Vulnerabilities

Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI

Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI 2026-05-21 at 13:14 By Eduard Kovacs More than 200 vulnerabilities patched in recent Chrome releases are marked as ‘reported by Google’. The post Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI Read More »

Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility

Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility 2026-05-21 at 11:40 By Kevin Townsend New vulnerabilities are being discovered too fast, the time-to-exploitation is too short, and our visibility into them is largely lacking. The post Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility appeared first on SecurityWeek. This article is

Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility Read More »

Microsoft Rolls Out Mitigations for ‘YellowKey’ BitLocker Bypass

Microsoft Rolls Out Mitigations for ‘YellowKey’ BitLocker Bypass 2026-05-20 at 18:46 By Ionut Arghire The exploitation is mitigated by preventing the FsTx Auto Recovery Utility from starting when the WinRE image launches. The post Microsoft Rolls Out Mitigations for ‘YellowKey’ BitLocker Bypass appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Microsoft Rolls Out Mitigations for ‘YellowKey’ BitLocker Bypass Read More »

Drupal to Patch Highly Critical Vulnerability at Risk of Quick Exploitation

Drupal to Patch Highly Critical Vulnerability at Risk of Quick Exploitation 2026-05-19 at 21:14 By Eduard Kovacs Drupal says attackers may develop an exploit for the vulnerability within hours or days. The post Drupal to Patch Highly Critical Vulnerability at Risk of Quick Exploitation appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Drupal to Patch Highly Critical Vulnerability at Risk of Quick Exploitation Read More »

YellowKey and GreenPlasma: Two New Windows Zero-Days Unveiled

YellowKey and GreenPlasma: Two New Windows Zero-Days Unveiled 2026-05-19 at 17:33 By James Ballantyne and Pauline Bolaños Two novel Windows zero-day vulnerabilities dubbed YellowKey, which bypasses BitLocker drive encryption, and GreenPlasma, a local privilege escalation bug that targets a trusted Windows process called CTFMON, were recently publicly released. Nightmare-Eclipse (aka Chaotic Eclipse), a researcher who

YellowKey and GreenPlasma: Two New Windows Zero-Days Unveiled Read More »

Unpatched ChromaDB Vulnerability Can Lead to Server Takeover

Unpatched ChromaDB Vulnerability Can Lead to Server Takeover 2026-05-19 at 16:58 By Ionut Arghire The security defect can be exploited remotely, without authentication, to execute arbitrary code and leak sensitive information. The post Unpatched ChromaDB Vulnerability Can Lead to Server Takeover appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Unpatched ChromaDB Vulnerability Can Lead to Server Takeover Read More »

PoC Released for DirtyDecrypt Linux Kernel Vulnerability

PoC Released for DirtyDecrypt Linux Kernel Vulnerability 2026-05-19 at 12:47 By Ionut Arghire Patched in April, the underlying vulnerability allows local attackers to elevate their privileges to root. The post PoC Released for DirtyDecrypt Linux Kernel Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

PoC Released for DirtyDecrypt Linux Kernel Vulnerability Read More »

Critical Vulnerability Exposes Industrial Robot Fleets to Hacking

Critical Vulnerability Exposes Industrial Robot Fleets to Hacking 2026-05-19 at 09:34 By Eduard Kovacs The vulnerability, CVE-2026-8153, affects Universal Robots PolyScope 5 and it can be exploited for OS command injection.  The post Critical Vulnerability Exposes Industrial Robot Fleets to Hacking appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Vulnerability Exposes Industrial Robot Fleets to Hacking Read More »

‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery

‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery 2026-05-18 at 15:48 By Ionut Arghire Four vulnerabilities in OpenClaw can be chained together to steal credentials, escape the sandbox, and plant persistent backdoors. The post ‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery Read More »

Researcher Drops MiniPlasma Windows Exploit for Unpatched 2020 CVE

Researcher Drops MiniPlasma Windows Exploit for Unpatched 2020 CVE 2026-05-18 at 13:58 By Ionut Arghire The researcher dropped the MiniPlasma exploit that uses the original proof-of-concept (PoC) code targeting the bug. The post Researcher Drops MiniPlasma Windows Exploit for Unpatched 2020 CVE appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Researcher Drops MiniPlasma Windows Exploit for Unpatched 2020 CVE Read More »

Exploitation of Critical NGINX Vulnerability Begins

Exploitation of Critical NGINX Vulnerability Begins 2026-05-18 at 10:34 By Ionut Arghire The flaw leads to denial-of-service on default configurations and to remote code execution if ASLR is disabled. The post Exploitation of Critical NGINX Vulnerability Begins appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Exploitation of Critical NGINX Vulnerability Begins Read More »

Hackers Earn $1.3 Million at Pwn2Own Berlin 2026 

Hackers Earn $1.3 Million at Pwn2Own Berlin 2026  2026-05-18 at 08:02 By Eduard Kovacs Participants demonstrated exploits for Windows, Linux, VMware, Nvidia, and AI products. The post Hackers Earn $1.3 Million at Pwn2Own Berlin 2026  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hackers Earn $1.3 Million at Pwn2Own Berlin 2026  Read More »

PoC Code Published for Critical NGINX Vulnerability

PoC Code Published for Critical NGINX Vulnerability 2026-05-16 at 14:43 By Ionut Arghire Introduced in 2008, the critical-severity security defect was patched this week in NGINX Plus and NGINX open source. The post PoC Code Published for Critical NGINX Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

PoC Code Published for Critical NGINX Vulnerability Read More »

Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild

Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild 2026-05-15 at 15:32 By Eduard Kovacs Microsoft has shared mitigations for CVE-2026-42897 until a permanent patch can be released for affected Exchange Server versions. The post Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt

Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild Read More »

Chrome 148 Update Patches Critical Vulnerabilities

Chrome 148 Update Patches Critical Vulnerabilities 2026-05-15 at 11:02 By Ionut Arghire The refresh resolves critical-severity use-after-free and other types of bugs in various browser components. The post Chrome 148 Update Patches Critical Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome 148 Update Patches Critical Vulnerabilities Read More »

Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026

Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026 2026-05-15 at 10:16 By Eduard Kovacs The zero-day, tracked as CVE-2026-20182, has been exploited in targeted attacks by a sophisticated threat actor identified as UAT-8616. The post Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026 appeared first on SecurityWeek. This article is an

Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026 Read More »

Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere

Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere 2026-05-14 at 18:25 By Kevin Townsend Independent benchmarking finds Mythos highly effective for source code audits, reverse engineering, and native-code analysis, though its exploit validation and reasoning capabilities remain inconsistent. The post Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere appeared first on SecurityWeek. This

Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere Read More »

New Linux Kernel Vulnerability Fragnesia Allows Root Privilege Escalation

New Linux Kernel Vulnerability Fragnesia Allows Root Privilege Escalation 2026-05-14 at 16:44 By Eduard Kovacs The vulnerability, tracked as CVE-2026-46300, is similar to the recently disclosed exploits named Dirty Frag and Copy Fail. The post New Linux Kernel Vulnerability Fragnesia Allows Root Privilege Escalation appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

New Linux Kernel Vulnerability Fragnesia Allows Root Privilege Escalation Read More »

Hackers Targeted PraisonAI Vulnerability Hours After Disclosure

Hackers Targeted PraisonAI Vulnerability Hours After Disclosure 2026-05-14 at 12:48 By Ionut Arghire The first exploitation attempts were observed less than four hours after the authentication bypass was publicly disclosed. The post Hackers Targeted PraisonAI Vulnerability Hours After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hackers Targeted PraisonAI Vulnerability Hours After Disclosure Read More »

Scroll to Top