Vulnerabilities

Organizations Warned of Exploited Zimbra Collaboration Vulnerability

Organizations Warned of Exploited Zimbra Collaboration Vulnerability 2026-01-23 at 15:31 By Ionut Arghire CISA has added the Zimbra flaw to the KEV catalog along with three other bugs exploited in the wild. The post Organizations Warned of Exploited Zimbra Collaboration Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Organizations Warned of Exploited Zimbra Collaboration Vulnerability Read More »

Infotainment, EV Charger Exploits Earn Hackers $1M at Pwn2Own Automotive 2026

Infotainment, EV Charger Exploits Earn Hackers $1M at Pwn2Own Automotive 2026 2026-01-23 at 13:33 By Eduard Kovacs Pwn2Own participants disclosed a total of 76 vulnerabilities during the three-day event.  The post Infotainment, EV Charger Exploits Earn Hackers $1M at Pwn2Own Automotive 2026 appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Infotainment, EV Charger Exploits Earn Hackers $1M at Pwn2Own Automotive 2026 Read More »

Fresh SmarterMail Flaw Exploited for Admin Access

Fresh SmarterMail Flaw Exploited for Admin Access 2026-01-23 at 12:46 By Ionut Arghire The exploitation of the authentication bypass vulnerability started two days after patches were released. The post Fresh SmarterMail Flaw Exploited for Admin Access appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Fresh SmarterMail Flaw Exploited for Admin Access Read More »

New Wave of Attacks Targeting FortiGate Firewalls

New Wave of Attacks Targeting FortiGate Firewalls 2026-01-22 at 14:41 By Ionut Arghire Hackers bypass the FortiCloud SSO login authentication to create new accounts and change device configurations. The post New Wave of Attacks Targeting FortiGate Firewalls appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

New Wave of Attacks Targeting FortiGate Firewalls Read More »

Furl Raises $10 Million for Autonomous Vulnerability Remediation

Furl Raises $10 Million for Autonomous Vulnerability Remediation 2026-01-22 at 13:11 By Ionut Arghire The startup will use the new funding to accelerate product development and deepen remediation capabilities. The post Furl Raises $10 Million for Autonomous Vulnerability Remediation appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Furl Raises $10 Million for Autonomous Vulnerability Remediation Read More »

Atlassian, GitLab, Zoom Release Security Patches

Atlassian, GitLab, Zoom Release Security Patches 2026-01-22 at 11:49 By Ionut Arghire Fixes were rolled out for over two dozen vulnerabilities, including critical- and high-severity bugs. The post Atlassian, GitLab, Zoom Release Security Patches appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Atlassian, GitLab, Zoom Release Security Patches Read More »

Hackers Targeting Cisco Unified CM Zero-Day 

Hackers Targeting Cisco Unified CM Zero-Day  2026-01-22 at 11:07 By Eduard Kovacs Cisco has released patches for CVE-2026-20045, a critical vulnerability that can be exploited for unauthenticated remote code execution. The post Hackers Targeting Cisco Unified CM Zero-Day  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hackers Targeting Cisco Unified CM Zero-Day  Read More »

Oracle’s First 2026 CPU Delivers 337 New Security Patches

Oracle’s First 2026 CPU Delivers 337 New Security Patches 2026-01-21 at 12:53 By Ionut Arghire Oracle’s January 2026 CPU resolves roughly 230 unique vulnerabilities across more than 30 products. The post Oracle’s First 2026 CPU Delivers 337 New Security Patches appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Oracle’s First 2026 CPU Delivers 337 New Security Patches Read More »

The AI Authorization Revolution: Why “Who Can Do What” Is the New Security Battleground

The AI Authorization Revolution: Why “Who Can Do What” Is the New Security Battleground 2026-01-20 at 21:37 By Bindu Sundaresan Remember when security was simple? Users had roles. Roles had permissions. Done. Those were the days when your biggest worry was whether someone from marketing accidentally got admin access to the finance system. This article

The AI Authorization Revolution: Why “Who Can Do What” Is the New Security Battleground Read More »

Chainlit Vulnerabilities May Leak Sensitive Information

Chainlit Vulnerabilities May Leak Sensitive Information 2026-01-20 at 17:01 By Ionut Arghire The two bugs, an arbitrary file read and an SSRF bug, can be exploited without user interaction to leak credentials, databases, and other data. The post Chainlit Vulnerabilities May Leak Sensitive Information appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Chainlit Vulnerabilities May Leak Sensitive Information Read More »

TP-Link Patches Vulnerability Exposing VIGI Cameras to Remote Hacking

TP-Link Patches Vulnerability Exposing VIGI Cameras to Remote Hacking 2026-01-19 at 17:21 By Eduard Kovacs The researcher who discovered the vulnerability saw more than 2,500 internet-exposed devices. The post TP-Link Patches Vulnerability Exposing VIGI Cameras to Remote Hacking appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

TP-Link Patches Vulnerability Exposing VIGI Cameras to Remote Hacking Read More »

In Other News: FortiSIEM Flaw Exploited, Sean Plankey Renominated, Russia’s Polish Grid Attack

In Other News: FortiSIEM Flaw Exploited, Sean Plankey Renominated, Russia’s Polish Grid Attack 2026-01-16 at 18:21 By SecurityWeek News Other noteworthy stories that might have slipped under the radar: BodySnatcher agentic AI hijacking, Telegram IP exposure, shipping systems hacked by researcher. The post In Other News: FortiSIEM Flaw Exploited, Sean Plankey Renominated, Russia’s Polish Grid

In Other News: FortiSIEM Flaw Exploited, Sean Plankey Renominated, Russia’s Polish Grid Attack Read More »

Cisco Patches Vulnerability Exploited by Chinese Hackers

Cisco Patches Vulnerability Exploited by Chinese Hackers 2026-01-16 at 11:54 By Ionut Arghire UAT-9686 exploited the bug to deploy the AquaShell backdoor on Cisco appliances with certain ports open to the internet. The post Cisco Patches Vulnerability Exploited by Chinese Hackers appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cisco Patches Vulnerability Exploited by Chinese Hackers Read More »

New StackWarp Attack Threatens Confidential VMs on AMD Processors

New StackWarp Attack Threatens Confidential VMs on AMD Processors 2026-01-15 at 20:27 By Eduard Kovacs Researchers have disclosed technical details on a new AMD processor attack that allows remote code execution inside confidential VMs. The post New StackWarp Attack Threatens Confidential VMs on AMD Processors appeared first on SecurityWeek. This article is an excerpt from

New StackWarp Attack Threatens Confidential VMs on AMD Processors Read More »

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Aveva, Phoenix Contact

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Aveva, Phoenix Contact 2026-01-15 at 11:34 By Eduard Kovacs Only a dozen new advisories have been published this Patch Tuesday by industrial giants.  The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Aveva, Phoenix Contact appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Aveva, Phoenix Contact Read More »

Fortinet Patches Critical Vulnerabilities in FortiFone, FortiSIEM

Fortinet Patches Critical Vulnerabilities in FortiFone, FortiSIEM 2026-01-14 at 11:56 By Ionut Arghire Exploitable without authentication, the two security defects could lead to configuration leak and code execution. The post Fortinet Patches Critical Vulnerabilities in FortiFone, FortiSIEM appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Fortinet Patches Critical Vulnerabilities in FortiFone, FortiSIEM Read More »

Chrome 144, Firefox 147 Patch High-Severity Vulnerabilities

Chrome 144, Firefox 147 Patch High-Severity Vulnerabilities 2026-01-14 at 11:50 By Ionut Arghire The two browser updates resolve 26 security defects, including bugs that could be exploited for code execution. The post Chrome 144, Firefox 147 Patch High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome 144, Firefox 147 Patch High-Severity Vulnerabilities Read More »

Adobe Patches Critical Apache Tika Bug in ColdFusion

Adobe Patches Critical Apache Tika Bug in ColdFusion 2026-01-13 at 22:09 By Ionut Arghire Adobe has released patches for 25 vulnerabilities across its products, including a critical Apache Tika flaw in ColdFusion. The post Adobe Patches Critical Apache Tika Bug in ColdFusion appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Adobe Patches Critical Apache Tika Bug in ColdFusion Read More »

Microsoft Patches Exploited Windows Zero-Day, 111 Other Vulnerabilities

Microsoft Patches Exploited Windows Zero-Day, 111 Other Vulnerabilities 2026-01-13 at 21:52 By Eduard Kovacs Two vulnerabilities patched this month by Microsoft were disclosed publicly before fixes were released. The post Microsoft Patches Exploited Windows Zero-Day, 111 Other Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Patches Exploited Windows Zero-Day, 111 Other Vulnerabilities Read More »

SAP’s January 2026 Security Updates Patch Critical Vulnerabilities

SAP’s January 2026 Security Updates Patch Critical Vulnerabilities 2026-01-13 at 17:45 By Ionut Arghire SAP has released 17 security notes, including four that address critical SQL injection, RCE, and code injection vulnerabilities. The post SAP’s January 2026 Security Updates Patch Critical Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

SAP’s January 2026 Security Updates Patch Critical Vulnerabilities Read More »

Scroll to Top