Topic: security patch
-
Android 16 QPR2 Beta 3 Now Available for Pixel Devices
Google has released Android 16 QPR2 Beta 3 for Pixel devices, marking the final beta phase before the official December launch with significant improvements over monthly patches. This beta achieves Platform Stability, finalizing all app-facing behaviors and APIs to allow developers to conduct fin...
Read More » -
Patch Now: FortiWeb Pre-Auth RCE Exploits Released
A critical vulnerability (CVE-2025-25257, 9.8/10 severity) in Fortinet's FortiWeb WAF allows unauthenticated remote code execution via SQL injection, requiring immediate patching. Exploits leverage improper SQL sanitization in the Fabric Connector, enabling attackers to inject malicious commands ...
Read More » -
ShareFile Vulnerabilities Enable Pre-Auth RCE Attacks
A critical flaw in Progress ShareFile's Storage Zones Controller allows attackers to bypass authentication and execute remote code without credentials, enabling data theft. The vulnerability chain involves an authentication bypass (CVE-2026-2699) and a remote code execution flaw (CVE-2026-2701), ...
Read More » -
WordPress Plugin Flaw Gives Hackers Admin Access
A severe vulnerability (CVE-2026-23550) in the Modular DS WordPress plugin is being actively exploited, allowing attackers to gain full administrative control over websites with over 40,000 active installations. The flaw, present in versions 2.5.1 and older, stems from inadequate request verifica...
Read More » -
Windows Zero-Day "BlueHammer" Leaked by Researcher
A security researcher has publicly released exploit code for a new, unpatched privilege escalation vulnerability in Windows. The flaw allows attackers to gain the highest system-level permissions, turning a limited breach into a full system takeover. The disclosure before a Microsoft patch is ava...
Read More » -
Windows 11 Notepad Bug Executes Files Via Markdown Links
A high-severity vulnerability in Windows 11 Notepad allowed attackers to execute malicious code remotely by tricking users into clicking a malicious link within a Markdown file. The flaw exploited the app's Markdown preview feature, where specially crafted links using non-standard protocols could...
Read More » -
Critical WatchGuard Firebox Flaw Actively Exploited in Attacks
A critical, unauthenticated remote code execution vulnerability (CVE-2025-14733) in WatchGuard Firebox firewalls is being actively exploited, requiring urgent patching. The flaw impacts numerous Firebox models and specific Fireware OS versions, primarily affecting systems using IKEv2 VPN, with a ...
Read More » -
Harvard Probes Data Breach from Oracle Zero-Day Flaw
Harvard University is investigating a potential data breach after the Clop ransomware group listed it on its leak portal, likely due to a zero-day vulnerability in Oracle's E-Business Suite servers. The university confirmed the issue is widespread among Oracle clients, applied the security patch ...
Read More » -
AI-Powered Cursor IDE at Risk of Prompt Injection Attacks
A critical security flaw (CVE-2025-54135) in Cursor IDE, dubbed CurXecute, allows remote code execution via manipulated AI prompts, risking unauthorized system access. Attackers can exploit the Model Context Protocol (MCP) by injecting malicious prompts through third-party servers (e.g., Slack), ...
Read More » -
Researcher Publishes MiniPlasma Windows Exploit for 2020 Bug
A security researcher released the "MiniPlasma exploit", based on 2020 proof-of-concept code, targeting an unpatched Windows flaw from that year that can allow arbitrary code execution or privilege escalation. The exploit highlights the ongoing risk of "unpatched vulnerabilities", as Microsof...
Read More » -
DavMail 6.6.0 fixes security flaw, improves Microsoft Graph
DavMail gateway version 6.6.0 has been released to patch a significant security vulnerability related to a regex flaw and to update OAuth redirect handling for compatibility with Microsoft's protocols. The update also includes general code cleanup and refinements to Microsoft Graph integration, i...
Read More » -
Google Pixel 10a 'Stallion' Factory Images Now Available
Google has released factory images for the Pixel 10a, allowing users to restore the device to its original software state for troubleshooting. The company provided two software builds: the initial shipping version and a day-one update to Android 16 QPR3 with the March 2026 security patch. The Pix...
Read More » -
Android 16 QPR3 Beta 1.1 Patch Now Rolling Out
Google has released an incremental Android 16 beta update (CP11.251114.007) to fix a critical bug causing apps to crash on startup for enrolled Pixel users. The update, about 57.8 MB, does not include a new security patch and remains on the December 2025 security update. It is available for a wid...
Read More » -
Google's Final Android 16 Beta Is Here: Pixel Drop QPR2 Beta 3
The third and final beta of Android 16 QPR2 is now available for Pixel 6 series and newer models, including the Pixel 10, through the Android Beta program. Installing this beta locks users into the beta pathway, preventing a return to stable software without a full data wipe until the official QP...
Read More » -
Galaxy S25 One UI 8.5 Beta Expands to More Regions
Samsung has expanded the One UI 8.5 beta program for the Galaxy S25 series to India and Poland, following its initial launch in four other countries, to gather user feedback before a stable release. The large beta update includes the December 2025 security patch and focuses on improving stability...
Read More » -
Marimo RCE flaw exploited in active attacks
A critical vulnerability (CVE-2026-39987) in the Marimo Python notebook platform is being actively exploited, allowing unauthenticated attackers to execute remote code and steal credentials. The flaw, disclosed on April 8, is in an unsecured WebSocket endpoint; exploitation began within hours, wi...
Read More »