Tag: vulnerability management
549 articles

Arch Linux Disables AUR Package Adoption Amid Malware Surge
To protect its users, Arch Linux has temporarily disabled package adoption on its Arch User Repository (AUR) due to a surge in malware takeovers. The move is a temporary measure to handle the situation, with the team promising to reinstate the feature once it's safe to do so.

Google Accelerates Chrome Security Updates to Counter AI-Powered Attacks
Google's Chrome Security Team is stepping up the pace of security updates to outsmart AI-powered attacks, and it's making a big impact: in just three releases, Chrome 149-151, the team fixed a staggering 1,442 flaws, including a 13-year blind spot discovered with the help of Gemini.

Google Leverages AI to Fix 1,072 Chrome Security Bugs
Google is supercharging Chrome's security with AI, and the results are staggering: a whopping 1,072 security bugs were squashed in Chrome 149 and 150, outpacing the total fixed in the previous 23 milestones combined. The tech giant is now using large language models to turbocharge its vulnerability management process, from sniffing out flaws to generating patches.

Attackers Exploit, Then Manipulate: The Post-Breach Playbook
Attackers often find an open door in our defenses, exploiting weaknesses like SQL injection vulnerabilities to gain a foothold - and then manipulate systems to wreak havoc. A recent incident revealed how an unvalidated input field on a webpage led to a full-blown breach of a Microsoft SQL Server host.

Cisco FMC Zero-Day Exploited with Static Credentials
A newly discovered zero-day vulnerability in Cisco's Secure Firewall Management Center (FMC) Software, tracked as CVE-2026-20316, allows hackers to log in with static credentials and access sensitive data. This high-severity flaw could be exploited for unauthorized access, making it a critical concern for users.

Cisco Warns of Actively Exploited FMC Credential Flaw
Cisco is warning of a high-severity vulnerability in its Secure Firewall Management Center (FMC) software, known as CVE-2026-20316, which is being actively exploited by hackers to gain unauthorized access to sensitive data. This flaw allows attackers to log in remotely using built-in static credentials, putting your system at risk.

Ruflo Flaw Exposes AI Systems to Unauthenticated Code Execution
A critical vulnerability in Ruflo, known as RufRoot, allows hackers to execute code remotely without authentication, putting AI systems at risk. This severe flaw, rated 10.0 on the CVSS scale, affects all Ruflo versions before 3.16.3.

AI Compresses Exploit Timelines, Exposes Prioritization Flaws
The arrival of AI models like Anthropic's Mythos is compressing exploit timelines, shrinking the window to patch vulnerabilities from weeks to just days or even hours. This acceleration exposes flaws in traditional prioritization methods, where only a handful of findings truly matter - out of 50,000, only a dozen make the cut.

AI-Discovered Vulnerabilities See Similar Exploitation Rates as Traditional Ones
New research reveals that vulnerabilities discovered using AI tools are being exploited at almost the same rate as those found through traditional methods, with a 1.3% exploitation rate for AI-discovered vulnerabilities. This challenges alarmist predictions of an impending AI-driven security crisis.

AI-Assisted Tools Discover More Vulnerabilities, But Exploitation Rate Remains Steady
AI-assisted tools are supercharging vulnerability discovery, uncovering over 1,000 new defects in just six months, yet the rate of exploitation remains surprisingly steady, with only 1.3% of AI-discovered vulnerabilities being exploited in the wild. This finding challenges the notion that AI-discovered vulnerabilities are inherently more attractive to attackers.

AI-Assisted Bug Discovery Falls Short of Expected Exploit Wave
The hype around AI-assisted bug discovery may have been overstated, as a recent analysis found that only 1.3% of vulnerabilities identified with AI have been confirmed as exploited in the wild. This surprisingly low rate suggests that AI-assisted discovery may not be the silver bullet for uncovering easily exploitable vulnerabilities.

IPMI Vulnerability Exposes 24,650 Server Management Interfaces
A recent security researcher found that over 30% of server management interface passwords can be easily cracked using common wordlists and factory default patterns, exposing a massive 24,650 interfaces to potential threats. This startling vulnerability, CVE-2013-4786, allows hackers to gain unauthorized access to sensitive server management hardware.

CAF Bank Halts Online Services Over Third-Party Software Vulnerability
CAF Bank has temporarily halted its online banking service due to a third-party software vulnerability, and customers are being supported while the issue is resolved with the help of external experts. The bank's CEO, Alison Taylor, has apologized for the disruption, assuring customers that access will be restored once the connection is secure.

Flaws in Hugging Face Diffusers Bypass Code Safeguards
Researchers uncovered a disturbing vulnerability in Hugging Face's diffusers library, where three high-severity flaws allowed hackers to secretly execute malicious code through model repositories, bypassing built-in safeguards designed to prevent such threats. This alarming exploit highlights the urgent need for enhanced security measures in AI repositories.

Arista Disrupts Actively Exploited VeloCloud Bug
Arista warns of a critical vulnerability in VeloCloud Orchestrator On-Prem, which is being actively exploited by hackers, putting the confidentiality, integrity, and availability of sensitive data at risk. This severe OS command injection flaw, scoring a perfect 10.0 on the CVSS scale, allows unauthorized access to internal functionality, compromising entire networks.

TeamCity Flaw Enables Unauthenticated Remote Code Execution
A critical TeamCity vulnerability, CVE-2026-63077, with a near-perfect CVSS score of 9.8, leaves all on-premise servers open to unauthenticated remote code execution - allowing attackers to run malicious commands with ease. Update your TeamCity server immediately to prevent exploitation.

Legacy Technology Exposes Nations to Growing Cyber Risk
The clock is ticking: with legacy technology, organisations know the risks, but lack a mechanism to spark change, leaving nations vulnerable to growing cyber threats. As exploits and AI evolve at breakneck speed, the window for protection is shrinking fast.

Arista Disrupts Zero-Day Attacks on VeloCloud Orchestrator
Arista has patched a critical zero-day vulnerability in its VeloCloud Orchestrator that allowed attackers to launch devastating, maximum-severity attacks with just network access - no login credentials required. The flaw, rated 10.0 in severity, could compromise the confidentiality, integrity, and availability of sensitive data managed by the orchestrator.

Microsoft Unveils AI-Powered Security Model to Outperform Rivals
Microsoft just unveiled a game-changing AI-powered security model that has achieved a remarkable 95.95 percent success rate in identifying vulnerabilities, leaving the competition in the dust. This innovative model, combined with the MDASH harness, is poised to revolutionize bug hunting and cybersecurity.

GitHub Targets Supply Chain Attacks with Dependabot Cooldown
GitHub's new Dependabot cooldown feature gives you a security boost by waiting at least three days after a release is published before updating dependencies, helping to prevent rapid adoption of malicious package releases. This brief pause allows time to catch poisoned or trojanized packages, keeping your projects safer.

GitHub, PyPI Fortify Defenses Against Supply Chain Attacks
GitHub and PyPI are stepping up their game to shield against supply chain attacks, introducing time-based gates to slow down the release of potentially risky package updates. GitHub's Dependabot now delays updates for 72 hours, while PyPI will reject new files added to releases over 14 days old.

Redis Exposes Zero-Days, RCE Exploit in Latest Security Releases
Redis just released seven security updates to fix major vulnerabilities that could let attackers run malicious code remotely, thanks to newly published proof-of-concept exploits targeting several Redis versions. The fixes cover multiple branches, including 6.x, 7.x, and 8.x, and patch memory-corruption flaws that can be triggered using the RESTORE command and other requirements.

NodeBB Fixes Flaws Exposing Admin Access, Private Chats
NodeBB has patched eight high-severity security flaws that left its forum platform vulnerable to admin access and private chat exposure, affecting all versions prior to 4.14.0. Admins should install the fixes immediately to safeguard their sites.

Malware Exploits Trust In Ordinary Systems
This week's ThreatsDay bulletin revealed a disturbing trend: hackers are disguising malware as ordinary tools and features, using familiar names and routine functions to infiltrate code repositories, desktop systems, mobile apps, and more. Even trusted platforms like GitHub and PyPI are being exploited, with GitHub announcing a security update to block vulnerable support bundle uploads.