Vulnerabilities

Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws

Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws 2026-08-11 at 19:50 By Ionut Arghire The security defects could be exploited for arbitrary code execution and denial-of-service. The post Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws Read More »

Zoom Patches Zero-Click Code Execution Vulnerability

Zoom Patches Zero-Click Code Execution Vulnerability 2026-08-11 at 18:49 By Ionut Arghire Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine. The post Zoom Patches Zero-Click Code Execution Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Zoom Patches Zero-Click Code Execution Vulnerability Read More »

SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities

SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities 2026-08-11 at 17:14 By Ionut Arghire SAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs. The post SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities Read More »

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC 2026-08-10 at 17:07 By Ionut Arghire Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition. The post Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC Read More »

CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability

CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability 2026-08-10 at 12:31 By Ionut Arghire The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands. The post CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability Read More »

Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

Critical Flaws Discovered in Belgian eID Software Used by 2 Million People 2026-08-10 at 07:44 By Eduard Kovacs The vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies. The post Critical Flaws Discovered in Belgian eID Software Used by 2 Million People appeared first on SecurityWeek. This article

Critical Flaws Discovered in Belgian eID Software Used by 2 Million People Read More »

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data 2026-08-08 at 14:30 By Eduard Kovacs The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data. The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek. This article is an

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data Read More »

Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect

Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect 2026-08-07 at 16:10 By King Orande and Cris Tomboc The LevelBlue OpsCTI Team recently identified a large-scale phishing campaign leveraging a new social engineering method to deploy unauthorized ConnectWise ScreenConnect clients. Rather than relying on conventional phishing pages, the campaign recreates convincing software

Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect Read More »

Microsoft, Apple Release Fresh Security Updates

Microsoft, Apple Release Fresh Security Updates 2026-08-07 at 12:09 By Ionut Arghire Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass. The post Microsoft, Apple Release Fresh Security Updates appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft, Apple Release Fresh Security Updates Read More »

Critical Vulnerabilities Patched With Chrome 151 Update

Critical Vulnerabilities Patched With Chrome 151 Update 2026-08-07 at 09:56 By Ionut Arghire The browser refresh eliminates over two dozen memory safety bugs, including critical use-after-free flaws. The post Critical Vulnerabilities Patched With Chrome 151 Update appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Vulnerabilities Patched With Chrome 151 Update Read More »

Critical Paperclip Flaw Allowed Admin Access, Code Execution

Critical Paperclip Flaw Allowed Admin Access, Code Execution 2026-08-06 at 14:09 By Ionut Arghire An attacker could self-register, sign in for board-level API access, and import a new company for code execution. The post Critical Paperclip Flaw Allowed Admin Access, Code Execution appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Critical Paperclip Flaw Allowed Admin Access, Code Execution Read More »

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones 

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones  2026-08-05 at 22:40 By Eduard Kovacs The chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications. The post How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones  Read More »

New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts

New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts 2026-08-05 at 15:48 By Eduard Kovacs Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation. The post New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts Read More »

CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities

CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities 2026-08-05 at 12:44 By Ionut Arghire The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass. The post CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities Read More »

TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover

TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover 2026-08-04 at 15:00 By Eduard Kovacs Forescout researchers have found 15 new vulnerabilities in the TP-Link Omada networking ecosystem. The post TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover Read More »

Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering 2026-08-04 at 13:54 By Ionut Arghire A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent. The post Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering appeared first on SecurityWeek. This

Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering Read More »

Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks 2026-08-04 at 12:56 By Ionut Arghire Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login. The post Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks Read More »

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers 2026-08-04 at 08:18 By Eduard Kovacs The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000. The post Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers appeared first on SecurityWeek. This article is an excerpt

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers Read More »

Scroll to Top