Vulnerabilities

PaperCut Exploitation Escalates to Active Intrusions

PaperCut Exploitation Escalates to Active Intrusions 2026-09-01 at 08:27 By Eduard Kovacs CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog. The post PaperCut Exploitation Escalates to Active Intrusions appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

PaperCut Exploitation Escalates to Active Intrusions Read More »

Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit

Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit 2026-08-31 at 17:32 By Eduard Kovacs Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product. The post Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit Read More »

ServiceNow Patches 3 Critical Code Injection Vulnerabilities

ServiceNow Patches 3 Critical Code Injection Vulnerabilities 2026-08-31 at 16:59 By Ionut Arghire Attackers could exploit the security defects to execute arbitrary code and access or tamper with data. The post ServiceNow Patches 3 Critical Code Injection Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

ServiceNow Patches 3 Critical Code Injection Vulnerabilities Read More »

Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs 2026-08-31 at 14:24 By Ionut Arghire Named KindaRails2Shell, the arbitrary file read flaw allows attackers to extract secrets and execute arbitrary code remotely. The post Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs Read More »

More Details Emerge on Exploited PaperCut Vulnerabilities

More Details Emerge on Exploited PaperCut Vulnerabilities 2026-08-31 at 09:51 By Eduard Kovacs PaperCut has released a second emergency patch for the exploited vulnerabilities, which are now tracked as CVE-2026-82078 and CVE-2026-81578. The post More Details Emerge on Exploited PaperCut Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

More Details Emerge on Exploited PaperCut Vulnerabilities Read More »

In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions

In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions 2026-08-28 at 18:35 By SecurityWeek News Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims. The post In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker

In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions Read More »

Still Circling: Inside the Operator Behind Blind Eagle’s GitHub Loader

Still Circling: Inside the Operator Behind Blind Eagle’s GitHub Loader 2026-08-28 at 17:00 By Serhii Melnyk This is a collaborative follow-up to our original post, developed jointly with Emmanuel C., an independent security researcher not affiliated with LevelBlue, who contributed additional infrastructure and tooling findings based on an analysis of the same GitHub staging account.

Still Circling: Inside the Operator Behind Blind Eagle’s GitHub Loader Read More »

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems 2026-08-28 at 15:36 By Eduard Kovacs CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents. The post OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems appeared first on SecurityWeek. This article is an

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems Read More »

PaperCut Releases Emergency Patch for Exploited Zero-Day

PaperCut Releases Emergency Patch for Exploited Zero-Day 2026-08-28 at 11:40 By Eduard Kovacs A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations. The post PaperCut Releases Emergency Patch for Exploited Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

PaperCut Releases Emergency Patch for Exploited Zero-Day Read More »

Recent Citrix NetScaler Vulnerability Exploited in the Wild

Recent Citrix NetScaler Vulnerability Exploited in the Wild 2026-08-27 at 07:39 By Eduard Kovacs CISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452. The post Recent Citrix NetScaler Vulnerability Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Recent Citrix NetScaler Vulnerability Exploited in the Wild Read More »

Adobe and Nvidia Patch Dozens of Vulnerabilities

Adobe and Nvidia Patch Dozens of Vulnerabilities 2026-08-26 at 15:39 By Eduard Kovacs Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products. The post Adobe and Nvidia Patch Dozens of Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Adobe and Nvidia Patch Dozens of Vulnerabilities Read More »

Chrome 152 Patches Over 300 Vulnerabilities

Chrome 152 Patches Over 300 Vulnerabilities 2026-08-26 at 12:50 By Eduard Kovacs Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities. The post Chrome 152 Patches Over 300 Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome 152 Patches Over 300 Vulnerabilities Read More »

CISA Warns of Exploited Gitea Vulnerability

CISA Warns of Exploited Gitea Vulnerability 2026-08-26 at 08:17 By Eduard Kovacs CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1. The post CISA Warns of Exploited Gitea Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Warns of Exploited Gitea Vulnerability Read More »

Energy Disruption in UK Critical Infrastructure and the Growing OT Cyber Threat

Energy Disruption in UK Critical Infrastructure and the Growing OT Cyber Threat 2026-08-25 at 18:27 By Nikita Kazymirskyi A cyber incident affecting a small UK electricity generator in July 2026 resulted in several days of operational unavailability and triggered a government and NCSC response. UK authorities confirmed that the event posed no threat to the

Energy Disruption in UK Critical Infrastructure and the Growing OT Cyber Threat Read More »

The Double Edge of AI in Healthcare: Guarding Data, Growing Empathy

The Double Edge of AI in Healthcare: Guarding Data, Growing Empathy 2026-08-25 at 17:00 By Bindu Sundaresan Healthcare has always run on two currencies: information and trust. Patients hand over their most sensitive data, diagnoses, genetic profiles, mental health histories, on the assumption that it will be protected and that the people (or systems) handling it

The Double Edge of AI in Healthcare: Guarding Data, Growing Empathy Read More »

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities 2026-08-25 at 16:33 By Eduard Kovacs CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Read More »

Silent Patches Don’t Stop Attackers—They Blind Defenders

Silent Patches Don’t Stop Attackers—They Blind Defenders 2026-08-25 at 13:00 By Tod Beardsley Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. The post Silent Patches Don’t Stop Attackers—They Blind Defenders appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Silent Patches Don’t Stop Attackers—They Blind Defenders Read More »

CISA Warns of Exploited Oracle WebLogic Vulnerability

CISA Warns of Exploited Oracle WebLogic Vulnerability 2026-08-25 at 10:46 By Eduard Kovacs The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers. The post CISA Warns of Exploited Oracle WebLogic Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Warns of Exploited Oracle WebLogic Vulnerability Read More »

91 Vulnerabilities Patched in Spring Application Framework

91 Vulnerabilities Patched in Spring Application Framework 2026-08-24 at 14:58 By Eduard Kovacs More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024.  The post 91 Vulnerabilities Patched in Spring Application Framework appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

91 Vulnerabilities Patched in Spring Application Framework Read More »

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug 2026-08-21 at 18:11 By SecurityWeek News Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. The post In Other News: Zombie Card Attack, T-Mobile Cut Cable

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug Read More »

Scroll to Top