Topic: software vulnerability

  • Microsoft emergency update patches macOS, Linux ASP.NET flaw

    Microsoft emergency update patches macOS, Linux ASP.NET flaw

    Microsoft has issued an urgent security update for a critical vulnerability (CVE-2026-40372) in its ASP.NET Core framework, allowing unauthenticated attackers to gain SYSTEM-level privileges on Linux and macOS systems. The flaw exists in specific versions of the Microsoft.AspNetCore.DataProtectio...

    Read More »
  • Urgent: Unpatched ScreenConnect Servers Vulnerable to Attack

    Urgent: Unpatched ScreenConnect Servers Vulnerable to Attack

    A critical vulnerability (CVE-2026-3564) in ScreenConnect allows attackers to hijack active sessions by exploiting weak cryptographic key handling in versions before 26.1. A successful attack could let unauthorized users remotely control the management instance, access employee computers, execute...

    Read More »
  • Critical FreeScout Flaw: Zero-Click RCE via Email (CVE-2026-28289)

    Critical FreeScout Flaw: Zero-Click RCE via Email (CVE-2026-28289)

    A critical vulnerability (CVE-2026-28289) in FreeScout help desk software allows remote attackers to execute code and take over servers by sending a malicious email, bypassing a previous patch. The flaw exploits a filename validation bypass using a Zero-Width Space character, enabling attackers t...

    Read More »
  • Critical n8n Vulnerabilities Exposed with Public Exploits

    Critical n8n Vulnerabilities Exposed with Public Exploits

    Critical vulnerabilities (CVE-2026-25049) in the n8n workflow platform allow users with workflow edit permissions to execute arbitrary code and fully compromise the host server, including stealing credentials. The flaws stem from incomplete AST-based sandboxing and a type-confusion vulnerability ...

    Read More »
  • Critical RCE Flaw in Trend Micro Apex Central: Patch Now

    Critical RCE Flaw in Trend Micro Apex Central: Patch Now

    A critical vulnerability (CVE-2025-69258) in Trend Micro's Apex Central console allows unauthenticated attackers to remotely execute malicious code with the highest SYSTEM privileges. The flaw, discovered by Tenable, is exploited by sending a crafted message to a specific port, forcing the system...

    Read More »
  • Abandoned Rust Library Flaw Sparks RCE Attack Risk

    Abandoned Rust Library Flaw Sparks RCE Attack Risk

    A critical security vulnerability (CVE-2025-62518) in the abandoned async-tar and tokio-tar Rust libraries allows remote code execution via desynchronization during TAR archive extraction, enabling attackers to insert malicious entries without authentication. The flaw, named TARmageddon, arises f...

    Read More »
  • Critical RCE Bug Threatens PTC Windchill and FlexPLM Users

    Critical RCE Bug Threatens PTC Windchill and FlexPLM Users

    A critical, unauthenticated remote code execution vulnerability (CVE-2024-xxxx) has been identified in PTC's Windchill and FlexPLM software, posing a severe security risk. Successful exploitation could allow attackers to steal intellectual property, tamper with critical product data, or deploy ra...

    Read More »
  • Fancy Bear Targets Ukraine, EU with Microsoft Office Flaw

    Fancy Bear Targets Ukraine, EU with Microsoft Office Flaw

    The Russian-linked cyber group Fancy Bear is exploiting a critical Microsoft Office vulnerability (CVE-2026-21509) to target Ukrainian and EU organizations, deploying malware via malicious documents. The campaign uses a sophisticated attack chain involving COM hijacking and the Covenant C2 framew...

    Read More »
  • Unpatched Fortra GoAnywhere Flaw Risks Full System Takeover

    Unpatched Fortra GoAnywhere Flaw Risks Full System Takeover

    A critical vulnerability (CVE-2025-10035) in Fortra's GoAnywhere MFT platform allows full system takeover via a deserialization flaw in the License servlet, requiring immediate patching. Exploitation necessitates access to the admin console, echoing a 2023 incident where exposed consoles led to w...

    Read More »
  • GiveWP Flaw Lets Hackers Run Server Commands

    GiveWP Flaw Lets Hackers Run Server Commands

    A critical zero-day vulnerability (CVE-2026-82222) in GiveWP allows unauthenticated attackers to execute arbitrary code by chaining three security flaws, including an insecure registration endpoint that bypasses standard WordPress restrictions. Exploitation involves creating an account to inject ...

    Read More »
  • Claude Mythos Finds Single Curl Flaw; Experts Split on Significance

    Claude Mythos Finds Single Curl Flaw; Experts Split on Significance

    Curl's lead developer Daniel Stenberg dismisses the Claude Mythos project's single-vulnerability finding as marketing hype rather than a meaningful security assessment. Industry observers argue the lone finding reflects Curl's robust security architecture, citing its long history of rigorous scru...

    Read More »
  • Notepad's Markdown Update Comes With a Critical RCE Flaw

    Notepad's Markdown Update Comes With a Critical RCE Flaw

    A high-severity vulnerability (CVE-2026-20841) in Microsoft Notepad's Markdown feature allows remote code execution if a user opens a malicious file and clicks an embedded link. Microsoft has patched the flaw, noting no current active exploits, but its impact is significant due to Notepad's ubiqu...

    Read More »
  • Russian Hackers Attack Using New Microsoft Office Bug

    Russian Hackers Attack Using New Microsoft Office Bug

    Russian state-backed hackers (APT28/Fancy Bear) are actively exploiting a patched Microsoft Office vulnerability (CVE-2026-21509) in targeted attacks against Ukrainian and EU entities, using phishing emails with malicious documents. The attack delivers sophisticated malware via a complex WebDAV c...

    Read More »
  • Ivanti warns of critical code execution flaw in Endpoint Manager

    Ivanti warns of critical code execution flaw in Endpoint Manager

    A critical vulnerability (CVE-2025-10573) in Ivanti's Endpoint Manager allows unauthenticated attackers to execute arbitrary code by tricking an administrator into viewing a compromised dashboard. Ivanti has released a patch, but the risk is heightened as hundreds of EPM instances are exposed onl...

    Read More »
  • Urgent: Active Attacks Target Unpatched Gladinet Flaw (CVE-2025-11371)

    Urgent: Active Attacks Target Unpatched Gladinet Flaw (CVE-2025-11371)

    A critical unauthenticated Local File Inclusion vulnerability (CVE-2025-11371) is actively being exploited, allowing attackers to remotely access any file on systems using Gladinet's CentreStack and Triofox platforms without credentials. Security researchers at Huntress confirmed real-world attac...

    Read More »
  • Microsoft GoAnywhere Bug Fuels Medusa Ransomware Attacks

    Microsoft GoAnywhere Bug Fuels Medusa Ransomware Attacks

    A critical vulnerability (CVE-2025-10035) in Fortra's GoAnywhere platform allows unauthenticated attackers to execute remote code, prompting urgent patching and removal of internet exposure. The flaw was exploited as a zero-day by Storm-1175, who used legitimate tools for reconnaissance and deplo...

    Read More »
  • Fortra GoAnywhere Zero-Day Exploited: Critical Flaw CVE-2025-10035

    Fortra GoAnywhere Zero-Day Exploited: Critical Flaw CVE-2025-10035

    A critical vulnerability (CVE-2025-10035) in Fortra's GoAnywhere platform, scoring 10.0 in severity, was exploited in zero-day attacks due to a deserialization flaw, with patches released on September 15, 2025. Evidence shows exploitation began as early as September 10, 2025, giving attackers an ...

    Read More »
  • Ransomware Attack Hits SmarterMail via Critical Flaw

    Ransomware Attack Hits SmarterMail via Critical Flaw

    A ransomware attack on SmarterTools began via an unpatched, employee-created virtual machine running outdated SmarterMail software, which allowed lateral movement into office and data center networks. The breach, attributed to the Warlock group exploiting a known vulnerability, led the company to...

    Read More »
  • Cisco confirms attackers exploiting Unified CM flaw

    Cisco confirms attackers exploiting Unified CM flaw

    Cisco confirmed active exploitation of CVE-2024-20253, a Unified Communications Manager flaw with publicly available proof-of-concept exploit code, for which a patch was released in early June. The vulnerability allows unauthenticated attackers to trigger a remote denial-of-service condition, pot...

    Read More »
  • Grafana Labs Breach Traced to TanStack Attack

    Grafana Labs Breach Traced to TanStack Attack

    Grafana Labs confirmed its security incident stemmed from the broader TanStack supply chain attack, where compromised dependencies from the library propagated malicious code to downstream users. The breach highlights the vulnerability of relying on open-source components, prompting Grafana Labs t...

    Read More »