Vulnerabilities

Critical Isolated-vm Vulnerability Leads to RCE on Host

Critical Isolated-vm Vulnerability Leads to RCE on Host 2026-08-21 at 15:26 By Ionut Arghire The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. The post Critical Isolated-vm Vulnerability Leads to RCE on Host appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Isolated-vm Vulnerability Leads to RCE on Host Read More »

Microsoft Rolls Out 22 Fresh Security Patches

Microsoft Rolls Out 22 Fresh Security Patches 2026-08-21 at 11:12 By Ionut Arghire Most of the fixes resolve code execution, privilege escalation, and information disclosure vulnerabilities. The post Microsoft Rolls Out 22 Fresh Security Patches appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Rolls Out 22 Fresh Security Patches Read More »

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities 2026-08-21 at 10:25 By Ionut Arghire The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware. The post CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities Read More »

Hackers Target Zimbra Servers in Active Exploitation Campaign

Hackers Target Zimbra Servers in Active Exploitation Campaign 2026-08-20 at 17:50 By Eduard Kovacs Exploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska. The post Hackers Target Zimbra Servers in Active Exploitation Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hackers Target Zimbra Servers in Active Exploitation Campaign Read More »

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities 2026-08-20 at 15:24 By Ionut Arghire The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges. The post Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities Read More »

MLflow Vulnerability Exploited for Cloud Credential Theft

MLflow Vulnerability Exploited for Cloud Credential Theft 2026-08-20 at 15:05 By Ionut Arghire The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information. The post MLflow Vulnerability Exploited for Cloud Credential Theft appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

MLflow Vulnerability Exploited for Cloud Credential Theft Read More »

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities 2026-08-19 at 13:37 By Ionut Arghire The flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities Read More »

943 Patches Rolled Out With Oracle’s August 2026 Security Update

943 Patches Rolled Out With Oracle’s August 2026 Security Update 2026-08-19 at 12:14 By Ionut Arghire The fixes resolve over 1,000 vulnerabilities across two dozen products, including over 460 remotely exploitable bugs. The post 943 Patches Rolled Out With Oracle’s August 2026 Security Update appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

943 Patches Rolled Out With Oracle’s August 2026 Security Update Read More »

Chrome, Firefox Updates Patch Dozens of Vulnerabilities

Chrome, Firefox Updates Patch Dozens of Vulnerabilities 2026-08-19 at 11:19 By Ionut Arghire The bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure. The post Chrome, Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome, Firefox Updates Patch Dozens of Vulnerabilities Read More »

Release the RAVEN: Destruction and Discipline

Release the RAVEN: Destruction and Discipline 2026-08-18 at 19:53 By Karl Biron In Part 4, we stole every document from every index, planted a rogue superuser account, created credential-independent API keys, and planted three persistence mechanisms that survive password rotations. Everything was logged. Now we answer two final questions: how much worse could it get,

Release the RAVEN: Destruction and Discipline Read More »

Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks

Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks 2026-08-18 at 18:03 By SecurityWeek News Join the live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. The post Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks appeared first on SecurityWeek.

Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks Read More »

AI-Driven Vulnerability Surge Breaks the Traditional Patching Model

AI-Driven Vulnerability Surge Breaks the Traditional Patching Model 2026-08-18 at 16:00 By Kevin Townsend Rapid7 warns that traditional patch cycles cannot keep pace with soaring vulnerability disclosures and faster exploitation, forcing defenders to prioritize exposure over severity scores. The post AI-Driven Vulnerability Surge Breaks the Traditional Patching Model appeared first on SecurityWeek. This article is

AI-Driven Vulnerability Surge Breaks the Traditional Patching Model Read More »

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Recent macOS Screen Sharing Vulnerability Exploited in Attacks 2026-08-17 at 11:47 By Ionut Arghire Threat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Recent macOS Screen Sharing Vulnerability Exploited in Attacks Read More »

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure 2026-08-17 at 11:13 By Eduard Kovacs The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure Read More »

In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities

In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities 2026-08-14 at 14:57 By SecurityWeek News Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON attendee blamed for Delta flight disruption. The post In Other News: Rapid7 Layoffs,

In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities Read More »

Hackers Exploiting Unpatched GeoServer Zero-Day

Hackers Exploiting Unpatched GeoServer Zero-Day 2026-08-14 at 10:01 By Ionut Arghire The security defect is described as an SQL injection that could allow attackers to achieve remote code execution. The post Hackers Exploiting Unpatched GeoServer Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hackers Exploiting Unpatched GeoServer Zero-Day Read More »

Beyond the Inbox: How BEC Leads to SSO Abuse

Beyond the Inbox: How BEC Leads to SSO Abuse 2026-08-13 at 20:40 By Jamie Mamroe and Federico Cedolini For years, many business email compromise (BEC) investigations have followed a familiar playbook: an attacker phishes credentials, logs into the victim’s mailbox, establishes persistence with inbox rules, monitors communications, and waits for an opportunity to steal money

Beyond the Inbox: How BEC Leads to SSO Abuse Read More »

Adobe Commerce Bug Targeted Immediately After Disclosure

Adobe Commerce Bug Targeted Immediately After Disclosure 2026-08-13 at 17:17 By Ionut Arghire The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Adobe Commerce Bug Targeted Immediately After Disclosure Read More »

Release the RAVEN: Kibana Under Siege

Release the RAVEN: Kibana Under Siege 2026-08-13 at 16:36 By Karl Biron In Parts 1 and 2, every command targeted port 9200. Every exploit, every reconnaissance query, every credential test hit the Elasticsearch REST API directly. But Elasticsearch rarely operates alone. Sitting alongside it on most deployments is Kibana, the visualization and management interface, quietly

Release the RAVEN: Kibana Under Siege Read More »

Scroll to Top