vulnerability

AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code

AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code 2026-09-18 at 15:45 By Eduard Kovacs Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts.  The post AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code Read More »

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products 2026-09-18 at 13:57 By Eduard Kovacs Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority. The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products Read More »

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched 2026-09-18 at 11:49 By Sinisa Markovic Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach into a company’s systems and data as the […]

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched Read More »

Critical Orkes Conductor Vulnerability Exploited in Attacks

Critical Orkes Conductor Vulnerability Exploited in Attacks 2026-09-18 at 11:42 By Ionut Arghire CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Orkes Conductor Vulnerability Exploited in Attacks Read More »

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities 2026-09-18 at 10:14 By Eduard Kovacs Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges. The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities Read More »

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot 2026-09-17 at 17:28 By Eduard Kovacs The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk. The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot Read More »

ISC Patches 14 Vulnerabilities in BIND 9 Security Update

ISC Patches 14 Vulnerabilities in BIND 9 Security Update 2026-09-17 at 15:39 By Ionut Arghire Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process. The post ISC Patches 14 Vulnerabilities in BIND 9 Security Update appeared first on SecurityWeek. This article is an excerpt from […]

ISC Patches 14 Vulnerabilities in BIND 9 Security Update Read More »

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard 2026-09-17 at 15:17 By Ionut Arghire The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution.   The post Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard appeared first on SecurityWeek. This article is an excerpt […]

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard Read More »

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day 2026-09-17 at 09:19 By Ionut Arghire Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day Read More »

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover 2026-09-16 at 14:32 By Ionut Arghire Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities. The post Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover Read More »

Chrome, Firefox Updates Patch 115 Vulnerabilities

Chrome, Firefox Updates Patch 115 Vulnerabilities 2026-09-16 at 13:28 By Ionut Arghire Google resolved 42 security defects in Chrome, and Mozilla fixed 73 bugs in Firefox. The post Chrome, Firefox Updates Patch 115 Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome, Firefox Updates Patch 115 Vulnerabilities Read More »

Enterprises Warned of Attacks Exploiting WSO2 Vulnerability

Enterprises Warned of Attacks Exploiting WSO2 Vulnerability 2026-09-16 at 11:39 By Eduard Kovacs The vulnerability, tracked as CVE-2026-5430, can be exploited to gain access to valuable enterprise data. The post Enterprises Warned of Attacks Exploiting WSO2 Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Enterprises Warned of Attacks Exploiting WSO2 Vulnerability Read More »

Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

Oracle Patches 800+ Vulnerabilities in September 2026 Security Update 2026-09-16 at 11:06 By Ionut Arghire The security updates resolve over 800 vulnerabilities across 17 product families, including over 100 critical-severity flaws. The post Oracle Patches 800+ Vulnerabilities in September 2026 Security Update appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Oracle Patches 800+ Vulnerabilities in September 2026 Security Update Read More »

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases 

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases  2026-09-15 at 14:06 By Ionut Arghire The updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks. The post Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases  appeared first on […]

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases  Read More »

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation 2026-09-15 at 08:18 By Eduard Kovacs An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges. The post Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation appeared first on SecurityWeek. This article is an […]

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation Read More »

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution 2026-09-14 at 14:51 By Ionut Arghire The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely. The post Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution appeared first on SecurityWeek. This article is an excerpt from […]

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution Read More »

Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

Three JFrog Artifactory Flaws Exploited for Backdoor Deployment 2026-09-14 at 12:27 By Ionut Arghire The vulnerabilities can allow attackers to bypass authentication and elevate their privileges to administrator. The post Three JFrog Artifactory Flaws Exploited for Backdoor Deployment appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Three JFrog Artifactory Flaws Exploited for Backdoor Deployment Read More »

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks 2026-09-14 at 11:25 By Ionut Arghire The flaw allows attackers to send files and execute them without authorization through an active remote session. The post ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks Read More »

GitLab Vulnerability Exploited One Day After Disclosure

GitLab Vulnerability Exploited One Day After Disclosure 2026-09-11 at 19:11 By Ionut Arghire The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

GitLab Vulnerability Exploited One Day After Disclosure Read More »

Check Point Patches Critical VPN Vulnerabilities

Check Point Patches Critical VPN Vulnerabilities 2026-09-11 at 14:10 By Ionut Arghire Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Check Point Patches Critical VPN Vulnerabilities Read More »

Scroll to Top