Skip to main content

Tag: vulnerability management

549 articles

Cluttered home office workspace with a Linux workstation and laptop in focus.

Arch Linux Disables AUR Package Adoption Amid Malware Surge

To protect its users, Arch Linux has temporarily disabled package adoption on its Arch User Repository (AUR) due to a surge in malware takeovers. The move is a temporary measure to handle the situation, with the team promising to reinstate the feature once it's safe to do so.

Analyst 207
Laptop screen on a clean desk with a blurred background, indicating activity with a subtle gradient effect.

Google Accelerates Chrome Security Updates to Counter AI-Powered Attacks

Google's Chrome Security Team is stepping up the pace of security updates to outsmart AI-powered attacks, and it's making a big impact: in just three releases, Chrome 149-151, the team fixed a staggering 1,442 flaws, including a 13-year blind spot discovered with the help of Gemini.

Analyst 207
A researcher's workspace with laptop, notes, and coding materials near a window with ambient daylight.

Google Leverages AI to Fix 1,072 Chrome Security Bugs

Google is supercharging Chrome's security with AI, and the results are staggering: a whopping 1,072 security bugs were squashed in Chrome 149 and 150, outpacing the total fixed in the previous 23 milestones combined. The tech giant is now using large language models to turbocharge its vulnerability management process, from sniffing out flaws to generating patches.

Analyst 207
Server room with IT staff in background, focus on single server with open panel showing circuit boards and cables.

Attackers Exploit, Then Manipulate: The Post-Breach Playbook

Attackers often find an open door in our defenses, exploiting weaknesses like SQL injection vulnerabilities to gain a foothold - and then manipulate systems to wreak havoc. A recent incident revealed how an unvalidated input field on a webpage led to a full-blown breach of a Microsoft SQL Server host.

Analyst 207
Cisco Secure Firewall Management Center device on a rack in a network operations center corridor.

Cisco FMC Zero-Day Exploited with Static Credentials

A newly discovered zero-day vulnerability in Cisco's Secure Firewall Management Center (FMC) Software, tracked as CVE-2026-20316, allows hackers to log in with static credentials and access sensitive data. This high-severity flaw could be exploited for unauthorized access, making it a critical concern for users.

Analyst 207
Rack-mounted device with blinking lights in a network operations center.

Cisco Warns of Actively Exploited FMC Credential Flaw

Cisco is warning of a high-severity vulnerability in its Secure Firewall Management Center (FMC) software, known as CVE-2026-20316, which is being actively exploited by hackers to gain unauthorized access to sensitive data. This flaw allows attackers to log in remotely using built-in static credentials, putting your system at risk.

Analyst 207
Shipping yard with container in foreground and blurred computer workstation in background.

Ruflo Flaw Exposes AI Systems to Unauthenticated Code Execution

A critical vulnerability in Ruflo, known as RufRoot, allows hackers to execute code remotely without authentication, putting AI systems at risk. This severe flaw, rated 10.0 on the CVSS scale, affects all Ruflo versions before 3.16.3.

Analyst 207
Security architect analyzes network data on tablet and laptop in network operations center.

AI Compresses Exploit Timelines, Exposes Prioritization Flaws

The arrival of AI models like Anthropic's Mythos is compressing exploit timelines, shrinking the window to patch vulnerabilities from weeks to just days or even hours. This acceleration exposes flaws in traditional prioritization methods, where only a handful of findings truly matter - out of 50,000, only a dozen make the cut.

Analyst 207
Cybersecurity researcher working at a desk with laptop and papers.

AI-Discovered Vulnerabilities See Similar Exploitation Rates as Traditional Ones

New research reveals that vulnerabilities discovered using AI tools are being exploited at almost the same rate as those found through traditional methods, with a 1.3% exploitation rate for AI-discovered vulnerabilities. This challenges alarmist predictions of an impending AI-driven security crisis.

Analyst 207
Researcher working at a lab bench with technology and security tools, surrounded by notes and diagrams.

AI-Assisted Tools Discover More Vulnerabilities, But Exploitation Rate Remains Steady

AI-assisted tools are supercharging vulnerability discovery, uncovering over 1,000 new defects in just six months, yet the rate of exploitation remains surprisingly steady, with only 1.3% of AI-discovered vulnerabilities being exploited in the wild. This finding challenges the notion that AI-discovered vulnerabilities are inherently more attractive to attackers.

Analyst 207
Researcher's workstation with laptop, books, and notes, under bright lighting, with a focused yet inactive atmosphere.

AI-Assisted Bug Discovery Falls Short of Expected Exploit Wave

The hype around AI-assisted bug discovery may have been overstated, as a recent analysis found that only 1.3% of vulnerabilities identified with AI have been confirmed as exploited in the wild. This surprisingly low rate suggests that AI-assisted discovery may not be the silver bullet for uncovering easily exploitable vulnerabilities.

Analyst 207
Rows of computer servers and management interfaces in a data center or server room.

IPMI Vulnerability Exposes 24,650 Server Management Interfaces

A recent security researcher found that over 30% of server management interface passwords can be easily cracked using common wordlists and factory default patterns, exposing a massive 24,650 interfaces to potential threats. This startling vulnerability, CVE-2013-4786, allows hackers to gain unauthorized access to sensitive server management hardware.

Analyst 207
Bank branch interior with a sign reading Online Services Unavailable.

CAF Bank Halts Online Services Over Third-Party Software Vulnerability

CAF Bank has temporarily halted its online banking service due to a third-party software vulnerability, and customers are being supported while the issue is resolved with the help of external experts. The bank's CEO, Alison Taylor, has apologized for the disruption, assuring customers that access will be restored once the connection is secure.

Analyst 207
Model repository and cards on a clean, neutral-colored table in a lab or tech workspace.

Flaws in Hugging Face Diffusers Bypass Code Safeguards

Researchers uncovered a disturbing vulnerability in Hugging Face's diffusers library, where three high-severity flaws allowed hackers to secretly execute malicious code through model repositories, bypassing built-in safeguards designed to prevent such threats. This alarming exploit highlights the urgent need for enhanced security measures in AI repositories.

Analyst 207
Network management system setup with large computer screen and servers in a brightly-lit data center environment.

Arista Disrupts Actively Exploited VeloCloud Bug

Arista warns of a critical vulnerability in VeloCloud Orchestrator On-Prem, which is being actively exploited by hackers, putting the confidentiality, integrity, and availability of sensitive data at risk. This severe OS command injection flaw, scoring a perfect 10.0 on the CVSS scale, allows unauthorized access to internal functionality, compromising entire networks.

Analyst 207
Rows of computer servers and equipment in a well-lit server room or data center.

TeamCity Flaw Enables Unauthenticated Remote Code Execution

A critical TeamCity vulnerability, CVE-2026-63077, with a near-perfect CVSS score of 9.8, leaves all on-premise servers open to unauthenticated remote code execution - allowing attackers to run malicious commands with ease. Update your TeamCity server immediately to prevent exploitation.

Analyst 207
Outdated computer equipment sits alongside modern technology in a dimly lit factory room.

Legacy Technology Exposes Nations to Growing Cyber Risk

The clock is ticking: with legacy technology, organisations know the risks, but lack a mechanism to spark change, leaving nations vulnerable to growing cyber threats. As exploits and AI evolve at breakneck speed, the window for protection is shrinking fast.

Analyst 207
Network control room with large screens displaying abstracted interface.

Arista Disrupts Zero-Day Attacks on VeloCloud Orchestrator

Arista has patched a critical zero-day vulnerability in its VeloCloud Orchestrator that allowed attackers to launch devastating, maximum-severity attacks with just network access - no login credentials required. The flaw, rated 10.0 in severity, could compromise the confidentiality, integrity, and availability of sensitive data managed by the orchestrator.

Analyst 207
Sleek computer terminal with futuristic security props on minimalist background.

Microsoft Unveils AI-Powered Security Model to Outperform Rivals

Microsoft just unveiled a game-changing AI-powered security model that has achieved a remarkable 95.95 percent success rate in identifying vulnerabilities, leaving the competition in the dust. This innovative model, combined with the MDASH harness, is poised to revolutionize bug hunting and cybersecurity.

Analyst 207
Software development workspace with laptop, notebook, and papers on a desk in front of a blurred coding environment and a…

GitHub Targets Supply Chain Attacks with Dependabot Cooldown

GitHub's new Dependabot cooldown feature gives you a security boost by waiting at least three days after a release is published before updating dependencies, helping to prevent rapid adoption of malicious package releases. This brief pause allows time to catch poisoned or trojanized packages, keeping your projects safer.

Analyst 207
Developer workstation with laptop and notes in a bright, daytime office environment.

GitHub, PyPI Fortify Defenses Against Supply Chain Attacks

GitHub and PyPI are stepping up their game to shield against supply chain attacks, introducing time-based gates to slow down the release of potentially risky package updates. GitHub's Dependabot now delays updates for 72 hours, while PyPI will reject new files added to releases over 14 days old.

Analyst 207
Technicians in a server room inspect equipment amidst rows of racks and storage devices.

Redis Exposes Zero-Days, RCE Exploit in Latest Security Releases

Redis just released seven security updates to fix major vulnerabilities that could let attackers run malicious code remotely, thanks to newly published proof-of-concept exploits targeting several Redis versions. The fixes cover multiple branches, including 6.x, 7.x, and 8.x, and patch memory-corruption flaws that can be triggered using the RESTORE command and other requirements.

Analyst 207
Brightly-lit computer server room with rows of equipment and a central node.

NodeBB Fixes Flaws Exposing Admin Access, Private Chats

NodeBB has patched eight high-severity security flaws that left its forum platform vulnerable to admin access and private chat exposure, affecting all versions prior to 4.14.0. Admins should install the fixes immediately to safeguard their sites.

Analyst 207
Developer workstation with laptop, monitor, and notes, surrounded by empty coffee cups in a brightly lit room.

Malware Exploits Trust In Ordinary Systems

This week's ThreatsDay bulletin revealed a disturbing trend: hackers are disguising malware as ordinary tools and features, using familiar names and routine functions to infiltrate code repositories, desktop systems, mobile apps, and more. Even trusted platforms like GitHub and PyPI are being exploited, with GitHub announcing a security update to block vulnerable support bundle uploads.

Analyst 207