Topic: security vulnerability
-
7,000 DJI Robot Vacuums Hacked in Remote Camera Access
A user discovered a major security flaw in DJI's Romo robot vacuum, allowing unauthorized global access to live camera feeds and location data from thousands of devices. The vulnerability stemmed from a fundamental authentication failure in DJI's servers, granting a single user token administrati...
Read More » -
Critical VoIP Phone Bug Enables Stealthy Eavesdropping (CVE-2026-2329)
A critical security flaw (CVE-2026-2329) in Grandstream GXP1600 series VoIP phones allows unauthenticated attackers to gain full remote control via a buffer overflow in the web interface. Successful exploitation enables attackers to steal credentials and, most alarmingly, reconfigure the phone to...
Read More » -
Critical Windows Notepad Flaw (CVE-2026-20841) Enables RCE via Markdown
A critical vulnerability (CVE-2026-20841) in Windows Notepad, stemming from its new Markdown support, allowed remote code execution via malicious links in Markdown files. Exploitation required user interaction, such as clicking a crafted link, but was made easier as Markdown files are often perce...
Read More » -
Critical RCE Flaw Found in BeyondTrust Remote Support Software
A critical pre-authentication command injection flaw (CVE-2026-1731) in BeyondTrust's Remote Support and Privileged Remote Access software allows unauthenticated attackers to remotely execute arbitrary commands. The vulnerability, impacting thousands of on-premises instances, requires immediate m...
Read More » -
DockerDash Exposes Critical AI Supply Chain Flaw
A critical vulnerability named DockerDash in Docker's Ask Gordon AI assistant allows attackers to inject malicious commands via manipulated Docker image metadata, bypassing security due to a lack of validation. The flaw enables remote code execution in cloud/CLI environments and data exfiltration...
Read More » -
Microsoft patches critical Office zero-day under active attack
Microsoft has urgently patched a critical, actively exploited Office vulnerability (CVE-2026-21509) that bypasses security features, requiring immediate updates to prevent system compromise. The flaw allows attackers to bypass OLE mitigations by tricking users into opening a malicious file, with ...
Read More » -
Microsoft fixes critical Office zero-day under active attack
Microsoft has urgently patched a critical, actively exploited zero-day vulnerability (CVE-2026-21509) in Office, which allows attackers to bypass security features by tricking users into opening malicious files. While patches are available for Office 2021, LTSC 2021/2024, and Microsoft 365, secur...
Read More » -
Critical Vulnerability in All In One SEO Plugin Impacts 3M+ WordPress Sites
A critical vulnerability in the All in One SEO plugin exposed its global AI access token to any logged-in user with Contributor-level permissions, risking unauthorized AI usage and service credit depletion. The flaw, stemming from a missing permission check on an API endpoint, is part of a trend,...
Read More » -
Critical FortiSIEM Exploit Released: CVE-2025-64155 PoC
A critical vulnerability (CVE-2025-64155) in Fortinet's FortiSIEM platform now has public exploit code, allowing unauthenticated attackers to remotely execute arbitrary code with root privileges. Fortinet has released patches, and customers are urged to immediately upgrade to fixed versions; a te...
Read More » -
Google Fast Pair Devices Vulnerable to "WhisperPair" Hack
A critical flaw named **"WhisperPair"** in Google's Fast Pair protocol allows attackers to remotely hijack compatible audio devices from up to 14 meters away, potentially turning them into surveillance tools. The vulnerability affects a wide range of popular audio devices from multiple manufactur...
Read More » -
Critical FortiSIEM Flaw Patched: Remote Code Execution Risk
A critical, unauthenticated OS command injection vulnerability (CVE-2025-64155) in Fortinet's FortiSIEM platform allows remote attackers to execute arbitrary code and take full control of systems. The flaw, found in the phMonitor service, involves a two-stage attack: unauthenticated argument inje...
Read More » -
Critical "Ni8mare" Bug Allows Hackers to Take Over n8n Servers
A critical, maximum-severity vulnerability (CVSS 10.0) in n8n allows unauthenticated remote attackers to take control of servers, posing a major risk due to the platform's widespread use and integration with sensitive enterprise systems. The flaw, named "Ni8mare," is a path traversal issue where ...
Read More » -
Patch Now: Critical MongoDB RCE Flaw Demands Immediate Action
A critical, high-severity vulnerability (CVE-2025-14847) in MongoDB allows unauthenticated attackers to remotely execute code by exploiting a flaw in the zlib compression implementation. Administrators must immediately upgrade to specific patched versions (e.g., MongoDB 8.2.3) or, as a workaround...
Read More » -
Critical WatchGuard VPN Flaw Actively Exploited
A critical, actively exploited vulnerability (CVE-2025-14733) in WatchGuard's Fireware OS allows unauthenticated remote attackers to execute arbitrary code on affected systems. The flaw impacts systems using specific IKEv2 VPN configurations, and patches are available for most supported versions,...
Read More » -
Critical JumpCloud Windows Agent Flaw Allows Local Privilege Escalation
A critical security flaw (CVE-2025-34352) in JumpCloud's Remote Assist for Windows agent allows local users to escalate privileges to SYSTEM level or cause denial-of-service attacks by exploiting insecure file handling during uninstallation. The vulnerability stems from the agent's uninstaller pe...
Read More » -
Critical Server Vulnerability Sparks Urgent Admin Response
A critical, maximum-severity vulnerability in the widely used React Server package allows attackers to easily execute arbitrary code via a single HTTP request, with public exploit code now available. The flaw's danger is amplified because React is integrated by default into many popular framework...
Read More » -
Patch Now: CISA Warns of Active Oracle Identity Manager Attack
A critical vulnerability (CVE-2025-61757) in Oracle Identity Manager is being actively exploited, allowing unauthenticated attackers to execute arbitrary code via HTTP. CISA has urgently added this flaw to its Known Exploited Vulnerabilities catalog, advising immediate patching or isolation of af...
Read More » -
US Jury System Bug Exposed Sensitive Personal Data
A security flaw in Tyler Technologies' jury management websites exposed sensitive personal information of potential jurors across multiple U.S. and Canadian states, allowing unauthorized access through brute-force attacks due to sequential identifiers and lack of rate-limiting. Exposed data inclu...
Read More » -
Pentiment, Other Games Pulled From Steam Amid Unity Security Flaw
A security flaw in Unity game engine versions from 2017.1 onward has led to the temporary removal of several popular games from Steam, affecting multiple platforms but with no current evidence of exploitation. The vulnerability, reported responsibly by a researcher, could allow unsafe file loadin...
Read More » -
Unity Uncovers Major 2017 Security Flaw in Dev Tool
Unity has identified a significant security flaw in its development platform since 2017, allowing attackers to execute unauthorized code and steal data across Android, Windows, Linux, and macOS systems. The company has released comprehensive fixes for all affected Unity Editor versions and a bina...
Read More »