Vulnerabilities

Critical Code Execution Vulnerability Patched in TeamCity 

Critical Code Execution Vulnerability Patched in TeamCity  2026-07-31 at 09:50 By Ionut Arghire Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol. The post Critical Code Execution Vulnerability Patched in TeamCity  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Code Execution Vulnerability Patched in TeamCity  Read More »

Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms 

Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms  2026-07-30 at 12:56 By Ionut Arghire Unauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container. The post Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms  Read More »

Cisco Secure FMC Zero-Day Exploited in the Wild

Cisco Secure FMC Zero-Day Exploited in the Wild 2026-07-30 at 09:31 By Eduard Kovacs The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices.  The post Cisco Secure FMC Zero-Day Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Cisco Secure FMC Zero-Day Exploited in the Wild Read More »

Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes

Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes 2026-07-29 at 22:22 By Karl Biron You have almost certainly interacted with Elasticsearch today. The search bar on your company’s internal wiki. The autocomplete on the e-commerce site where you ordered lunch. The log aggregation dashboard your SOC team stares at for eight […]

Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes Read More »

Critical VM Escape Vulnerability Patched in VMware ESXi

Critical VM Escape Vulnerability Patched in VMware ESXi 2026-07-29 at 14:42 By Eduard Kovacs A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion. The post Critical VM Escape Vulnerability Patched in VMware ESXi appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical VM Escape Vulnerability Patched in VMware ESXi Read More »

JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack

JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack 2026-07-29 at 11:46 By Ionut Arghire The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given. The post JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack Read More »

Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe

Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe 2026-07-28 at 17:19 By Eduard Kovacs Apple announced that dozens of vulnerabilities have been patched in each of its operating systems. The post Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe Read More »

Act Security Emerges from Stealth to Fight the Patch Problem

Act Security Emerges from Stealth to Fight the Patch Problem 2026-07-28 at 14:00 By Kevin Townsend Act Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments. The post Act Security Emerges from Stealth to Fight the Patch Problem appeared first on SecurityWeek. This article is an […]

Act Security Emerges from Stealth to Fight the Patch Problem Read More »

Unpatched Fastjson Vulnerability Exploited in Attacks

Unpatched Fastjson Vulnerability Exploited in Attacks 2026-07-28 at 10:27 By Ionut Arghire The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. The post Unpatched Fastjson Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Unpatched Fastjson Vulnerability Exploited in Attacks Read More »

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day 2026-07-28 at 09:40 By Ionut Arghire Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day Read More »

LegacyHive: Hunting Windows Profile Initialization Abuse Through Offline Registry Manipulation

LegacyHive: Hunting Windows Profile Initialization Abuse Through Offline Registry Manipulation 2026-07-27 at 17:07 By Serhii Melnyk and Timmy Lister Following GreenPlasma, YellowKey and MiniPlasma, as well as RoguePlanet and GreatXML, the Nightmare-Eclipse disclosure actor has published LegacyHive, its latest Windows proof-of-concept (PoC) released shortly after Microsoft’s July 2026 Patch Tuesday. This article is an excerpt […]

LegacyHive: Hunting Windows Profile Initialization Abuse Through Offline Registry Manipulation Read More »

PTC Windchill Vulnerability Exploited in Ransomware Campaign

PTC Windchill Vulnerability Exploited in Ransomware Campaign 2026-07-27 at 16:19 By Ionut Arghire The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication. The post PTC Windchill Vulnerability Exploited in Ransomware Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

PTC Windchill Vulnerability Exploited in Ransomware Campaign Read More »

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws 2026-07-24 at 17:20 By SecurityWeek News Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion attempt. The post In Other News: Dolphin X AI-Powered Malware, […]

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws Read More »

Is Patching Dead? Vulnerability Management in the Post-Mythos Era

Is Patching Dead? Vulnerability Management in the Post-Mythos Era 2026-07-23 at 18:00 By Danelle Au You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. The post Is Patching Dead? Vulnerability Management in the Post-Mythos Era appeared first on […]

Is Patching Dead? Vulnerability Management in the Post-Mythos Era Read More »

New Check Point Zero-Day Vulnerability Exploited in the Wild

New Check Point Zero-Day Vulnerability Exploited in the Wild 2026-07-23 at 12:06 By Eduard Kovacs The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations. The post New Check Point Zero-Day Vulnerability Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

New Check Point Zero-Day Vulnerability Exploited in the Wild Read More »

Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft

Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft 2026-07-22 at 17:22 By Eduard Kovacs An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts. The post Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft appeared first on SecurityWeek. This […]

Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft Read More »

Vibe-Coded Apps Riddled With Exploitable Security Flaws

Vibe-Coded Apps Riddled With Exploitable Security Flaws 2026-07-22 at 16:00 By Kevin Townsend Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues. The post Vibe-Coded Apps Riddled With Exploitable Security Flaws appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Vibe-Coded Apps Riddled With Exploitable Security Flaws Read More »

Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks

Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks 2026-07-22 at 14:29 By Eduard Kovacs CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access. The post Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Read More »

Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates

Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates 2026-07-22 at 12:33 By Eduard Kovacs Many of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI. The post Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Read More »

Scroll to Top