vulnerability

Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate

Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate 2026-05-27 at 17:30 By Eduard Kovacs Novee researchers discovered an account takeover vulnerability in the open source CFP management tool Pretalx. The post Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate appeared first on SecurityWeek. This article is an […]

Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate Read More »

Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment

Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment 2026-05-26 at 17:32 By Ionut Arghire Hardcoded machineKey values in a configuration file enabled ViewState deserialization attacks leading to remote code execution. The post Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment Read More »

High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659)

High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659) 2026-05-26 at 13:56 By Zeljka Zorz Microsoft has released patches for a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint that may be exploited in low-complexity attacks. It affects the SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. About CVE-2026-45659 CVE-2026-45659 stems from […]

High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659) Read More »

Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images

Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images 2026-05-26 at 13:56 By Mike Lennon DockSec, an OWASP incubator project, correlates findings from multiple container security scanners and uses AI to generate plain-English remediation guidance and exact Dockerfile fixes. The post Open Source DockSec Uses AI to Cut Through Vulnerability Noise […]

Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images Read More »

Ghost CMS Vulnerability Exploited to Hack Over 700 Websites

Ghost CMS Vulnerability Exploited to Hack Over 700 Websites 2026-05-25 at 16:59 By Eduard Kovacs Sites belonging to major universities such as Harvard and Oxford, as well as DuckDuckGo, have been compromised in the attack. The post Ghost CMS Vulnerability Exploited to Hack Over 700 Websites appeared first on SecurityWeek. This article is an excerpt […]

Ghost CMS Vulnerability Exploited to Hack Over 700 Websites Read More »

Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects

Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects 2026-05-25 at 13:58 By Eduard Kovacs Many findings have been confirmed to be critical or high-severity vulnerabilities and the number will continue to increase.  The post Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects appeared first on SecurityWeek. This article is an excerpt […]

Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects Read More »

‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains

‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains 2026-05-23 at 14:04 By Ionut Arghire The stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic. The post ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains appeared first on SecurityWeek. This article is […]

‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains Read More »

TrendAI Patches Apex One Zero-Day Exploited in the Wild

TrendAI Patches Apex One Zero-Day Exploited in the Wild 2026-05-22 at 11:53 By Eduard Kovacs CVE-2026-34926 is a directory traversal flaw that can be exploited against the on-premise version of Apex One. The post TrendAI Patches Apex One Zero-Day Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

TrendAI Patches Apex One Zero-Day Exploited in the Wild Read More »

Cisco Patches Critical Vulnerability in Secure Workload

Cisco Patches Critical Vulnerability in Secure Workload 2026-05-21 at 15:24 By Ionut Arghire Insufficient validation and authentication in the Secure Workload’s REST APIs provide remote attackers with Site Admin privileges. The post Cisco Patches Critical Vulnerability in Secure Workload appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cisco Patches Critical Vulnerability in Secure Workload Read More »

Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498)

Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498) 2026-05-21 at 14:22 By Zeljka Zorz Attackers are exploiting two Microsoft Defender vulnerabilities (CVE-2026-41091 and CVE-2026-45498), Microsoft acknowledged and CISA confirmed by adding them to its Known Exploited Vulnerabilities catalog. The vulnerabilities CVE-2026-41091 allows for local privilege elevation (LPE), and is caused by the Microsoft Malware […]

Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498) Read More »

Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking

Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking 2026-05-21 at 14:22 By Eduard Kovacs CVE-2026-9082 can be exploited without authentication for information disclosure, privilege escalation, and remote code execution. The post Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking Read More »

Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI

Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI 2026-05-21 at 13:14 By Eduard Kovacs More than 200 vulnerabilities patched in recent Chrome releases are marked as ‘reported by Google’. The post Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI Read More »

Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility

Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility 2026-05-21 at 11:40 By Kevin Townsend New vulnerabilities are being discovered too fast, the time-to-exploitation is too short, and our visibility into them is largely lacking. The post Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility appeared first on SecurityWeek. This article is […]

Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility Read More »

Anthropic Silently Patches Claude Code Sandbox Bypass

Anthropic Silently Patches Claude Code Sandbox Bypass 2026-05-20 at 16:04 By Eduard Kovacs The researcher who found it says the vulnerability could have been chained with a prompt injection to exfiltrate data. The post Anthropic Silently Patches Claude Code Sandbox Bypass appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Anthropic Silently Patches Claude Code Sandbox Bypass Read More »

Drupal to Patch Highly Critical Vulnerability at Risk of Quick Exploitation

Drupal to Patch Highly Critical Vulnerability at Risk of Quick Exploitation 2026-05-19 at 21:14 By Eduard Kovacs Drupal says attackers may develop an exploit for the vulnerability within hours or days. The post Drupal to Patch Highly Critical Vulnerability at Risk of Quick Exploitation appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Drupal to Patch Highly Critical Vulnerability at Risk of Quick Exploitation Read More »

Unpatched ChromaDB Vulnerability Can Lead to Server Takeover

Unpatched ChromaDB Vulnerability Can Lead to Server Takeover 2026-05-19 at 16:58 By Ionut Arghire The security defect can be exploited remotely, without authentication, to execute arbitrary code and leak sensitive information. The post Unpatched ChromaDB Vulnerability Can Lead to Server Takeover appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Unpatched ChromaDB Vulnerability Can Lead to Server Takeover Read More »

PoC Released for DirtyDecrypt Linux Kernel Vulnerability

PoC Released for DirtyDecrypt Linux Kernel Vulnerability 2026-05-19 at 12:47 By Ionut Arghire Patched in April, the underlying vulnerability allows local attackers to elevate their privileges to root. The post PoC Released for DirtyDecrypt Linux Kernel Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

PoC Released for DirtyDecrypt Linux Kernel Vulnerability Read More »

Critical Vulnerability Exposes Industrial Robot Fleets to Hacking

Critical Vulnerability Exposes Industrial Robot Fleets to Hacking 2026-05-19 at 09:34 By Eduard Kovacs The vulnerability, CVE-2026-8153, affects Universal Robots PolyScope 5 and it can be exploited for OS command injection.  The post Critical Vulnerability Exposes Industrial Robot Fleets to Hacking appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Vulnerability Exposes Industrial Robot Fleets to Hacking Read More »

Attackers are exploiting critical NGINX vulnerability (CVE-2026-42945)

Attackers are exploiting critical NGINX vulnerability (CVE-2026-42945) 2026-05-18 at 16:32 By Zeljka Zorz A critical NGINX vulnerability (CVE-2026-42945) disclosed last week is being exploited by attackers, VulnCheck security researcher Patrick Garrity revealed on Saturday. The vulnerability, dubbed NGINX Rift, can be reliably exploited to trigger a denial-of-service condition and can potentially allow for unauthenticated remote […]

Attackers are exploiting critical NGINX vulnerability (CVE-2026-42945) Read More »

‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery

‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery 2026-05-18 at 15:48 By Ionut Arghire Four vulnerabilities in OpenClaw can be chained together to steal credentials, escape the sandbox, and plant persistent backdoors. The post ‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery Read More »

Scroll to Top