Skip to main content

Tag: vulnerability

663 articles

USB drive plugged into a laptop on a cluttered desk in a dimly lit home office with blurred screen.

Anonymous Researcher Exposes New Microsoft Zero-Days

A shocking new discovery by an anonymous researcher has revealed not one, but two fresh Windows zero-days, just days after Microsoft's monthly Patch Tuesday. Meet YellowKey, a sneaky BitLocker bypass that can be launched from a USB drive, giving attackers unrestricted access to a protected machine - if they can get their hands on it.

Analyst 207
Generic e-commerce setup with laptop on counter surrounded by packaging materials.

Škoda Discloses Data Breach After Online Shop Hack

Škoda's online shop was recently hacked, exposing customer data after attackers exploited a vulnerability in the e-commerce software. The company has since fixed the issue, alerted authorities, and is working with a forensics team to investigate.

Analyst 207
Laptop screen displays Jenkins plugin interface with code environment, beside blurred smartphone and sticky notes.

TeamPCP Breaches Checkmarx Jenkins Plugin Again

If you're using the Checkmarx Jenkins AST plugin, make sure you're on a safe footing by using version 2.0.13-829.vc72453fa_1c16 or earlier, published on December 17, 2025, as newer versions may be vulnerable. Checkmarx has since released a patched version, 2.0.13-848.v76e89de8a_053, available on GitHub and the Jenkins Marketplace.

Analyst 207
Server room with rows of equipment and a single server in the foreground, GGUF file on nearby surface.

Ollama Vulnerability Exposes Servers to Remote Memory Leak

A newly discovered vulnerability in Ollama, dubbed "Bleeding Llama," exposes over 300,000 servers worldwide to a severe remote memory leak, with a CVSS score of 9.1. This critical flaw, tracked as CVE-2026-7482, allows attackers to exploit a weakness in the GGUF model loader.

Analyst 207
Chrome browser window on laptop with multiple extensions, displaying blurred Claude AI interface on cluttered desk near…

Claude AI Extension Flaw Enables Cross-Plugin Hijacking

A security flaw in the Claude AI Chrome extension could put users at risk, as it allows other browser extensions to issue commands to Claude without verification. This vulnerability creates a backdoor for hackers to hijack the AI model, warns LayerX senior researcher Aviad Gispan.

Analyst 207
A clean and minimalist computer workstation with a laptop on a plain desk, surrounded by generic technical equipment.

Linux Flaw Exposes Root Access Risk

A newly discovered Linux kernel flaw, nicknamed Dirty Frag, poses a serious risk of root access to major Linux distributions, allowing attackers to exploit vulnerabilities and gain control. Security researcher Hyunwoo Kim found the flaw, which can be chained with other vulnerabilities to obtain root privileges.

Analyst 207
A minimalist room with a laptop, smartphone, and papers on a desk near large windows.

Bitcoin Core Exposes High-Severity Memory Safety Flaw

Bitcoin Core developers have disclosed a high-severity vulnerability, tracked as CVE-2024-52911, which is the project's first known memory safety flaw that could potentially allow remote code execution. This rare but critical bug was fixed months ago and affects Bitcoin Core releases from 2017 to early 2025.

Analyst 207
Cluttered developer workstation with laptop and monitor in shared office space.

Cline Kanban Flaw Exposes AI Coding Agents to Website Hijacking

A critical vulnerability in Cline Kanban's WebSocket endpoints lets hackers hijack websites visited by developers, silently interacting with local AI agents - and it's a flaw that requires zero phishing, malware, or social engineering. This severe flaw, scoring 9.7 on the CVSS scale, puts AI coding agents at risk of website hijacking.

Analyst 207
Close-up of Linux server room with a single workstation and equipment in sharp focus under soft daylight.

Linux Flaw Exposes Millions to Local Privilege Escalation

A critical Linux flaw, known as Copy Fail, has been discovered, exposing millions to potential local privilege escalation attacks - a vulnerability that highlights a deterministic logic error in the Linux kernel's cryptographic subsystem. This flaw, tracked as CVE-2026-31431, was publicly disclosed on April 29, 2026.

Analyst 207
Journalist sits at desk with laptop and papers, looking concerned in a neutral-colored room with a large window.

Polymarket Exposes Vulnerabilities in Event Verification Process

Polymarket's event verification process has exposed a glaring vulnerability, highlighting the risks of tying prediction market outcomes to fragile and easily manipulated sources of information. This weakness has even led to alarming threats against journalists, underscoring the urgent need for a more robust verification system.

Analyst 207
Secure server room with prominent terminal display.

Progress Warns of MOVEit Automation Authentication Bypass Flaw

Progress Software has patched a critical authentication-bypass flaw in its MOVEit Automation product, and is strongly urging users to upgrade to the latest version to avoid low-complexity attacks by remote threat actors. Upgrading to version 2025.1.5, 2025.0.9, or 2024.1.8 and above will fix the vulnerability.

Analyst 207
Linux workstation setup on a clean surface with technical books and notes in a quiet office.

CISA Warns of Active Linux Exploit

A newly discovered Linux kernel bug, dubbed "Copy Fail," allows unprivileged users to gain root privileges on unpatched systems, prompting urgent warnings from CISA and researchers. If your Linux system was built between 2017 and the recent patch, you're at risk - and need to act fast to protect yourself.

Analyst 207
Modern Linux workstation in a clean server room with natural daylight.

Linux Flaw Exposes Major Distros to Root Access

Meet CVE-2026-31431, aka "Copy Fail," a newly discovered Linux flaw that leaves major distros vulnerable to root access - and it's surprisingly easy to exploit, affecting a wide range of systems from 2017 to 2026.

Analyst 207
Modern office workstation with laptop and papers, terminal screen and server room in background.

Linux Flaw Enables Unprivileged Root Access on Major Distributions

A newly discovered Linux flaw, dubbed "Copy Fail," allows unprivileged users to gain root access on major distributions by exploiting a logic error in the kernel's cryptographic subsystem. This high-severity vulnerability, tracked as CVE-2026-31431, poses a significant threat to Linux systems, enabling attackers to write controlled bytes into the page cache of readable files and escalate privileges.

Analyst 207
Sharp-focus laptop screen on a modern desk with blurred background.

Google Fixes Critical Gemini CLI Flaw Enabling Remote Code Execution

Google patched a critical flaw in Gemini CLI that allowed hackers to inject malicious code and take control of host systems, thanks to a report from Novee Security. The vulnerability, scoring a perfect 10.0 on the CVSS scale, has been fixed in recent updates to the @google/gemini-cli and google-github-actions/run-gemini-cli packages.

Analyst 207
Rows of computer servers and networking equipment in a web hosting facility, with a single server terminal screen blank and…

cPanel Rushes Emergency Update to Fix Auth Bypass Bug

A critical security vulnerability in cPanel software has been discovered, allowing unauthorized access to the control panel, prompting immediate action from providers like Namecheap to protect customers. cPanel has since rushed out an emergency update to fix the authentication bypass bug affecting all currently supported versions.

Analyst 207
A typical office workstation with a blank laptop screen in the foreground.

Windows RPC Exposes New Local Privilege Escalation Technique

A newly discovered technique allows hackers to easily escalate their privileges to SYSTEM level on Windows systems, using a vulnerability in the Remote Procedure Call stack. This alarming exploit relies on clever manipulation of Security Quality of Service parameters and impersonation levels.

Analyst 207
Fragmented code scroll hovers and reassembles in mid-air amidst shattered code shards, set against a dark tech company HQ…

Google Fixes Antigravity Flaw That Enabled Code Execution

Google's Antigravity tool, designed to streamline coding, had a flaw that allowed hackers to run malicious code - but luckily, the tech giant has patched the vulnerability. This fix prevents cyber threats that could have exploited the tool's file-creation capabilities and lax input sanitization.

Analyst 207
A hovering laptop screen glows amidst scattered code and cables, surrounded by swirling particles, with shattered circuit…

Google's Antigravity AI Flaw Exposes Remote Code Risk

Google's top-of-the-line Antigravity AI safeguard can be surprisingly easily tricked into letting its guard down, leaving the door open for attackers to execute remote code. Even with its highest security setting, the AI agent manager's weaknesses can be exploited, putting users at risk.

Analyst 207
Dark scene with broken padlock, circuit boards, and laptop screen displaying malicious model file in shadows.

SGLang Flaw Enables Remote Code Execution via Malicious Model Files

A single malicious file can become a powerful gateway for attackers to run arbitrary commands on vulnerable machines - and a newly disclosed flaw in SGLang, CVE-2026-5760, reveals just how easily this can happen through specially crafted GGUF model files. This highly severe vulnerability, scoring 9.8 out of 10.0, enables remote code execution on systems that trust it.

Analyst 207
Dark abandoned factory with tangled wires, circuit boards, and broken machinery parts scattered around a small laptop.

MCP Flaw Exposes AI Supply Chain to Remote Code Execution Risk

A critical flaw in the Model Context Protocol could allow attackers to run malicious code across dependent machines, posing a remote code execution risk that ripples through the AI supply chain. This structural weakness, discovered by cybersecurity researchers, highlights a vulnerable link in the AI ecosystem.

Analyst 207
Lone figure in shadows holds cracked smartphone, near eerie glowing laptop, against ominous cityscape backdrop.

Protobuf library flaw enables remote JavaScript code execution

A critical flaw in the popular protobuf.js library has been exposed, allowing hackers to execute JavaScript code remotely - and a proof-of-concept exploit has already been published, putting countless systems at risk.

Analyst 207
A cracked padlock lies on a laptop keyboard with a faintly glowing screen, surrounded by a dimly lit room with scattered…

Microsoft Defender Zero-Day Exploit Grants SYSTEM Privileges

A security researcher, known as Chaotic Eclipse, has taken a bold stand against Microsoft's approach to working with cybersecurity experts by releasing a proof-of-concept exploit, dubbed RedSun, that grants SYSTEM privileges and exposes a zero-day vulnerability in Microsoft Defender. This dramatic move sparks renewed debate about disclosure, access, and the complex relationship between researchers and tech giants.

Analyst 207
Cracked lock with eerie glow, surrounded by dark gradient and ghostly cryptographic chain.

wolfSSL library vulnerability undermines ECDSA signature verification

A single misstep in a crucial cryptographic check can have far-reaching consequences, rendering digital certificates unreliable and putting security at risk. The recently discovered wolfSSL library vulnerability compromises ECDSA signature verification, allowing for potentially forged certificates and weakened security.

Analyst 207