Vulnerabilities

Energy Disruption in UK Critical Infrastructure and the Growing OT Cyber Threat

Energy Disruption in UK Critical Infrastructure and the Growing OT Cyber Threat 2026-08-25 at 18:27 By Nikita Kazymirskyi A cyber incident affecting a small UK electricity generator in July 2026 resulted in several days of operational unavailability and triggered a government and NCSC response. UK authorities confirmed that the event posed no threat to the […]

Energy Disruption in UK Critical Infrastructure and the Growing OT Cyber Threat Read More »

The Double Edge of AI in Healthcare: Guarding Data, Growing Empathy

The Double Edge of AI in Healthcare: Guarding Data, Growing Empathy 2026-08-25 at 17:00 By Bindu Sundaresan Healthcare has always run on two currencies: information and trust. Patients hand over their most sensitive data, diagnoses, genetic profiles, mental health histories, on the assumption that it will be protected and that the people (or systems) handling it […]

The Double Edge of AI in Healthcare: Guarding Data, Growing Empathy Read More »

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities 2026-08-25 at 16:33 By Eduard Kovacs CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Read More »

Silent Patches Don’t Stop Attackers—They Blind Defenders

Silent Patches Don’t Stop Attackers—They Blind Defenders 2026-08-25 at 13:00 By Tod Beardsley Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. The post Silent Patches Don’t Stop Attackers—They Blind Defenders appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Silent Patches Don’t Stop Attackers—They Blind Defenders Read More »

CISA Warns of Exploited Oracle WebLogic Vulnerability

CISA Warns of Exploited Oracle WebLogic Vulnerability 2026-08-25 at 10:46 By Eduard Kovacs The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers. The post CISA Warns of Exploited Oracle WebLogic Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Warns of Exploited Oracle WebLogic Vulnerability Read More »

91 Vulnerabilities Patched in Spring Application Framework

91 Vulnerabilities Patched in Spring Application Framework 2026-08-24 at 14:58 By Eduard Kovacs More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024.  The post 91 Vulnerabilities Patched in Spring Application Framework appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

91 Vulnerabilities Patched in Spring Application Framework Read More »

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug 2026-08-21 at 18:11 By SecurityWeek News Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. The post In Other News: Zombie Card Attack, T-Mobile Cut Cable […]

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug Read More »

Critical Isolated-vm Vulnerability Leads to RCE on Host

Critical Isolated-vm Vulnerability Leads to RCE on Host 2026-08-21 at 15:26 By Ionut Arghire The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. The post Critical Isolated-vm Vulnerability Leads to RCE on Host appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Isolated-vm Vulnerability Leads to RCE on Host Read More »

Microsoft Rolls Out 22 Fresh Security Patches

Microsoft Rolls Out 22 Fresh Security Patches 2026-08-21 at 11:12 By Ionut Arghire Most of the fixes resolve code execution, privilege escalation, and information disclosure vulnerabilities. The post Microsoft Rolls Out 22 Fresh Security Patches appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Rolls Out 22 Fresh Security Patches Read More »

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities 2026-08-21 at 10:25 By Ionut Arghire The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware. The post CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities Read More »

Hackers Target Zimbra Servers in Active Exploitation Campaign

Hackers Target Zimbra Servers in Active Exploitation Campaign 2026-08-20 at 17:50 By Eduard Kovacs Exploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska. The post Hackers Target Zimbra Servers in Active Exploitation Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hackers Target Zimbra Servers in Active Exploitation Campaign Read More »

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities 2026-08-20 at 15:24 By Ionut Arghire The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges. The post Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities Read More »

MLflow Vulnerability Exploited for Cloud Credential Theft

MLflow Vulnerability Exploited for Cloud Credential Theft 2026-08-20 at 15:05 By Ionut Arghire The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information. The post MLflow Vulnerability Exploited for Cloud Credential Theft appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

MLflow Vulnerability Exploited for Cloud Credential Theft Read More »

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities 2026-08-19 at 13:37 By Ionut Arghire The flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities Read More »

943 Patches Rolled Out With Oracle’s August 2026 Security Update

943 Patches Rolled Out With Oracle’s August 2026 Security Update 2026-08-19 at 12:14 By Ionut Arghire The fixes resolve over 1,000 vulnerabilities across two dozen products, including over 460 remotely exploitable bugs. The post 943 Patches Rolled Out With Oracle’s August 2026 Security Update appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

943 Patches Rolled Out With Oracle’s August 2026 Security Update Read More »

Chrome, Firefox Updates Patch Dozens of Vulnerabilities

Chrome, Firefox Updates Patch Dozens of Vulnerabilities 2026-08-19 at 11:19 By Ionut Arghire The bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure. The post Chrome, Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome, Firefox Updates Patch Dozens of Vulnerabilities Read More »

Release the RAVEN: Destruction and Discipline

Release the RAVEN: Destruction and Discipline 2026-08-18 at 19:53 By Karl Biron In Part 4, we stole every document from every index, planted a rogue superuser account, created credential-independent API keys, and planted three persistence mechanisms that survive password rotations. Everything was logged. Now we answer two final questions: how much worse could it get, […]

Release the RAVEN: Destruction and Discipline Read More »

Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks

Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks 2026-08-18 at 18:03 By SecurityWeek News Join the live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. The post Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks appeared first on SecurityWeek. […]

Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks Read More »

AI-Driven Vulnerability Surge Breaks the Traditional Patching Model

AI-Driven Vulnerability Surge Breaks the Traditional Patching Model 2026-08-18 at 16:00 By Kevin Townsend Rapid7 warns that traditional patch cycles cannot keep pace with soaring vulnerability disclosures and faster exploitation, forcing defenders to prioritize exposure over severity scores. The post AI-Driven Vulnerability Surge Breaks the Traditional Patching Model appeared first on SecurityWeek. This article is […]

AI-Driven Vulnerability Surge Breaks the Traditional Patching Model Read More »

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Recent macOS Screen Sharing Vulnerability Exploited in Attacks 2026-08-17 at 11:47 By Ionut Arghire Threat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Recent macOS Screen Sharing Vulnerability Exploited in Attacks Read More »

Scroll to Top