Topic: vulnerability patching
-
Apple’s Newest Bug Detective: AI
Apple's latest 26.5.2 software update patches a record number of vulnerabilities, many discovered using AI-assisted tools. The update fixes 87 security flaws in iOS and iPadOS 26.6, 155 in Macs, and roughly 100 each in watchOS, tvOS, and visionOS. The surge in fixes is driven by AI coding agents ...
Read More » -
Microsoft unveils AI security tools that beat rival platforms
Microsoft launched new AI-powered security tools, including the MAI-Cyber-1-Flash model, to automate risk detection and vulnerability remediation at scale, drawing on its experience from processing over 1 trillion security signals daily. The announcement comes shortly after OpenAI lost control of...
Read More » -
0-day researcher threatens 'bone shattering drop' after Microsoft calls police
A disgruntled security researcher known as Nightmare Eclipse has released six Windows zero-days, three of which are already being actively exploited, and has threatened a major disclosure event on July 14. Microsoft’s blog post condemned the uncoordinated disclosures and included a legal warning ...
Read More » -
Google discovers first AI-crafted zero-day exploit, thwarts attack pre-launch
Google's Threat Intelligence Group discovered what is believed to be the first zero-day exploit created by AI, designed for a mass attack but neutralized before deployment through collaboration with the software vendor. This event marks a significant escalation in the cybersecurity arms race, as ...
Read More » -
EU Ministers to Discuss Mythos AI as US Blocks Expansion
Euro-area finance ministers are meeting with banking supervisors to address the cybersecurity challenge posed by Anthropic’s Mythos AI model, which can autonomously exploit zero-day vulnerabilities but is not available to any EU government. The technology’s dual-use nature creates a stark asymmet...
Read More » -
Firestarter malware evades Cisco firewall updates and patches
U.S. and U.K. cybersecurity authorities warn of the custom-built Firestarter backdoor persisting on Cisco Firepower and Secure Firewall appliances, linked to threat actor UAT-4356, which exploited vulnerabilities CVE-2025-20333 and CVE-2025-20362 for initial access. The malware survives reboots, ...
Read More » -
Cisco FMC Flaw Exploited Before Patch (CVE-2026-20131)
The Interlock ransomware gang exploited a critical zero-day vulnerability (CVE-2026-20131) in Cisco's Secure Firewall Management Center for over a month before a patch was released, using it for arbitrary code execution and privilege escalation. Amazon's threat intelligence, using a honeypot, unc...
Read More » -
CISA Urges iOS Patch to Stop Crypto-Theft Exploits
U.S. authorities have issued an urgent alert for iPhone users to update their devices, as federal agencies are mandated to patch three actively exploited iOS vulnerabilities used for cryptocurrency theft and espionage. The sophisticated Coruna exploit kit leverages multiple iOS weaknesses to bypa...
Read More » -
Feds Probe Mysterious iOS Vulnerabilities Under Attack
Federal agencies are mandated to patch three critical, actively exploited iOS vulnerabilities, with CISA urging all organizations to apply updates immediately to protect against confirmed threats. The attacks utilized the sophisticated Coruna toolkit, which bundled 23 iOS exploits into effective ...
Read More » -
NCSC Warns of Severe Cyber-Attacks on Critical Infrastructure
The UK's National Cyber Security Centre (NCSC) has issued an urgent warning to critical national infrastructure providers, citing severe and disruptive cyber-attacks as a present danger, following incidents like those against energy networks in Poland. These sophisticated threats aim to cause hig...
Read More » -
Russian Hackers Exploit Patched Microsoft Office Flaw
A Russian state-sponsored hacking group is actively exploiting a patched Microsoft Office vulnerability (CVE-2026-21509) through phishing campaigns to install backdoors on targeted systems. The attacks use two methods: one deploys a malicious VBA project to steal emails, while the other uses a mu...
Read More » -
CISA Retires 10 Emergency Cyber Directives in Bulk Move
CISA has retired ten Emergency Directives, as their required security measures are now fully implemented or superseded by the broader Binding Operational Directive 22-01. BOD 22-01 mandates federal agencies to patch vulnerabilities from CISA's Known Exploited Vulnerabilities catalog, with deadlin...
Read More » -
Microsoft's December Updates Break Message Queuing
Microsoft's December 2025 security updates are causing Message Queuing (MSMQ) to fail, disrupting business applications and IIS websites on several Windows versions. The failure occurs because the updates changed permissions on a key system folder, requiring MSMQ users to have write access typica...
Read More » -
Barts Health Takes Legal Action After Oracle Data Breach
Barts Health NHS Trust is seeking a High Court injunction to prevent the use of data stolen by the Cl0p ransomware gang, which includes names and addresses from billing records. The breach exploited unpatched vulnerabilities in Oracle E-Business Suite software, part of a wider global campaign aff...
Read More » -
Pall Mall Process: Defining Responsible Cyber Intrusion
The Pall Mall Process, a joint UK-France initiative with 27 governments and major tech firms, aims to establish international standards for the commercial cyber intrusion industry to curb dangerous practices while acknowledging legitimate security needs. The process is currently consulting with i...
Read More » -
DoorDash Email Spoofing Sparks Heated Security Disclosure Feud
A security flaw in DoorDash's corporate platform allowed unauthorized users to send authentic-looking phishing emails from the company's official address, bypassing spam filters. The vulnerability was discovered by a researcher who demonstrated how to inject malicious HTML into emails, but DoorDa...
Read More » -
Logitech Data Breach Exposes User Information
Logitech experienced a data breach due to a zero-day vulnerability in third-party software, leading to unauthorized data copying, but the company promptly patched the issue after a fix was released. The stolen data includes information on employees, consumers, customers, and suppliers, but sensit...
Read More » -
GlobalLogic Hit by Cl0p Ransomware Following Oracle EBS Breach
GlobalLogic, a Hitachi-owned software firm, notified 10,471 current and former employees that their personal and financial data was stolen due to a breach in its Oracle E-Business Suite platform. The breach exploited a zero-day vulnerability in Oracle's system, leading to data exfiltration on Oct...
Read More » -
Urgent Samsung Patch Stops Spyware Exploit
Samsung has released a critical security update for a vulnerability (CVE-2025-21042) in its image processing library, which was actively exploited to install the LANDFALL spyware on mobile devices. The spyware uses a zero-click infection method via manipulated image files, allowing it to infect d...
Read More » -
New Gladinet Triofox Flaw Exploited by Attackers (CVE-2025-12480)
A critical security flaw (CVE-2025-12480) in Gladinet Triofox allows unauthenticated attackers to bypass access controls and gain administrative privileges, which has been exploited by the threat group UNC6485 since late August 2025. Attackers used an HTTP Host header attack to access the configu...
Read More »