Skip to main content

Tag: vulnerability disclosure

54 articles

Collaborative software development workspace with team members working on laptops and whiteboards surrounded by notes and…

Linux Foundation's Akrites to Launch Vulnerability Platform in September

Get ready for a game-changer in vulnerability management: Akrites, launched by the Linux Foundation, is set to unveil a groundbreaking platform in September that streamlines AI-enabled vulnerability reports to open-source maintainers, ensuring swift fixes for the entire ecosystem. By doing so, it will revolutionize the way we tackle security incidents and vulnerability disclosure.

Analyst 207
Smartphone on cluttered office desk with cityscape background through window.

Unisoc Exploit Chain Grants Attackers Full Android Kernel Access

Security researchers have uncovered a two-stage exploit chain that can give attackers full access to the Android kernel on devices using Unisoc modem firmware, and alarmingly, the vendor has remained unresponsive to disclosure efforts. This chain can be triggered by a simple malformed video call, putting countless devices at risk.

Analyst 207
A generic router sits on a neutral surface with visible lights and ports.

Zbtlink Router Firmware Exposes Potential Backdoor Risks

Some Zbtlink routers have a shocking secret: they come equipped with a built-in backdoor that lets them phone home and wait for orders, all without needing to be hacked. This unsettling feature, dubbed ENDLESSDOORS, was found on twenty models across years of images, sparking concerns about potential security risks.

Analyst 207
Laptop screen displays code on cluttered desk with papers and coffee cups nearby.

AI Agent Frameworks Expose Enterprise Security Gaps

A recent study revealed a shocking truth: many AI agent frameworks used by enterprises have gaping security holes that allow attackers to exploit them, even after a year of testing, 11 vulnerabilities were still found. This weakness not only puts AI models at risk of prompt injection, but also enables malicious content to spread into trusted framework logic.

Analyst 207
Laptop on a clean surface with a blank screen and coding materials nearby.

Google AI Dev Kit Exposes Supply Chain Vulnerability

Researchers at Pillar Security have uncovered a shocking vulnerability in the Google AI Dev Kit, exposing a supply chain weakness that could allow malicious AI agents to manipulate and wreak havoc on repository workflows. This game-changing exploit has already been downloaded over 90 million times, making it a potentially massive threat.

Analyst 207
Close-up of laptop motherboard with firmware chip in focus on laboratory bench.

Microsoft Secure Boot Vulnerability Exposed After 13 Years

A shocking security vulnerability in Microsoft's Secure Boot, a safeguard designed to protect Windows and Linux devices from firmware infections, has been easily exploitable for 13 of its 14 years of existence. Researchers uncovered 11 defective firmware images, some dating back to 2013, that were still publicly available and signed by Microsoft, making it alarmingly simple to bypass the security measure.

Analyst 207
Rows of computer servers and networking equipment in a data center with a generic computer in the foreground.

OpenAI Models Exploit JFrog Zero-Days to Breach Hugging Face

OpenAI's models uncovered critical zero-day vulnerabilities in JFrog's self-hosted Artifactory installations, potentially granting hackers unrestricted internet access - but thanks to JFrog's swift response, fixes were rapidly developed and deployed to protect customers. The vulnerabilities, now patched, were responsibly disclosed by OpenAI researchers and publicly credited by JFrog.

Analyst 207
Researcher working at a lab bench with technology and security tools, surrounded by notes and diagrams.

AI-Assisted Tools Discover More Vulnerabilities, But Exploitation Rate Remains Steady

AI-assisted tools are supercharging vulnerability discovery, uncovering over 1,000 new defects in just six months, yet the rate of exploitation remains surprisingly steady, with only 1.3% of AI-discovered vulnerabilities being exploited in the wild. This finding challenges the notion that AI-discovered vulnerabilities are inherently more attractive to attackers.

Analyst 207
People from various industries collaborate in a modern conference room with laptops and whiteboards.

NVIDIA Launches Open Secure AI Alliance Without Key Players

NVIDIA is shaking up the AI security landscape with the launch of the Open Secure AI Alliance, a groundbreaking coalition of nearly 40 tech giants, including Adobe, Cisco, and Microsoft, dedicated to developing open-source security tools to safeguard artificial intelligence. By joining forces, they're building a robust defense stack to protect AI agents from identity threats to secure coding workflows.

Analyst 207
Smartphone displaying Click To Pray app in a neutral room with subtle church background.

Pope's Prayer App Leaks 700K Users' Info Amid Security Vulnerability

A shocking security breach has been uncovered in the Pope's official prayer app, Click To Pray, exposing the sensitive information of over 719,000 registered users for months due to a vulnerability that allowed anyone to access account data. The flaw, discovered by an ethical hacker, highlights the alarming risks of unsecured personal data.

Analyst 207
Person holding laptop with blurred screen, conveying vulnerability and digital security concerns.

Apple Rectifies Hide My Email Flaw That Exposed User Addresses

Apple has fixed a vulnerability in its Hide My Email feature that could have exposed user email addresses, although it's unclear how often the flaw was exploited. The flaw was discovered by security researchers and disclosed to Apple in June 2025.

Analyst 207
Windows computer workstation on a clean desk in a modern office with natural light.

Unofficial Patches Mitigate Windows Zero-Day Flaw

Microsoft is investigating a newly discovered Windows zero-day flaw, dubbed LegacyHive, and is working to update impacted products to protect customers as soon as possible. A researcher disclosed the vulnerability, along with a proof-of-concept exploit, on the same day as Microsoft's July 2024 Patch Tuesday updates.

Analyst 207
Cybersecurity team discusses around a conference table in a modern operations room.

Vulnerability Management Faces Patch Apocalypse Amid AI-Driven Discovery Surge

The AI-driven discovery surge is creating a perfect storm in vulnerability management, with nearly 48,000 CVEs published in 2025 alone, and a growing mismatch between rapid vulnerability discovery and slower human-led remediation. This has given rise to the "Patch Apocalypse," where the scale, speed, and exploitability of vulnerabilities are outpacing traditional patching approaches.

Analyst 207
Dimly lit computer laboratory with scattered technology equipment.

Anonymous Researcher Exploits 15 Software Products with Zero-Day Code Dump

A security bombshell has been dropped: an anonymous researcher has publicly shared exploit code for zero-day vulnerabilities in 15 software products, and hackers are already taking advantage of at least two of them. The alarming revelation has sent shockwaves through the cybersecurity community.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit server room.

phpBB Fixes Decade-Old Auth Bypass Bug

A major vulnerability in phpBB has been uncovered, allowing attackers to bypass authentication and log in as any user, including administrators, with ease and no special knowledge required. This decade-old bug, exploitable in default configurations, has been patched - but only after researchers took steps to privately disclose the issue to prevent widespread exploitation.

Analyst 207
Brightly-lit lab with computer workstations and equipment, large screen displays abstract code representation.

Microsoft Unveils Record 200 Patches, Warns of Rising AI-Driven Flaws

Microsoft just dropped a record 200 security patches to fix critical flaws in Windows and supported software, with nearly three dozen vulnerabilities rated as critical and at least three already being exploited by hackers. This massive update signals a new normal in vulnerability disclosure, with AI-driven flaws on the rise.

Analyst 207
Security researcher at laptop workstation with blurred screen, conveying tension.

Microsoft Revives Vulnerability Disclosure Debate with Researcher Crackdown

Microsoft is stirring up controversy in the vulnerability disclosure debate, clashing with a security researcher over the responsible handling of zero-day vulnerabilities. The tech giant's strong response, including threats of legal action, has sparked heated discussion on coordinated disclosure.

Analyst 207
Humanitarian aid distribution point with supplies and workers amidst a somber atmosphere, with a computer screen in the…

World Food Programme Breach Exposes 600k Gazan Family Records

A devastating data breach at the World Food Programme has left 600,000 vulnerable Gazan families exposed, with their personal records compromised - but thankfully, aid recipients have been assured that their support will continue uninterrupted.

Analyst 207
Smartphone on a neutral surface with a blurred mobile app interface and a hint of a cityscape through a nearby window.

Microsoft 365 Android Apps Expose Account Tokens Due to Debug Flag Oversight

A single line of code, "setIsDebugMode(true)," inadvertently left in multiple Microsoft 365 Android apps, created a gaping security hole that allowed other apps on the same phone to access sensitive account tokens without user permission. This tiny oversight, discovered by Enclave's Yanir Tsarimi and Ofek Levin, exposed users to potential security risks.

Analyst 207
Dimly lit computer workstation with code on laptop screen, surrounded by computer hardware and security research books.

Microsoft Threatens Security Researcher Over Windows Exploits

A mysterious security researcher known as "Nightmare Eclipse" has unleashed a string of powerful Windows exploits, including one that can bypass BitLocker, leaving Microsoft scrambling to respond. The bold move has sparked a tense standoff between the researcher and the tech giant.

Analyst 207
Vulnerability management team in high-tech operations room with large screens displaying data visualizations.

AI-Driven Exploitation Forces New Vulnerability Management Tactics

The threat landscape has changed: vulnerabilities are now being discovered, exploited, and weaponized in a matter of hours, leaving defenders scrambling to keep up. With AI-driven attacks accelerating, it's clear that traditional vulnerability management tactics just aren't fast enough.

Analyst 207
Person working at desk with laptop showing ChatGPT summary page surrounded by papers.

ChatGPT Vulnerability Exposes Users to Phishing Attacks via Web Summaries

Beware of ChatGPhish, a vulnerability in ChatGPT's web summarization feature that lets hackers disguise phishing attacks as harmless links and images. This security flaw could put you at risk of falling prey to scams via web summaries.

Analyst 207
Researcher's workstation with laptop, notes, and papers, overlooking office building.

Microsoft Faces Backlash Over Zero-Day Disclosure Feud

A researcher known as Nightmare Eclipse has unleashed a series of six Windows zero-day vulnerabilities, with working exploit code for at least three, and has threatened to release another on July 14, sparking a public feud with Microsoft. The ominous warning, which has left Microsoft speaking out against uncoordinated disclosures, has security experts on high alert.

Analyst 207
Windows desktop and laptop setup with blurred screen, featuring a subtle security symbol.

Microsoft Opposes Public Zero-Day Disclosures, Cites Customer Risk

Microsoft is speaking out against public zero-day disclosures, warning that revealing vulnerabilities without prior notice can put customers at unnecessary risk. The tech giant is urging researchers to adopt Coordinated Vulnerability Disclosure, sharing findings with affected vendors before going public.

Analyst 207