Tag: vulnerability management
549 articles

Microsoft Patch Tuesday Disrupts 400 Flaws, Zero-Day Exploits
Microsoft's August Patch Tuesday update is a doozy, tackling a whopping 400 security flaws, including a zero-day vulnerability that's already being exploited by hackers. This massive release also includes fixes for two other zero-day vulnerabilities that were publicly disclosed.

Cursor Security Flaw Enables Pre-Trust Command Execution
A security flaw in Cursor allowed hackers to run malicious commands on a developer's machine before they even had a chance to trust the repository, thanks to a vulnerability in its isolated worktree feature. Fortunately, a fix was swiftly rolled out just three days after Manifold Security reported the issue on July 20.

Ransomware gangs exploit Microsoft SharePoint flaw
Ransomware gangs are actively exploiting a high-severity Microsoft SharePoint flaw, known as CVE-2026-45659, that allows them to execute arbitrary code on unpatched servers, and it's crucial to patch up ASAP to avoid falling victim. Microsoft has already released security updates for affected SharePoint versions, so make sure to get those installed pronto!

AI Agents Expose Enterprises to Growing Prompt Injection Risk
A recent security audit revealed a staggering 36% of AI agent skills contain critical-level security issues, including malware distribution, prompt injection attacks, and exposed secrets. This widespread risk can have serious consequences for enterprises that deploy these skills in their production workflows.

NATO, AI Startup Gain Power to Track Software Vulnerabilities
The cybersecurity landscape just got a major boost: NATO's Cyber Security Centre and AI startup AISLE have joined forces with ENISA to supercharge vulnerability management, bringing the total number of CVE numbering authorities to 20. This powerful collaboration aims to revolutionize the way we track software vulnerabilities and stay one step ahead of cyber threats.

CISA Warns of Active Progress Kemp LoadMaster Exploit Attempts
The US Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm on a critical flaw in Progress Kemp LoadMaster, warning of a surge in exploitation attempts - 792 attempts in just 41 days - and adding the bug to its list of known exploited vulnerabilities. This highly severe vulnerability, with a CVSS score of 9.6, allows attackers to execute arbitrary commands on the LoadMaster appliance without authentication.

AI-Generated Patches Found Flawed in Testing
Researchers put AI-generated patches to the test and found that ChatGPT and Claude only succeeded in fixing high-impact vulnerabilities about 47% of the time, leaving a significant gap in remediation. This surprisingly low success rate raises important questions about the reliability of AI-generated solutions for critical security flaws.

WordPress Fixes Pre-Auth XSS Flaw That Enables PHP Code Execution
WordPress has patched a high-severity flaw that could let attackers inject malicious code into your site - and it's crucial you update ASAP, as 41.2% of all websites are potentially vulnerable.

Flaws in AI Coding Tools Expose CI Workflow Secrets
Researchers have uncovered critical flaws in AI coding tools that can expose sensitive CI workflow secrets, allowing low-privilege code to execute and cross privilege boundaries. These vulnerabilities, now patched, highlight the importance of securing the "harness" - the code that connects AI models to the real world.

AI Patches Fall Short Without Human Oversight
Researchers at 1Password's Off-by-1 Labs put AI to the test, generating 6,080 patches for six real vulnerabilities - but here's the catch: human oversight was crucial to ensuring those patches actually worked. Even with advanced models like ChatGPT and Claude Opus, AI patches fell short without a human in the loop.

Cisco Fixes Flaws in SD-WAN, IOS XE Software
Cisco has patched critical vulnerabilities in its SD-WAN and IOS XE software, discovered during rigorous internal security testing, to keep your network safe. Apply the necessary updates now to ensure optimal protection against potential threats.

Humans Miss Third of Malicious AI Coding Requests
Can you really trust your instincts to spot malicious AI coding requests? A recent browser game experiment revealed that humans miss a whopping one in three malicious requests, making them the weakest link in the approval process.

CISA Warns of Active TeamCity Exploit
Warning: a critical vulnerability in JetBrains TeamCity (CVE-2026-63077) is being actively exploited in the wild, allowing unauthenticated attackers to execute malicious code remotely. This severe flaw has a CVSS score of 9.8, highlighting the urgent need for immediate action.

Paperclip AI Flaws Expose Servers to Host Command Attacks
Harmless-looking configuration files can quickly turn into a nightmare, as Oasis Security warns that Paperclip AI flaws can allow attackers to execute host commands, all by treating agent configuration as executable input. This vulnerability, including one flaw scored 10.0 by CVSS, can be exploited by unauthenticated actors to gain control of servers.

CISA Warns of Active Exploits in Langflow, N-central, Apache Tomcat Flaws
A critical flaw in IBM's Langflow, rated 9.8 out of 10, allows hackers to remotely execute code on vulnerable systems - and multiple easy-to-follow exploits have already surfaced online. This severe vulnerability enables attackers to bypass login and wreak havoc, making it a pressing concern for Langflow users.

Gitea Flaw Exposes Server Files to Unauthenticated Attackers
A critical vulnerability, CVE-2026-59774, left self-hosted Gitea servers open to attack, allowing unauthenticated hackers to access sensitive files. Immediate action is required for self-hosted administrators to upgrade to version 1.27.1 and prevent exploitation.

Zero-Knowledge Proofs Offer Secure Path for Cyber Risk Disclosure
ZKPs offer a game-changing solution, allowing companies to securely share proof of vulnerabilities without exposing sensitive data that could be exploited by attackers. By using ZKPs, organizations can demonstrate the truth of a statement, such as confirming a specific vulnerability exists, without revealing confidential details.

AI-Powered Vulnerability Discovery Surges, Threatens Patch Window
In a staggering two-month sprint, Palo Alto Networks' NOVA uncovered 14,090 confirmed vulnerabilities in just 3,915 open-source software projects - a remarkable demonstration of AI-powered vulnerability discovery's rapid impact. This autonomous pipeline is revolutionizing the way we identify and tackle software vulnerabilities.

Generative AI Disrupts Hacker Landscape
The technical barriers that once limited credible cyberattacks are rapidly eroding, making it essential to rethink security strategies and prioritize exploitable risk over theoretical exposure. With generative AI, the traditional ranking of attacker sophistication is collapsing, empowering less-skilled hackers to launch more potent threats.

CISA Flags N-able N-central Flaw as Exploited Vulnerability
A critical flaw in N-able N-central has been flagged by CISA as an exploited vulnerability, allowing attackers to bypass authentication and take over accounts. This weakness, known as CVE-2026-18577, lets hackers gain admin access to vulnerable servers and deploy malicious persistence mechanisms.

Fake Vulnerabilities Flood CVE Pipeline via AI-Generated Reports
The CVE pipeline is being flooded with fake vulnerability reports generated by AI, which are then assigned scores as high as 9.8, only to be later debunked as non-existent flaws. Security vendor JFrog recently uncovered six bogus SQLite vulnerabilities, highlighting the alarming ease with which unverified reports can enter the system.

N-able Discloses Auth Bypass Flaw in N-central Exploited in Attacks
A critical authentication bypass vulnerability, CVE-2026-18577, is under active attack, putting N-able's N-central servers at risk - but a hotfix (2026.3.1.7) is now available to prevent further exploitation. This flaw is linked to an earlier, incomplete patch for CVE-2026-18576, which also threatened administrative account takeovers.

N-able Servers Compromised After Incomplete Fix
N-able's servers were compromised due to an incomplete fix for a critical vulnerability, allowing attackers to exploit an authentication bypass and gain remote administrative access to on-premises servers and customer systems. The incident highlights the importance of thorough patching, as N-able's initial fix failed to fully address the issue.

Big Tech Bolsters Open-Source AI as Attackers Target Vulnerabilities
Big tech giants like Nvidia, Amazon, and Google are joining forces to supercharge open-source AI, embracing a new era of transparency and collaboration. By adopting open-weight models, they're acknowledging that the future of AI safety lies in community-driven innovation and collective vigilance.