Topic: software vulnerability

  • GiveWP Flaw Lets Hackers Run Server Commands

    GiveWP Flaw Lets Hackers Run Server Commands

    A critical zero-day vulnerability (CVE-2026-82222) in GiveWP allows unauthenticated attackers to execute arbitrary code by chaining three security flaws, including an insecure registration endpoint that bypasses standard WordPress restrictions. Exploitation involves creating an account to inject ...

    Read More »
  • NVIDIA’s open-source scanner secures AI agent skills

    NVIDIA’s open-source scanner secures AI agent skills

    NVIDIA released SkillSpector, an open-source security scanner that analyzes AI agent skills' source code and metadata to provide a risk score, findings list, and recommendations, supporting local directories, zip files, SKILL.md files, or Git URLs. The scanner flags suspicious patterns like hidde...

    Read More »
  • Hackers exploit critical Gitea Docker auth bypass

    Hackers exploit critical Gitea Docker auth bypass

    Hackers are actively exploiting a critical authentication bypass vulnerability (CVE-2023-XXXXX) in the official Docker image for Gitea, allowing attackers to impersonate any user, including administrators, and gain full control over repositories and sensitive data. Active exploitation attempts ta...

    Read More »
  • Cisco confirms attackers exploiting Unified CM flaw

    Cisco confirms attackers exploiting Unified CM flaw

    Cisco confirmed active exploitation of CVE-2024-20253, a Unified Communications Manager flaw with publicly available proof-of-concept exploit code, for which a patch was released in early June. The vulnerability allows unauthenticated attackers to trigger a remote denial-of-service condition, pot...

    Read More »
  • Grafana Labs Breach Traced to TanStack Attack

    Grafana Labs Breach Traced to TanStack Attack

    Grafana Labs confirmed its security incident stemmed from the broader TanStack supply chain attack, where compromised dependencies from the library propagated malicious code to downstream users. The breach highlights the vulnerability of relying on open-source components, prompting Grafana Labs t...

    Read More »
  • Claude Mythos Finds Single Curl Flaw; Experts Split on Significance

    Claude Mythos Finds Single Curl Flaw; Experts Split on Significance

    Curl's lead developer Daniel Stenberg dismisses the Claude Mythos project's single-vulnerability finding as marketing hype rather than a meaningful security assessment. Industry observers argue the lone finding reflects Curl's robust security architecture, citing its long history of rigorous scru...

    Read More »
  • Microsoft emergency update patches macOS, Linux ASP.NET flaw

    Microsoft emergency update patches macOS, Linux ASP.NET flaw

    Microsoft has issued an urgent security update for a critical vulnerability (CVE-2026-40372) in its ASP.NET Core framework, allowing unauthenticated attackers to gain SYSTEM-level privileges on Linux and macOS systems. The flaw exists in specific versions of the Microsoft.AspNetCore.DataProtectio...

    Read More »
  • Microsoft Defender RedSun Zero-Day Exploit Gains SYSTEM Access

    Microsoft Defender RedSun Zero-Day Exploit Gains SYSTEM Access

    A researcher named "Chaotic Eclipse" has released a second exploit, called RedSun, targeting Microsoft Defender to gain SYSTEM-level access on Windows, protesting Microsoft's security community engagement policies. The exploit works by corrupting a core Defender component, allowing an attacker to...

    Read More »
  • Critical RCE Bug Threatens PTC Windchill and FlexPLM Users

    Critical RCE Bug Threatens PTC Windchill and FlexPLM Users

    A critical, unauthenticated remote code execution vulnerability (CVE-2024-xxxx) has been identified in PTC's Windchill and FlexPLM software, posing a severe security risk. Successful exploitation could allow attackers to steal intellectual property, tamper with critical product data, or deploy ra...

    Read More »
  • Urgent: Unpatched ScreenConnect Servers Vulnerable to Attack

    Urgent: Unpatched ScreenConnect Servers Vulnerable to Attack

    A critical vulnerability (CVE-2026-3564) in ScreenConnect allows attackers to hijack active sessions by exploiting weak cryptographic key handling in versions before 26.1. A successful attack could let unauthorized users remotely control the management instance, access employee computers, execute...

    Read More »
  • Critical FreeScout Flaw: Zero-Click RCE via Email (CVE-2026-28289)

    Critical FreeScout Flaw: Zero-Click RCE via Email (CVE-2026-28289)

    A critical vulnerability (CVE-2026-28289) in FreeScout help desk software allows remote attackers to execute code and take over servers by sending a malicious email, bypassing a previous patch. The flaw exploits a filename validation bypass using a Zero-Width Space character, enabling attackers t...

    Read More »
  • Notepad's Markdown Update Comes With a Critical RCE Flaw

    Notepad's Markdown Update Comes With a Critical RCE Flaw

    A high-severity vulnerability (CVE-2026-20841) in Microsoft Notepad's Markdown feature allows remote code execution if a user opens a malicious file and clicks an embedded link. Microsoft has patched the flaw, noting no current active exploits, but its impact is significant due to Notepad's ubiqu...

    Read More »
  • SmarterTools Breached by Hackers Exploiting Own Software Flaw

    SmarterTools Breached by Hackers Exploiting Own Software Flaw

    The Warlock ransomware gang breached SmarterTools by exploiting an unpatched SmarterMail server, demonstrating how a single overlooked system can compromise an entire network. Attackers used a specific authentication bypass vulnerability to gain access, moved laterally with Windows tools, but wer...

    Read More »
  • Ransomware Attack Hits SmarterMail via Critical Flaw

    Ransomware Attack Hits SmarterMail via Critical Flaw

    A ransomware attack on SmarterTools began via an unpatched, employee-created virtual machine running outdated SmarterMail software, which allowed lateral movement into office and data center networks. The breach, attributed to the Warlock group exploiting a known vulnerability, led the company to...

    Read More »
  • Critical n8n Vulnerabilities Exposed with Public Exploits

    Critical n8n Vulnerabilities Exposed with Public Exploits

    Critical vulnerabilities (CVE-2026-25049) in the n8n workflow platform allow users with workflow edit permissions to execute arbitrary code and fully compromise the host server, including stealing credentials. The flaws stem from incomplete AST-based sandboxing and a type-confusion vulnerability ...

    Read More »
  • Russian Hackers Attack Using New Microsoft Office Bug

    Russian Hackers Attack Using New Microsoft Office Bug

    Russian state-backed hackers (APT28/Fancy Bear) are actively exploiting a patched Microsoft Office vulnerability (CVE-2026-21509) in targeted attacks against Ukrainian and EU entities, using phishing emails with malicious documents. The attack delivers sophisticated malware via a complex WebDAV c...

    Read More »
  • Fancy Bear Targets Ukraine, EU with Microsoft Office Flaw

    Fancy Bear Targets Ukraine, EU with Microsoft Office Flaw

    The Russian-linked cyber group Fancy Bear is exploiting a critical Microsoft Office vulnerability (CVE-2026-21509) to target Ukrainian and EU organizations, deploying malware via malicious documents. The campaign uses a sophisticated attack chain involving COM hijacking and the Covenant C2 framew...

    Read More »
  • Critical RCE Flaw in Trend Micro Apex Central: Patch Now

    Critical RCE Flaw in Trend Micro Apex Central: Patch Now

    A critical vulnerability (CVE-2025-69258) in Trend Micro's Apex Central console allows unauthenticated attackers to remotely execute malicious code with the highest SYSTEM privileges. The flaw, discovered by Tenable, is exploited by sending a crafted message to a specific port, forcing the system...

    Read More »
  • Ivanti warns of critical code execution flaw in Endpoint Manager

    Ivanti warns of critical code execution flaw in Endpoint Manager

    A critical vulnerability (CVE-2025-10573) in Ivanti's Endpoint Manager allows unauthenticated attackers to execute arbitrary code by tricking an administrator into viewing a compromised dashboard. Ivanti has released a patch, but the risk is heightened as hundreds of EPM instances are exposed onl...

    Read More »
  • Abandoned Rust Library Flaw Sparks RCE Attack Risk

    Abandoned Rust Library Flaw Sparks RCE Attack Risk

    A critical security vulnerability (CVE-2025-62518) in the abandoned async-tar and tokio-tar Rust libraries allows remote code execution via desynchronization during TAR archive extraction, enabling attackers to insert malicious entries without authentication. The flaw, named TARmageddon, arises f...

    Read More »