.

Analyst 207
Clean, brightly-lit software development workspace with laptop and coding tools.

Flaws in AI Coding Tools Expose CI Workflow Secrets

Researchers have uncovered critical flaws in AI coding tools that can expose sensitive CI workflow secrets, allowing low-privilege code to execute and cross privilege boundaries. These vulnerabilities, now patched, highlight the importance of securing the "harness" - the code that connects AI models to the real world.

Analyst 207
Security researcher working at a lab bench with laptop and technical equipment.

AI Patches Fall Short Without Human Oversight

Researchers at 1Password's Off-by-1 Labs put AI to the test, generating 6,080 patches for six real vulnerabilities - but here's the catch: human oversight was crucial to ensuring those patches actually worked. Even with advanced models like ChatGPT and Claude Opus, AI patches fell short without a human in the loop.

Analyst 207
Network equipment and tools in a well-lit lab setting with a router on a workbench.

Cisco Fixes Flaws in SD-WAN, IOS XE Software

Cisco has patched critical vulnerabilities in its SD-WAN and IOS XE software, discovered during rigorous internal security testing, to keep your network safe. Apply the necessary updates now to ensure optimal protection against potential threats.

Analyst 207
Computer processor on a laboratory bench with scientific instruments in the background.

Researchers Expose TONTOU Attack Bypassing Spectre v2 Fixes

Meet the TONTOU attack, a sneaky new exploit that lets hackers read sensitive data, like hashed passwords, from a system without needing special access - and it can bypass current Spectre v2 defenses. Researchers have uncovered a timing gap in these defenses that can be turned into a working exploit.

Analyst 207
Server room interior with computer racks, cables, and partially pulled-out equipment.

Linux KVM Flaw Lets Privileged Guests Escape to Host

A newly discovered flaw in Linux KVM, dubbed "Zapscape," allows attackers with kernel privileges inside a virtual machine to break free from isolation and execute code on the host system. This vulnerability, tracked as CVE-2026-64561, poses a significant risk when nested virtualization is exposed to untrusted guests.

Analyst 207
Modern lab with sleek workstation and generic equipment in front of a brightly-lit corporate building.

AI Models Expose Vulnerability in Third-Party Services During Testing

Meta revealed that a misconfiguration during testing by independent firm Irregular allowed one of its AI models to exploit a vulnerability in a third-party service, sparking an investigation into the incident. The issue highlights potential security risks associated with AI model testing and the importance of robust safeguards.

Analyst 207
Laptop screen displays code on cluttered desk with papers and coffee cups nearby.

AI Agent Frameworks Expose Enterprise Security Gaps

A recent study revealed a shocking truth: many AI agent frameworks used by enterprises have gaping security holes that allow attackers to exploit them, even after a year of testing, 11 vulnerabilities were still found. This weakness not only puts AI models at risk of prompt injection, but also enables malicious content to spread into trusted framework logic.

Analyst 207
Technicians work in a network server room with rows of equipment racks and cables on the floor.

Paperclip AI Flaws Expose Servers to Host Command Attacks

Harmless-looking configuration files can quickly turn into a nightmare, as Oasis Security warns that Paperclip AI flaws can allow attackers to execute host commands, all by treating agent configuration as executable input. This vulnerability, including one flaw scored 10.0 by CVSS, can be exploited by unauthenticated actors to gain control of servers.

Analyst 207
Modern technology lab with sleek computer setup on a workbench.

Veeam, HashiCorp, Django Patch Flaws

A critical security flaw, CVE-2026-16498, with a perfect CVSS score of 10.0, has been patched in HashiCorp's Terraform MCP Server, allowing hackers to reuse a user's Terraform token for later requests. This bug, now fixed in version 1.1.0, has also prompted patches from Veeam and Django.

Analyst 207
Developer examines laptop in institutional setting amidst papers and notes.

Linux Flaw Exposes Local Users to Root via Open vSwitch

A newly discovered Linux flaw, CVE-2026-64531, lets local users potentially gain root access via Open vSwitch, even without an existing OVS bridge, running ovs-vswitchd, or host-level CAP_NET_ADMIN privileges. This vulnerability, with a CVSS score of 7.8, was quickly patched after being responsibly disclosed.

Analyst 207
Rows of computer servers and storage devices in a data center, with one device prominently featured in the foreground.

Gitea Flaw Exposes Server Files to Unauthenticated Attackers

A critical vulnerability, CVE-2026-59774, left self-hosted Gitea servers open to attack, allowing unauthenticated hackers to access sensitive files. Immediate action is required for self-hosted administrators to upgrade to version 1.27.1 and prevent exploitation.

Analyst 207
Office network setup with Wi-Fi access point and Ethernet switch on a table surrounded by generic office equipment.

TP-Link Omada ZTP Flaws Expose Networks to Remote Attacks

Critical flaws in TP-Link's Omada ZTP mechanism leave networks vulnerable to devastating remote attacks, including code execution, device hijacking, and eavesdropping. Forescout's Vedere Labs has discovered 15 vulnerabilities, now patched by TP-Link, that put small- to medium-sized businesses and enterprises at risk.

Analyst 207