vulnerability

200 accounts compromised in Swiss government’s Microsoft SharePoint breach

200 accounts compromised in Swiss government’s Microsoft SharePoint breach 2026-08-07 at 15:29 By Sinisa Markovic Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT), compromising the login credentials of around 200 accounts. On July 28, BIT’s security specialists noticed unusual activity on the SharePoint servers. […]

200 accounts compromised in Swiss government’s Microsoft SharePoint breach Read More »

Microsoft, Apple Release Fresh Security Updates

Microsoft, Apple Release Fresh Security Updates 2026-08-07 at 12:09 By Ionut Arghire Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass. The post Microsoft, Apple Release Fresh Security Updates appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft, Apple Release Fresh Security Updates Read More »

Critical Vulnerabilities Patched With Chrome 151 Update

Critical Vulnerabilities Patched With Chrome 151 Update 2026-08-07 at 09:56 By Ionut Arghire The browser refresh eliminates over two dozen memory safety bugs, including critical use-after-free flaws. The post Critical Vulnerabilities Patched With Chrome 151 Update appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Vulnerabilities Patched With Chrome 151 Update Read More »

Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts

Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts 2026-08-06 at 15:54 By Eduard Kovacs Zenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched. The post Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts appeared first

Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts Read More »

Critical Paperclip Flaw Allowed Admin Access, Code Execution

Critical Paperclip Flaw Allowed Admin Access, Code Execution 2026-08-06 at 14:09 By Ionut Arghire An attacker could self-register, sign in for board-level API access, and import a new company for code execution. The post Critical Paperclip Flaw Allowed Admin Access, Code Execution appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Critical Paperclip Flaw Allowed Admin Access, Code Execution Read More »

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones 

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones  2026-08-05 at 22:40 By Eduard Kovacs The chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications. The post How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones  Read More »

CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities

CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities 2026-08-05 at 12:44 By Ionut Arghire The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass. The post CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities Read More »

15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic

15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic 2026-08-05 at 12:35 By Mirko Zorz TP-Link prints the serial number of an Omada router on its packaging and on a label attached to the device. Those numbers run in sequence, and feeding a guessed one to the Omada cloud service returns the

15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic Read More »

TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover

TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover 2026-08-04 at 15:00 By Eduard Kovacs Forescout researchers have found 15 new vulnerabilities in the TP-Link Omada networking ecosystem. The post TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover Read More »

Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering 2026-08-04 at 13:54 By Ionut Arghire A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent. The post Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering appeared first on SecurityWeek. This

Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering Read More »

Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks 2026-08-04 at 12:56 By Ionut Arghire Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login. The post Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks Read More »

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers 2026-08-04 at 08:18 By Eduard Kovacs The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000. The post Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers appeared first on SecurityWeek. This article is an excerpt

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers Read More »

Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)

Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577) 2026-08-03 at 17:33 By Zeljka Zorz Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) solution widely used by managed service providers, to gain access to managed endpoints. How the flaw was discovered “On July 31, 2026,

Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577) Read More »

Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers

Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers 2026-08-03 at 16:51 By Sinisa Markovic A Chinese threat actor operating under the aliases “knaithe” and “KnYuan” used multiple LLMs to automate cyberattacks against internet-facing systems with limited human intervention. Researchers at Palo Alto Networks’ Unit 42 uncovered the operation after the threat actor’s

Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers Read More »

N‑able Patches Vulnerability Exploited to Hack N-central Servers

N‑able Patches Vulnerability Exploited to Hack N-central Servers 2026-08-03 at 15:34 By Eduard Kovacs The N‑central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass. The post N‑able Patches Vulnerability Exploited to Hack N-central Servers appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

N‑able Patches Vulnerability Exploited to Hack N-central Servers Read More »

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066) 2026-08-03 at 14:42 By Zeljka Zorz A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web apps, may allow attackers to read sensitive files off a server and, in some cases, take full control of

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066) Read More »

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks 2026-08-03 at 13:39 By Ionut Arghire The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement. The post Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks Read More »

Ruby on Rails Patches Critical Vulnerability

Ruby on Rails Patches Critical Vulnerability 2026-08-01 at 14:15 By Ionut Arghire The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Ruby on Rails Patches Critical Vulnerability Read More »

Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace

Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace 2026-07-31 at 13:28 By Ionut Arghire The internet giant has built an agent harness to find vulnerabilities across Chrome’s codebase. The post Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace Read More »

Critical Code Execution Vulnerability Patched in TeamCity 

Critical Code Execution Vulnerability Patched in TeamCity  2026-07-31 at 09:50 By Ionut Arghire Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol. The post Critical Code Execution Vulnerability Patched in TeamCity  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Code Execution Vulnerability Patched in TeamCity  Read More »

Scroll to Top