Topic: security patch

  • JetBrains patches critical unauthenticated RCE flaw in TeamCity

    JetBrains patches critical unauthenticated RCE flaw in TeamCity

    JetBrains released a security update for CVE-2026-63077, a critical unauthenticated remote code execution vulnerability in TeamCity On-Premises, and urges administrators to upgrade immediately or install a security patch plugin. The flaw in the TeamCity agent polling protocol allows attackers to ...

    Read More »
  • BeyondTrust Patches Critical Pre-Auth RCE Flaw in Remote Access Tools

    BeyondTrust Patches Critical Pre-Auth RCE Flaw in Remote Access Tools

    A critical security flaw (CVE-2026-1731) in BeyondTrust's self-hosted remote access software allows unauthenticated attackers to execute arbitrary OS commands, posing a severe risk of complete system compromise. The vulnerability impacts specific versions of Remote Support and Privileged Remote A...

    Read More »
  • Trend Micro Apex Central RCE PoC Released (CVE-2025-69258)

    Trend Micro Apex Central RCE PoC Released (CVE-2025-69258)

    Trend Micro has issued a critical security update for its Apex Central on-premise platform, addressing multiple vulnerabilities, including a severe one (CVE-2025-69258) that allows unauthenticated attackers to execute code with SYSTEM privileges. The vulnerabilities, discovered by Tenable, involv...

    Read More »
  • Galaxy S23 Security Update: Enhanced Protection Now Available

    Galaxy S23 Security Update: Enhanced Protection Now Available

    Samsung has released the December 2025 security patch for the Galaxy S23 series, following updates for newer models, with the rollout beginning in South Korea. The update, version S918NKSS6EYL1, fixes 57 security vulnerabilities to protect user data and device integrity. Owners can manually check...

    Read More »
  • Google's December Update Fixes 33 Bugs, Boosts Pixel Security

    Google's December Update Fixes 33 Bugs, Boosts Pixel Security

    Google has released a December security patch for Pixel 6 and later models, addressing 33 bugs and patching critical vulnerabilities to enhance device stability and security. The update fixes specific user-reported issues, including a battery icon glitch, ensures the 80% charge limit works correc...

    Read More »
  • New Microsoft SharePoint exploit used in active hacker attacks

    New Microsoft SharePoint exploit used in active hacker attacks

    CVE-2026-55040, a critical JWT authentication bypass in Microsoft SharePoint, is being actively exploited in the wild within a day of Rapid7 publishing a proof-of-concept exploit, allowing unauthenticated attackers to impersonate users or admins. Microsoft patched the flaw in its July 2026 Patch ...

    Read More »
  • Check Point ties VPN zero-day exploits to Qilin ransomware group

    Check Point ties VPN zero-day exploits to Qilin ransomware group

    Check Point patched a critical zero-day vulnerability (CVE-2026-50751) in its Remote Access VPN and Mobile Access products that allows unauthenticated attackers to bypass authentication, specifically impacting deployments using the deprecated IKEv1 protocol. The exploitation campaign, which began...

    Read More »
  • 4th Linux Kernel Bug This Month Exposes SSH Host Keys

    4th Linux Kernel Bug This Month Exposes SSH Host Keys

    A new Linux kernel vulnerability called "ssh-keysign-pwn" (CVE-2026-46333) allows unprivileged users to read sensitive files like SSH host private keys and the shadow password file by exploiting a flaw in the ptrace access check during process exit. A patch has been released by Linus Torvalds and...

    Read More »
  • Urgent: Unpatched ScreenConnect Servers Vulnerable to Attack

    Urgent: Unpatched ScreenConnect Servers Vulnerable to Attack

    A critical vulnerability (CVE-2026-3564) in ScreenConnect allows attackers to hijack active sessions by exploiting weak cryptographic key handling in versions before 26.1. A successful attack could let unauthorized users remotely control the management instance, access employee computers, execute...

    Read More »
  • Galaxy S25 Series Receives Major New Software Update

    Galaxy S25 Series Receives Major New Software Update

    Samsung is rolling out a security-focused update for the Galaxy S25 series, not the anticipated One UI 8.5, starting in South Korea. The update, over 500MB, delivers the March 2026 Android security patch to fix 65 vulnerabilities and protect user data. While lacking new features, this release hig...

    Read More »
  • Android's February 2026 Security Update: What's Inside?

    Android's February 2026 Security Update: What's Inside?

    The February 2026 Android 16 security update is exceptionally light, containing no major vulnerabilities and only one high-severity patch for Pixel devices. The minimal update indicates platform stability, with attention now turning to the upcoming Android 16 QPR3 release expected to focus on per...

    Read More »
  • October 2025 Pixel Update: Full Verizon Patch Notes

    October 2025 Pixel Update: Full Verizon Patch Notes

    Verizon has released patch notes for the October 2025 Pixel update ahead of Google's official distribution, with the carrier's documentation showing a scheduled release date but no files yet available. The update includes interface improvements for Pixel 7-10 devices, such as fixing a camera laun...

    Read More »
  • Apple fixes eavesdropping bug in Beats Studio Buds

    Apple fixes eavesdropping bug in Beats Studio Buds

    Apple released Beats Firmware Update 1B211 to fix CVE-2025-20701, a high-severity flaw that allowed nearby attackers to secretly listen through the earbuds' microphone by impersonating paired devices. The vulnerability, rated 8.8/10 severity, was discovered by security researchers from Insinuator...

    Read More »
  • Critical NetScaler Flaw Poses Imminent Exploit Risk (CVE-2026-3055)

    Critical NetScaler Flaw Poses Imminent Exploit Risk (CVE-2026-3055)

    Organizations must urgently patch Citrix NetScaler ADC and Gateway due to two new vulnerabilities, with the critical CVE-2026-3055 allowing attackers to steal user session tokens from systems configured as a SAML Identity Provider. The secondary vulnerability, CVE-2026-4368, is a race condition t...

    Read More »
  • Windows 11 Update Warning: Patch Tuesday Boot Failures

    Windows 11 Update Warning: Patch Tuesday Boot Failures

    Microsoft has confirmed its January 2026 security update for Windows 11 is causing severe boot failures, preventing some PCs from starting entirely. The issue primarily affects physical machines running Windows 11 versions 24H2 and 25H2, requiring users to manually uninstall the update to recover...

    Read More »
  • Microsoft Races to Fix ‘RoguePlanet’ Zero-Day Flaw

    Microsoft Races to Fix ‘RoguePlanet’ Zero-Day Flaw

    Microsoft is developing a fix for a zero-day vulnerability called 'RoguePlanet' in its Defender antivirus, which uses a race condition to let attackers gain full System-level privileges. The public exploit requires no user interaction and allows complete system control, enabling malware installat...

    Read More »
  • Cisco Patches Actively Exploited SD-WAN vManage Zero-Day Flaw

    Cisco Patches Actively Exploited SD-WAN vManage Zero-Day Flaw

    Cisco released emergency patches for a critical zero-day vulnerability (CVE-2026-20262) in Catalyst SD-WAN Manager, which is actively exploited in the wild to allow attackers with low-level privileges to escalate to root access. The flaw stems from insufficient input validation during file upload...

    Read More »
  • IBM API Connect flaw exposes critical authentication bypass risk

    IBM API Connect flaw exposes critical authentication bypass risk

    A critical vulnerability (CVE-2025-13915) in IBM API Connect allows attackers to bypass authentication and gain unauthorized remote access, posing a high risk to sectors like finance and healthcare. IBM urges immediate patching to specific affected versions and advises disabling the Developer Por...

    Read More »
  • Cisco confirms attackers exploiting Unified CM flaw

    Cisco confirms attackers exploiting Unified CM flaw

    Cisco confirmed active exploitation of CVE-2024-20253, a Unified Communications Manager flaw with publicly available proof-of-concept exploit code, for which a patch was released in early June. The vulnerability allows unauthenticated attackers to trigger a remote denial-of-service condition, pot...

    Read More »
  • Google releases final Android 17 Beta 4.1 for Pixel

    Google releases final Android 17 Beta 4.1 for Pixel

    Google has released Android 17 Beta 4.1 for Pixel devices as a minor bug-fix update with the May 2026 security patch, polishing the experience before the final stable launch. Beta 4 was confirmed as the last scheduled beta of the release cycle, but Beta 4.1 addresses several known issues without ...

    Read More »