Topic: software vulnerabilities

  • SolarWinds Serv-U Exposes Critical RCE Vulnerabilities

    SolarWinds Serv-U Exposes Critical RCE Vulnerabilities

    SolarWinds has released critical patches for its Serv-U file transfer software to address four severe vulnerabilities that could allow attackers to gain full system control, requiring immediate updates. The vulnerabilities, which include broken access control and type confusion bugs, enable remot...

    Read More »
  • Urgent SolarWinds Web Help Desk Patch Fixes Critical RCE Flaws

    Urgent SolarWinds Web Help Desk Patch Fixes Critical RCE Flaws

    SolarWinds has urgently patched multiple critical vulnerabilities in its Web Help Desk software, strongly advising all customers to immediately upgrade to version 2026.1 to mitigate risks like remote code execution. The critical flaws, discovered by external researchers, include authentication by...

    Read More »
  • Trend Micro Apex Central RCE PoC Released (CVE-2025-69258)

    Trend Micro Apex Central RCE PoC Released (CVE-2025-69258)

    Trend Micro has issued a critical security update for its Apex Central on-premise platform, addressing multiple vulnerabilities, including a severe one (CVE-2025-69258) that allows unauthenticated attackers to execute code with SYSTEM privileges. The vulnerabilities, discovered by Tenable, involv...

    Read More »
  • Don't Wait on NVD: Get Real-Time Vulnerability Alerts Instantly

    Don't Wait on NVD: Get Real-Time Vulnerability Alerts Instantly

    Vulnerability management is essential for cybersecurity, but many organizations struggle to keep up with emerging threats due to the high volume of software components and actively exploited vulnerabilities. SecAlerts offers a modern solution by providing real-time, customized vulnerability alert...

    Read More »
  • Microsoft Criticizes "Uncoordinated" Zero-Day Disclosures

    Microsoft Criticizes "Uncoordinated" Zero-Day Disclosures

    Microsoft criticized the practice of revealing zero-day vulnerabilities without prior coordination, warning it places customers in harm's way by creating unnecessary risk. The company stated that premature disclosures leave systems exposed to attacks, as malicious actors can exploit weaknesses be...

    Read More »
  • Progress Software patches stealthy WAF bypass flaw (CVE-2026-21876)

    Progress Software patches stealthy WAF bypass flaw (CVE-2026-21876)

    Progress Software patched five high-severity vulnerabilities in MOVEit WAF and LoadMaster, including CVE-2026-21876, a critical bypass flaw allowing unauthenticated attackers to circumvent WAF protections via crafted HTTP requests. CVE-2026-21876 affects the OWASP core rule set, was reported in J...

    Read More »
  • Anthropic AI Tool Finds and Fixes Critical Software Bugs

    Anthropic AI Tool Finds and Fixes Critical Software Bugs

    Anthropic has launched "Project Glasswing", an AI system using the "Claude Mythos Preview model" to autonomously scan for and repair previously unknown critical software vulnerabilities. The system is designed to understand code context, diagnose root causes, and generate functional patches, ...

    Read More »
  • Trend Micro Apex One Flaws: Critical Code Execution Risk

    Trend Micro Apex One Flaws: Critical Code Execution Risk

    Trend Micro has patched two critical remote code execution vulnerabilities (CVE-2025-71210 & CVE-2025-71211) in its Apex One endpoint protection platform, urging immediate updates. The flaws are path traversal issues in the management console, where exploitation requires prior access, and the com...

    Read More »
  • AI Converts C to Rust for Enhanced Software Safety

    AI Converts C to Rust for Enhanced Software Safety

    A new initiative called the Great Refactor proposes using AI to automatically convert vulnerable C/C++ code into the memory-safe language Rust, aiming to eliminate entire categories of software bugs at their source. Rust is uniquely positioned for this task as it offers both high performance and ...

    Read More »
  • Cisco IMC patch, Patch Tuesday outlook, Black Hat 2026 recap

    Cisco IMC patch, Patch Tuesday outlook, Black Hat 2026 recap

    AI-powered security tools are advancing: Stairwell's Backstory maps full malware campaigns from single alerts (finding ~2.4 undocumented variants per published sample), while Stellar Cyber's Agentic Auto Triage autonomously closes false-positive tickets, saving analysts 19 minutes per hour. New v...

    Read More »
  • ATM Flaws Expose Software Supply Chain Weaknesses

    ATM Flaws Expose Software Supply Chain Weaknesses

    Researcher Matt Burch identified nine critical vulnerabilities in CryptoPro Secure Disk, a widely used encryption tool that exposes ATM manufacturers and other industries to significant security risks. These flaws allowed attackers to bypass integrity checks and gain unrestricted access to encryp...

    Read More »
  • CISA: Hackers Exploiting Langflow, N-central, Tomcat Flaws

    CISA: Hackers Exploiting Langflow, N-central, Tomcat Flaws

    CISA has mandated that federal agencies patch three actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat within 72 hours, with private sector entities strongly encouraged to remediate as well. The Langflow flaw (CVE-2025-3248) enables unauthenticated remote code execut...

    Read More »
  • Palo Alto Warns of Active Exploit for High-Severity Bug

    Palo Alto Warns of Active Exploit for High-Severity Bug

    A critical high-severity vulnerability in Palo Alto Networks' PAN-OS software is being actively exploited, allowing attackers to execute arbitrary code or disrupt system operations. Palo Alto Networks urges all customers to immediately update to patched versions of PAN-OS to mitigate threats, as ...

    Read More »
  • Storm-1175 Uses Medusa Attack Flaws

    Storm-1175 Uses Medusa Attack Flaws

    A financially motivated group, Storm-1175, has conducted relentless Medusa ransomware attacks for three years by exploiting newly disclosed and previously unknown vulnerabilities, heavily impacting healthcare, education, and finance sectors across multiple countries. The group's consistent tactic...

    Read More »
  • Hackers Exploit Flaws, Use Elastic Cloud to Manage Stolen Data

    Hackers Exploit Flaws, Use Elastic Cloud to Manage Stolen Data

    Attackers exploited software vulnerabilities to steal system data and used a legitimate Elastic Cloud SIEM trial account as a central hub to manage and analyze the stolen information, blending malicious activity with normal traffic. The campaign impacted at least 216 hosts across various sectors,...

    Read More »
  • Noisy Ransomware Uncovered a Long-Term Espionage Operation

    Noisy Ransomware Uncovered a Long-Term Espionage Operation

    A ransomware group's disruptive attack on two Russian companies inadvertently exposed a long-running, sophisticated cyber espionage operation, highlighting how a visible breach can mask a more insidious threat. The espionage group, QuietCrabs, used a stealthy multi-stage attack with unique malwar...

    Read More »
  • Mythos Preview weaponizes N-day vulnerabilities in hours

    Mythos Preview weaponizes N-day vulnerabilities in hours

    Anthropic's Mythos Preview system can weaponize N-day vulnerabilities in hours, compressing what previously took days or weeks and shifting focus from zero-day to already-patched flaws. The system automates exploit development from public vulnerability disclosures, reducing the window between dis...

    Read More »
  • UK NCSC Chief Calls for Secure Vibe Coding at RSAC

    UK NCSC Chief Calls for Secure Vibe Coding at RSAC

    The UK's NCSC argues that AI-assisted software development ("vibe coding") must be paired with rapid safeguards to improve security, or it risks amplifying vulnerabilities instead of reducing them. Security teams must immediately embed core principles like "secure by default" coding into AI model...

    Read More »
  • F5 Hack Puts Thousands of Networks at Imminent Risk

    F5 Hack Puts Thousands of Networks at Imminent Risk

    A sophisticated nation-state hacking group breached F5's network, exposing proprietary source code and undisclosed vulnerability data, endangering thousands of government and corporate networks that rely on BIG-IP appliances. The attackers maintained persistent access for years, gaining control o...

    Read More »
  • Infostealer Hits Enterprise Devices via FortiClient EMS Flaw

    Infostealer Hits Enterprise Devices via FortiClient EMS Flaw

    Attackers are exploiting a known vulnerability in FortiClient Enterprise Management Server (CVE-2026-35616) to deliver an infostealer disguised as a legitimate Fortinet endpoint update, targeting enterprise environments. The malware silently harvests credentials, browser data, and cryptocurrency ...

    Read More »