Vulnerabilities

Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection

Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection 2026-07-08 at 13:30 By Ionut Arghire Researchers show how attackers can use a crafted public GitHub Issue to trick AI-powered workflows into exposing data from private repositories without authentication. The post Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection appeared first on SecurityWeek. This article […]

Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection Read More »

Critical Gitea Flaw Under Active Exploitation, Researchers Warn

Critical Gitea Flaw Under Active Exploitation, Researchers Warn 2026-07-07 at 20:17 By Ionut Arghire Attackers are exploiting the critical Gitea vulnerability CVE-2026-20896 to bypass authentication with a single HTTP header and access vulnerable repositories and secrets. The post Critical Gitea Flaw Under Active Exploitation, Researchers Warn appeared first on SecurityWeek. This article is an excerpt […]

Critical Gitea Flaw Under Active Exploitation, Researchers Warn Read More »

Critical Adobe ColdFusion Vulnerability Exploited in Attacks

Critical Adobe ColdFusion Vulnerability Exploited in Attacks 2026-07-07 at 15:38 By Ionut Arghire Hackers are exploiting a recently patched critical vulnerability (CVE-2026-48282) in Adobe ColdFusion that carries a CVSS score of 10/10. The post Critical Adobe ColdFusion Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Adobe ColdFusion Vulnerability Exploited in Attacks Read More »

Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems

Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems 2026-07-07 at 13:00 By Ionut Arghire The 16-year-old Januscape flaw affects Linux’s KVM hypervisor, allowing attackers to escape virtual machines and potentially execute code on the underlying host. The post Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems appeared first on […]

Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems Read More »

Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability

Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability 2026-07-06 at 15:48 By Ionut Arghire Organizations are urged to patch after proof-of-concept code makes the Linux root escalation flaw easier to exploit. The post Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability appeared first on SecurityWeek. This article is an excerpt from […]

Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability Read More »

Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution

Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution 2026-07-03 at 10:57 By Ionut Arghire The DuneSlide vulnerabilities enable zero-click prompt injection attacks that escape Cursor’s sandbox and execute arbitrary code on the underlying operating system. The post Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution […]

Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution Read More »

New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure

New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure 2026-07-02 at 18:04 By Ionut Arghire Hackers are targeting NetScaler appliances using public PoC code to retrieve arbitrary memory content in the HTTP response. The post New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure Read More »

Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability

Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability 2026-07-02 at 13:48 By Ionut Arghire A PoC exploit has been available since public disclosure, and the first exploitation attempts were observed last week. The post Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability Read More »

Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities

Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities 2026-07-01 at 14:27 By Ionut Arghire Seven of the security defects have a maximum severity rating of 10/10 and could lead to arbitrary code execution. The post Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities Read More »

Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack

Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack 2026-07-01 at 14:20 By Ionut Arghire Citrix urges customers to patch NetScaler after fixing six vulnerabilities, including the HTTP/2 Bomb flaw and a high-severity CitrixBleed-style information disclosure bug. The post Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack appeared first on SecurityWeek. This article is […]

Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack Read More »

Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari

Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari 2026-07-01 at 12:30 By Ionut Arghire The updates fix vulnerabilities in WebKit, the kernel, WebRTC, Web Extensions, and other components affecting iPhone, iPad, Mac, and Safari users. The post Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari appeared first on SecurityWeek. This article […]

Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari Read More »

BlueHammer Vulnerability Exploited in Ransomware Attacks

BlueHammer Vulnerability Exploited in Ransomware Attacks 2026-06-30 at 16:56 By Eduard Kovacs The Microsoft Defender vulnerability CVE-2026-33825 was exploited in the wild as a zero-day before patches were released. The post BlueHammer Vulnerability Exploited in Ransomware Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

BlueHammer Vulnerability Exploited in Ransomware Attacks Read More »

Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks

Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks 2026-06-30 at 16:00 By Kevin Townsend Decades-old Bash shell tricks can bypass safeguards in most open source AI coding agents, potentially turning malicious repositories into supply chain attack vectors. The post Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks appeared first […]

Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks Read More »

Exploitation of Recent Oracle E-Business Suite Vulnerability Begins

Exploitation of Recent Oracle E-Business Suite Vulnerability Begins 2026-06-30 at 14:29 By Ionut Arghire The critical-severity defect allows unauthenticated attackers to take over the E-Business Suite’s Payments product. The post Exploitation of Recent Oracle E-Business Suite Vulnerability Begins appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Exploitation of Recent Oracle E-Business Suite Vulnerability Begins Read More »

Critical SimpleHelp Vulnerability Exploited for Malware Delivery

Critical SimpleHelp Vulnerability Exploited for Malware Delivery 2026-06-30 at 11:43 By Ionut Arghire The threat actor is focused on collecting credentials, SSH keys, cryptocurrency wallets, and development tooling. The post Critical SimpleHelp Vulnerability Exploited for Malware Delivery appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical SimpleHelp Vulnerability Exploited for Malware Delivery Read More »

New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking

New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking 2026-06-30 at 08:04 By Eduard Kovacs CISA has published an advisory to inform organizations about three vulnerabilities found by a researcher in Daktronics controllers. The post New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking appeared first on SecurityWeek. This article is […]

New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking Read More »

‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access

‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access 2026-06-29 at 14:20 By Ionut Arghire A variant of DirtyFrag, the flaw allows unprivileged local users to manipulate the Linux page cache and gain root privileges. The post ‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access Read More »

Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories

Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories 2026-06-26 at 18:23 By Eduard Kovacs AWS has patched the vulnerability and published its own advisory to inform customers about the potential impact.  The post Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories appeared first on SecurityWeek. This article is an excerpt from […]

Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories Read More »

Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning

Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning 2026-06-25 at 14:23 By Eduard Kovacs The exploited flaw, CVE-2025-67038, is one of the vulnerabilities disclosed in April as part of the BRIDGE:BREAK research project. The post Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning appeared first on SecurityWeek. This article […]

Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning Read More »

Scroll to Top