vulnerability

Emphere Raises $2.1 Million for AI-Powered Vulnerability Remediation

Emphere Raises $2.1 Million for AI-Powered Vulnerability Remediation 2026-06-07 at 18:57 By Ionut Arghire Emphere’s solution delivers AI-driven remediation to software companies to speed up releases. The post Emphere Raises $2.1 Million for AI-Powered Vulnerability Remediation appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Emphere Raises $2.1 Million for AI-Powered Vulnerability Remediation Read More »

Gemini Voice Assistant Hijacked via Messaging Notifications

Gemini Voice Assistant Hijacked via Messaging Notifications 2026-06-04 at 16:06 By Eduard Kovacs Attackers could have triggered dangerous actions, including controlling smart home devices via Google Home and starting Zoom video calls. The post Gemini Voice Assistant Hijacked via Messaging Notifications appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Gemini Voice Assistant Hijacked via Messaging Notifications Read More »

Mirasvit Vulnerability Exploited to Execute Code on Magento Servers

Mirasvit Vulnerability Exploited to Execute Code on Magento Servers 2026-06-04 at 16:06 By Ionut Arghire A flaw in the Full Page Cache Warmer extension can be exploited without authentication via serialized PHP object payloads. The post Mirasvit Vulnerability Exploited to Execute Code on Magento Servers appeared first on SecurityWeek. This article is an excerpt from […]

Mirasvit Vulnerability Exploited to Execute Code on Magento Servers Read More »

Cisco Warns of Available PoC for Critical Unified CM Vulnerability

Cisco Warns of Available PoC for Critical Unified CM Vulnerability 2026-06-04 at 13:16 By Ionut Arghire The high-severity flaw can be exploited remotely, without authentication, in server-side request forgery (SSRF) attacks. The post Cisco Warns of Available PoC for Critical Unified CM Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Cisco Warns of Available PoC for Critical Unified CM Vulnerability Read More »

VS Code Vulnerability Allows One-Click GitHub Token Theft

VS Code Vulnerability Allows One-Click GitHub Token Theft 2026-06-04 at 13:16 By Eduard Kovacs A researcher has disclosed the full details of the vulnerability and released a PoC without notifying Microsoft in advance. The post VS Code Vulnerability Allows One-Click GitHub Token Theft appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

VS Code Vulnerability Allows One-Click GitHub Token Theft Read More »

‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds

‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds 2026-06-03 at 13:52 By Ionut Arghire The default HTTP/2 configuration of major web servers is vulnerable to an attack chain combining a compression bomb and a Slowloris-style hold. The post ‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds appeared first on SecurityWeek. This article is […]

‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds Read More »

Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk

Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk 2026-06-02 at 18:01 By Kevin Townsend A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations. The post Exclusive: How One Line of Code Put Billions of Microsoft Android […]

Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk Read More »

Oracle WebLogic Vulnerability Exploited in the Wild

Oracle WebLogic Vulnerability Exploited in the Wild 2026-06-02 at 15:46 By Eduard Kovacs The vulnerability is CVE-2024-21182 and it can be exploited without authentication to hack affected WebLogic servers. The post Oracle WebLogic Vulnerability Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Oracle WebLogic Vulnerability Exploited in the Wild Read More »

Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches

Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches 2026-06-02 at 15:25 By Ionut Arghire A stack-based buffer overflow bug can be exploited for remote code execution on a vulnerable device. The post Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches Read More »

Google fixes actively exploited Android vulnerability (CVE-2025-48595)

Google fixes actively exploited Android vulnerability (CVE-2025-48595) 2026-06-02 at 15:17 By Zeljka Zorz Google has announced the June 2026 Android security updates, which fix a bucketload of vulnerabilities, including a high-severity vulnerability (CVE-2025-48595) in the Android Framework that “may be under limited, targeted exploitation.” About CVE-2025-48595 CVE-2025-48595 is an integer overflow vulnerability in the Android […]

Google fixes actively exploited Android vulnerability (CVE-2025-48595) Read More »

Oracle’s First Monthly Patches Resolve 77 Vulnerabilities

Oracle’s First Monthly Patches Resolve 77 Vulnerabilities 2026-06-02 at 10:58 By Ionut Arghire Oracle’s monthly Critical Security Patch Update (CSPU) rollouts are meant to deliver critical fixes faster. The post Oracle’s First Monthly Patches Resolve 77 Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Oracle’s First Monthly Patches Resolve 77 Vulnerabilities Read More »

Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs

Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs 2026-06-01 at 20:16 By Ionut Arghire Organizations are advised to patch CVE-2026-41089 as soon as possible, given its severity, the potential ongoing exploitation. The post Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs Read More »

Recent Palo Alto Networks Vulnerability Exploited for Weeks

Recent Palo Alto Networks Vulnerability Exploited for Weeks 2026-06-01 at 17:37 By Ionut Arghire Hackers began exploiting CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS, four days after public disclosure. The post Recent Palo Alto Networks Vulnerability Exploited for Weeks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Recent Palo Alto Networks Vulnerability Exploited for Weeks Read More »

Windows Netlogon RCE exploited, domain controllers at risk (CVE-2026-41089)

Windows Netlogon RCE exploited, domain controllers at risk (CVE-2026-41089) 2026-06-01 at 17:17 By Zeljka Zorz CVE-2026-41089, a critical Windows Netlogon RCE flaw that allows remote code execution, is now actively exploited in the wild, the Centre for Cybersecurity Belgium (CCB) warned on Friday. About CVE-2026-41089 CVE-2026-41089 is a stack-based buffer overflow vulnerability in Windows Netlogon, […]

Windows Netlogon RCE exploited, domain controllers at risk (CVE-2026-41089) Read More »

Exploit Code Published for Critical Flowise RCE Vulnerability

Exploit Code Published for Critical Flowise RCE Vulnerability 2026-05-30 at 18:55 By Ionut Arghire The one-click vulnerability allows attackers to execute arbitrary code on self-hosted Flowise servers by tricking users into importing a malicious chatflow. The post Exploit Code Published for Critical Flowise RCE Vulnerability appeared first on SecurityWeek. This article is an excerpt from […]

Exploit Code Published for Critical Flowise RCE Vulnerability Read More »

New infostealer reaches enterprise devices through FortiClient EMS vulnerability

New infostealer reaches enterprise devices through FortiClient EMS vulnerability 2026-05-29 at 18:31 By Zeljka Zorz Attackers are delivering a broad-spectrum infostealer to enterprise computers by exploiting a known vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS). “The [malicious] payload was presented as a Fortinet endpoint update and executed through FortiClient-managed VPN scripting workflows,” Arctic Wold […]

New infostealer reaches enterprise devices through FortiClient EMS vulnerability Read More »

Zapier exploit chain shows how known anti-patterns compose into critical risk

Zapier exploit chain shows how known anti-patterns compose into critical risk 2026-05-28 at 16:00 By Mirko Zorz A five-stage exploit chain disclosed by Token Security researchers turned a free Zapier account into write access on Zapier’s public developer SDK packages and on internal packages that load in every authenticated zapier.com session. Each link in the […]

Zapier exploit chain shows how known anti-patterns compose into critical risk Read More »

Scroll to Top