Vulnerabilities

Exploitarium: Inside the Archive Behind the Mass 0-Day Drop

Exploitarium: Inside the Archive Behind the Mass 0-Day Drop 2026-07-21 at 16:23 By Serhii Melnyk Coordinated vulnerability disclosures operate on a straightforward premise: the affected vendor is notified first, given a defined window to remediate, and public disclosure follows. This article is an excerpt from LevelBlue SpiderLabs Blog View Original Source

Exploitarium: Inside the Archive Behind the Mass 0-Day Drop Read More »

Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data

Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data 2026-07-21 at 13:19 By Eduard Kovacs A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure. The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Read More »

Exploitation of ServiceNow Vulnerability Seen Days After Disclosure

Exploitation of ServiceNow Vulnerability Seen Days After Disclosure 2026-07-21 at 11:41 By Eduard Kovacs The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution. The post Exploitation of ServiceNow Vulnerability Seen Days After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Exploitation of ServiceNow Vulnerability Seen Days After Disclosure Read More »

Zimbra Update Patches Critical Vulnerabilities

Zimbra Update Patches Critical Vulnerabilities 2026-07-21 at 11:20 By Ionut Arghire The latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects. The post Zimbra Update Patches Critical Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Zimbra Update Patches Critical Vulnerabilities Read More »

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch 2026-07-20 at 17:11 By Eduard Kovacs The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek. This article is an excerpt […]

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch Read More »

LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC

LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC 2026-07-20 at 15:35 By Pauline Bolaños Vexed researcher Nightmare-Eclipse (aka Chaotic Eclipse, Dead Eclipse, and MSNightmare) released his ninth unpatched Windows vulnerability called LegacyHive. This latest bug drop is a Local Privilege Escalation (LPE) vulnerability affecting Windows User Profile, a component responsible for loading and unloading […]

LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC Read More »

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability 2026-07-20 at 15:32 By Ionut Arghire Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Read More »

Chrome 150 Update Patches Severe Memory Safety Bugs

Chrome 150 Update Patches Severe Memory Safety Bugs 2026-07-20 at 11:12 By Ionut Arghire The fresh security update resolves six critical and high-severity use-after-free vulnerabilities. The post Chrome 150 Update Patches Severe Memory Safety Bugs appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome 150 Update Patches Severe Memory Safety Bugs Read More »

WP2Shell WordPress Vulnerabilities Exploited in the Wild

WP2Shell WordPress Vulnerabilities Exploited in the Wild 2026-07-20 at 08:21 By Eduard Kovacs Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure. The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

WP2Shell WordPress Vulnerabilities Exploited in the Wild Read More »

Fresh SharePoint Vulnerability Exploited Soon After Disclosure

Fresh SharePoint Vulnerability Exploited Soon After Disclosure 2026-07-17 at 10:15 By Ionut Arghire The critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server. The post Fresh SharePoint Vulnerability Exploited Soon After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Fresh SharePoint Vulnerability Exploited Soon After Disclosure Read More »

The Cybersecurity Homework You Can’t Skip

The Cybersecurity Homework You Can’t Skip 2026-07-16 at 19:08 By Summer might mean slightly fewer meetings, lighter inboxes, and the illusion of breathing room (in a perfect world), but we all know that attackers don’t take vacations, so neither should the fundamentals that keep your organization secure. If anything, now is the perfect time to […]

The Cybersecurity Homework You Can’t Skip Read More »

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites 2026-07-16 at 16:43 By Rodel Mendrez You’re browsing a legitimate small business website. Before the page loads, a familiar Cloudflare box appears: “Verify you are human.” It asks you to open Terminal, paste a code, and press Enter. You’ve seen this before. You follow the steps. […]

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites Read More »

AI Data Centers Are Being Built Faster Than They Can Be Secured

AI Data Centers Are Being Built Faster Than They Can Be Secured 2026-07-16 at 16:00 By Kevin Townsend AI infrastructure introduces new security risks that traditional data center designs were never built to handle. The post AI Data Centers Are Being Built Faster Than They Can Be Secured appeared first on SecurityWeek. This article is […]

AI Data Centers Are Being Built Faster Than They Can Be Secured Read More »

Splunk, Zoom Patch Critical Vulnerabilities

Splunk, Zoom Patch Critical Vulnerabilities 2026-07-16 at 13:54 By Ionut Arghire The flaws could allow attackers to access credentials and data, take over accounts, and escalate their privileges. The post Splunk, Zoom Patch Critical Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Splunk, Zoom Patch Critical Vulnerabilities Read More »

F5 Patches Multiple NGINX, BIG-IP Vulnerabilities

F5 Patches Multiple NGINX, BIG-IP Vulnerabilities 2026-07-16 at 12:20 By Ionut Arghire Attackers could exploit the bugs to modify configurations, terminate or restart processes, cross security boundaries, leak memory, and execute code. The post F5 Patches Multiple NGINX, BIG-IP Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

F5 Patches Multiple NGINX, BIG-IP Vulnerabilities Read More »

Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day 

Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day  2026-07-16 at 09:48 By Ionut Arghire The researcher stripped the proof-of-concept (PoC) exploit to prevent immediate exploitation of the vulnerability. The post Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day  Read More »

Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities

Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities 2026-07-16 at 09:08 By Eduard Kovacs The cybersecurity companies patched critical and high-severity vulnerabilities in some of their products. The post Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities Read More »

Unpatched Cursor Vulnerability Exposes Users to Code Execution

Unpatched Cursor Vulnerability Exposes Users to Code Execution 2026-07-15 at 17:37 By Ionut Arghire An attacker can create a malicious repository containing a git.exe in the project root, and Cursor executes it automatically. The post Unpatched Cursor Vulnerability Exposes Users to Code Execution appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Unpatched Cursor Vulnerability Exposes Users to Code Execution Read More »

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities 2026-07-15 at 17:07 By Ionut Arghire Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days. The post CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities Read More »

Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow

Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow 2026-07-15 at 14:02 By Ionut Arghire A critical security defect in the ServiceNow AI platform could allow remote attackers to execute arbitrary code. The post Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow Read More »

Scroll to Top