Vulnerabilities

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers 2026-08-04 at 08:18 By Eduard Kovacs The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000. The post Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers appeared first on SecurityWeek. This article is an excerpt […]

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers Read More »

N‑able Patches Vulnerability Exploited to Hack N-central Servers

N‑able Patches Vulnerability Exploited to Hack N-central Servers 2026-08-03 at 15:34 By Eduard Kovacs The N‑central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass. The post N‑able Patches Vulnerability Exploited to Hack N-central Servers appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

N‑able Patches Vulnerability Exploited to Hack N-central Servers Read More »

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks 2026-08-03 at 13:39 By Ionut Arghire The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement. The post Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks Read More »

Ruby on Rails Patches Critical Vulnerability

Ruby on Rails Patches Critical Vulnerability 2026-08-01 at 14:15 By Ionut Arghire The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Ruby on Rails Patches Critical Vulnerability Read More »

Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace

Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace 2026-07-31 at 13:28 By Ionut Arghire The internet giant has built an agent harness to find vulnerabilities across Chrome’s codebase. The post Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace Read More »

Critical Flaw Led to Azure Cosmos DB Pwnage

Critical Flaw Led to Azure Cosmos DB Pwnage 2026-07-31 at 12:04 By Ionut Arghire Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access. The post Critical Flaw Led to Azure Cosmos DB Pwnage appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Critical Flaw Led to Azure Cosmos DB Pwnage Read More »

Critical Code Execution Vulnerability Patched in TeamCity 

Critical Code Execution Vulnerability Patched in TeamCity  2026-07-31 at 09:50 By Ionut Arghire Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol. The post Critical Code Execution Vulnerability Patched in TeamCity  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Code Execution Vulnerability Patched in TeamCity  Read More »

Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms 

Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms  2026-07-30 at 12:56 By Ionut Arghire Unauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container. The post Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms  Read More »

Cisco Secure FMC Zero-Day Exploited in the Wild

Cisco Secure FMC Zero-Day Exploited in the Wild 2026-07-30 at 09:31 By Eduard Kovacs The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices.  The post Cisco Secure FMC Zero-Day Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Cisco Secure FMC Zero-Day Exploited in the Wild Read More »

Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes

Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes 2026-07-29 at 22:22 By Karl Biron You have almost certainly interacted with Elasticsearch today. The search bar on your company’s internal wiki. The autocomplete on the e-commerce site where you ordered lunch. The log aggregation dashboard your SOC team stares at for eight

Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes Read More »

Critical VM Escape Vulnerability Patched in VMware ESXi

Critical VM Escape Vulnerability Patched in VMware ESXi 2026-07-29 at 14:42 By Eduard Kovacs A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion. The post Critical VM Escape Vulnerability Patched in VMware ESXi appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical VM Escape Vulnerability Patched in VMware ESXi Read More »

JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack

JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack 2026-07-29 at 11:46 By Ionut Arghire The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given. The post JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack Read More »

Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe

Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe 2026-07-28 at 17:19 By Eduard Kovacs Apple announced that dozens of vulnerabilities have been patched in each of its operating systems. The post Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe Read More »

Act Security Emerges from Stealth to Fight the Patch Problem

Act Security Emerges from Stealth to Fight the Patch Problem 2026-07-28 at 14:00 By Kevin Townsend Act Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments. The post Act Security Emerges from Stealth to Fight the Patch Problem appeared first on SecurityWeek. This article is an

Act Security Emerges from Stealth to Fight the Patch Problem Read More »

Unpatched Fastjson Vulnerability Exploited in Attacks

Unpatched Fastjson Vulnerability Exploited in Attacks 2026-07-28 at 10:27 By Ionut Arghire The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. The post Unpatched Fastjson Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Unpatched Fastjson Vulnerability Exploited in Attacks Read More »

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day 2026-07-28 at 09:40 By Ionut Arghire Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day Read More »

LegacyHive: Hunting Windows Profile Initialization Abuse Through Offline Registry Manipulation

LegacyHive: Hunting Windows Profile Initialization Abuse Through Offline Registry Manipulation 2026-07-27 at 17:07 By Serhii Melnyk and Timmy Lister Following GreenPlasma, YellowKey and MiniPlasma, as well as RoguePlanet and GreatXML, the Nightmare-Eclipse disclosure actor has published LegacyHive, its latest Windows proof-of-concept (PoC) released shortly after Microsoft’s July 2026 Patch Tuesday. This article is an excerpt

LegacyHive: Hunting Windows Profile Initialization Abuse Through Offline Registry Manipulation Read More »

PTC Windchill Vulnerability Exploited in Ransomware Campaign

PTC Windchill Vulnerability Exploited in Ransomware Campaign 2026-07-27 at 16:19 By Ionut Arghire The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication. The post PTC Windchill Vulnerability Exploited in Ransomware Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

PTC Windchill Vulnerability Exploited in Ransomware Campaign Read More »

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws 2026-07-24 at 17:20 By SecurityWeek News Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion attempt. The post In Other News: Dolphin X AI-Powered Malware,

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws Read More »

Scroll to Top