Vulnerabilities

19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access

19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access 2026-06-01 at 17:37 By Ionut Arghire Proof-of-concept (PoC) exploit code has been released for the CIFSwitch flaw, which allows low-privileged users to escalate to root on vulnerable Linux systems. The post 19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access appeared first on SecurityWeek. This article […]

19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access Read More »

Recent Palo Alto Networks Vulnerability Exploited for Weeks

Recent Palo Alto Networks Vulnerability Exploited for Weeks 2026-06-01 at 17:37 By Ionut Arghire Hackers began exploiting CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS, four days after public disclosure. The post Recent Palo Alto Networks Vulnerability Exploited for Weeks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Recent Palo Alto Networks Vulnerability Exploited for Weeks Read More »

Exploit Code Published for Critical Flowise RCE Vulnerability

Exploit Code Published for Critical Flowise RCE Vulnerability 2026-05-30 at 18:55 By Ionut Arghire The one-click vulnerability allows attackers to execute arbitrary code on self-hosted Flowise servers by tricking users into importing a malicious chatflow. The post Exploit Code Published for Critical Flowise RCE Vulnerability appeared first on SecurityWeek. This article is an excerpt from

Exploit Code Published for Critical Flowise RCE Vulnerability Read More »

Gogs Zero-Day Exposes Servers to Remote Code Execution

Gogs Zero-Day Exposes Servers to Remote Code Execution 2026-05-29 at 18:31 By Ionut Arghire The critical-severity issue, assigned a CVSS score of 9.4, is an argument injection flaw that can be exploited by authenticated attackers via pull requests with malicious branch names. The post Gogs Zero-Day Exposes Servers to Remote Code Execution appeared first on

Gogs Zero-Day Exposes Servers to Remote Code Execution Read More »

IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell”

IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell” 2026-05-28 at 17:54 By SecurityWeek News Project Lightwell is designed to fix vulnerabilities without breaking what is already in production. The post IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell” appeared

IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell” Read More »

Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign

Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign 2026-05-28 at 17:00 By Maor Gabay We recently observed a multi-stage macOS intrusion campaign conducted by the North Korean state-sponsored threat group Sapphire Sleet (also tracked as BlueNoroff/UNC1069). This article is an excerpt from LevelBlue SpiderLabs Blog View Original Source

Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign Read More »

Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks

Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks 2026-05-28 at 15:55 By Ionut Arghire Fortinet rolled out hotfixes for the security defect in April, warning that it had been exploited in the wild as a zero-day and urging immediate patching. The post Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks appeared first on SecurityWeek. This

Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks Read More »

Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate

Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate 2026-05-27 at 17:30 By Eduard Kovacs Novee researchers discovered an account takeover vulnerability in the open source CFP management tool Pretalx. The post Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate appeared first on SecurityWeek. This article is an

Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate Read More »

CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day

CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day 2026-05-27 at 09:56 By Ionut Arghire Resolved last week, the vulnerability was exploited in the wild as a zero-day to execute scripts with root privileges. The post CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day appeared first on SecurityWeek. This article is an

CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day Read More »

Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment

Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment 2026-05-26 at 17:32 By Ionut Arghire Hardcoded machineKey values in a configuration file enabled ViewState deserialization attacks leading to remote code execution. The post Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment Read More »

Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images

Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images 2026-05-26 at 13:56 By Mike Lennon DockSec, an OWASP incubator project, correlates findings from multiple container security scanners and uses AI to generate plain-English remediation guidance and exact Dockerfile fixes. The post Open Source DockSec Uses AI to Cut Through Vulnerability Noise

Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images Read More »

Ghost CMS Vulnerability Exploited to Hack Over 700 Websites

Ghost CMS Vulnerability Exploited to Hack Over 700 Websites 2026-05-25 at 16:59 By Eduard Kovacs Sites belonging to major universities such as Harvard and Oxford, as well as DuckDuckGo, have been compromised in the attack. The post Ghost CMS Vulnerability Exploited to Hack Over 700 Websites appeared first on SecurityWeek. This article is an excerpt

Ghost CMS Vulnerability Exploited to Hack Over 700 Websites Read More »

Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects

Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects 2026-05-25 at 13:58 By Eduard Kovacs Many findings have been confirmed to be critical or high-severity vulnerabilities and the number will continue to increase.  The post Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects appeared first on SecurityWeek. This article is an excerpt

Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects Read More »

From WinRE to SYSTEM: Hunting the YellowKey and MiniPlasma Attack Chain

From WinRE to SYSTEM: Hunting the YellowKey and MiniPlasma Attack Chain 2026-05-22 at 22:53 By Since April 2026, LevelBlue SpiderLabs’ Cyber Threat Intelligence team has tracked a series of public zero-day disclosures targeting Microsoft Windows, attributed to an anonymous actor operating under the names Chaotic Eclipse and Nightmare Eclipse. The activity spans multiple areas of

From WinRE to SYSTEM: Hunting the YellowKey and MiniPlasma Attack Chain Read More »

Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure

Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure 2026-05-22 at 21:05 By Eduard Kovacs Drupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites. The post Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure appeared first on SecurityWeek. This article is an

Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure Read More »

TrendAI Patches Apex One Zero-Day Exploited in the Wild

TrendAI Patches Apex One Zero-Day Exploited in the Wild 2026-05-22 at 11:53 By Eduard Kovacs CVE-2026-34926 is a directory traversal flaw that can be exploited against the on-premise version of Apex One. The post TrendAI Patches Apex One Zero-Day Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

TrendAI Patches Apex One Zero-Day Exploited in the Wild Read More »

Cisco Patches Critical Vulnerability in Secure Workload

Cisco Patches Critical Vulnerability in Secure Workload 2026-05-21 at 15:24 By Ionut Arghire Insufficient validation and authentication in the Secure Workload’s REST APIs provide remote attackers with Site Admin privileges. The post Cisco Patches Critical Vulnerability in Secure Workload appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cisco Patches Critical Vulnerability in Secure Workload Read More »

Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking

Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking 2026-05-21 at 14:22 By Eduard Kovacs CVE-2026-9082 can be exploited without authentication for information disclosure, privilege escalation, and remote code execution. The post Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking Read More »

Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days

Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days 2026-05-21 at 13:14 By Ionut Arghire The bugs could be exploited to elevate privileges to System or create a denial-of-service (DoS) condition. The post Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days Read More »

Scroll to Top