Vulnerabilities

One Patch Behind: Nightmare-Eclipse’s ShieldCrash and the Defender Bypass That Won’t Stay Fixed

One Patch Behind: Nightmare-Eclipse’s ShieldCrash and the Defender Bypass That Won’t Stay Fixed 2026-09-16 at 16:35 By Serhii Melnyk and Timmy Lister In our previous blog, we analyzed four proofs of concept (PoCs) from the leak persona Nightmare-Eclipse that targeted Kaspersky, Avast, NVIDIA, and CrowdStrike, respectively. This article is an excerpt from LevelBlue SpiderLabs Blog […]

One Patch Behind: Nightmare-Eclipse’s ShieldCrash and the Defender Bypass That Won’t Stay Fixed Read More »

Pixel Modem Zero-Day Exploited in Targeted Attacks

Pixel Modem Zero-Day Exploited in Targeted Attacks 2026-09-16 at 16:10 By Eduard Kovacs Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15. The post Pixel Modem Zero-Day Exploited in Targeted Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Pixel Modem Zero-Day Exploited in Targeted Attacks Read More »

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover 2026-09-16 at 14:32 By Ionut Arghire Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities. The post Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover Read More »

Chrome, Firefox Updates Patch 115 Vulnerabilities

Chrome, Firefox Updates Patch 115 Vulnerabilities 2026-09-16 at 13:28 By Ionut Arghire Google resolved 42 security defects in Chrome, and Mozilla fixed 73 bugs in Firefox. The post Chrome, Firefox Updates Patch 115 Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome, Firefox Updates Patch 115 Vulnerabilities Read More »

Enterprises Warned of Attacks Exploiting WSO2 Vulnerability

Enterprises Warned of Attacks Exploiting WSO2 Vulnerability 2026-09-16 at 11:39 By Eduard Kovacs The vulnerability, tracked as CVE-2026-5430, can be exploited to gain access to valuable enterprise data. The post Enterprises Warned of Attacks Exploiting WSO2 Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Enterprises Warned of Attacks Exploiting WSO2 Vulnerability Read More »

Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

Oracle Patches 800+ Vulnerabilities in September 2026 Security Update 2026-09-16 at 11:06 By Ionut Arghire The security updates resolve over 800 vulnerabilities across 17 product families, including over 100 critical-severity flaws. The post Oracle Patches 800+ Vulnerabilities in September 2026 Security Update appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Oracle Patches 800+ Vulnerabilities in September 2026 Security Update Read More »

$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws

$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws 2026-09-15 at 19:00 By Kevin Townsend AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage. The post $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws Read More »

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases 

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases  2026-09-15 at 14:06 By Ionut Arghire The updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks. The post Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases  appeared first on […]

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases  Read More »

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation 2026-09-15 at 08:18 By Eduard Kovacs An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges. The post Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation appeared first on SecurityWeek. This article is an […]

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation Read More »

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution 2026-09-14 at 14:51 By Ionut Arghire The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely. The post Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution appeared first on SecurityWeek. This article is an excerpt from […]

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution Read More »

Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

Three JFrog Artifactory Flaws Exploited for Backdoor Deployment 2026-09-14 at 12:27 By Ionut Arghire The vulnerabilities can allow attackers to bypass authentication and elevate their privileges to administrator. The post Three JFrog Artifactory Flaws Exploited for Backdoor Deployment appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Three JFrog Artifactory Flaws Exploited for Backdoor Deployment Read More »

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks 2026-09-14 at 11:25 By Ionut Arghire The flaw allows attackers to send files and execute them without authorization through an active remote session. The post ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks Read More »

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days 2026-09-12 at 14:10 By Ionut Arghire Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments. The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days Read More »

GitLab Vulnerability Exploited One Day After Disclosure

GitLab Vulnerability Exploited One Day After Disclosure 2026-09-11 at 19:11 By Ionut Arghire The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

GitLab Vulnerability Exploited One Day After Disclosure Read More »

Check Point Patches Critical VPN Vulnerabilities

Check Point Patches Critical VPN Vulnerabilities 2026-09-11 at 14:10 By Ionut Arghire Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Check Point Patches Critical VPN Vulnerabilities Read More »

Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation

Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation 2026-09-10 at 16:30 By SecurityWeek News Join the webinar for a focused, 20-minute discussion on Frontier Pace Governance, an approach to balancing automation, policy, and business risk as IT operations accelerate. The post Webinar Today: Keep Pace With AI – A New Operating Model […]

Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation Read More »

Critical NetScaler Vulnerability Exploited in Attacks

Critical NetScaler Vulnerability Exploited in Attacks 2026-09-10 at 15:20 By Ionut Arghire Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3. The post Critical NetScaler Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical NetScaler Vulnerability Exploited in Attacks Read More »

Organizations Warned of Cisco Secure FMC Exploitation

Organizations Warned of Cisco Secure FMC Exploitation 2026-09-10 at 13:06 By Eduard Kovacs Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026. The post Organizations Warned of Cisco Secure FMC Exploitation appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Organizations Warned of Cisco Secure FMC Exploitation Read More »

New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender 2026-09-10 at 10:09 By Ionut Arghire The exploit provides full System privileges on Windows machines running the September 2026 patches. The post New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender Read More »

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks 2026-09-10 at 09:33 By Ionut Arghire The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026. The post Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks Read More »

Scroll to Top