vulnerability

‘By Design’ Flaw in MCP Could Enable Widespread AI Supply Chain Attacks

‘By Design’ Flaw in MCP Could Enable Widespread AI Supply Chain Attacks 2026-04-15 at 16:34 By Kevin Townsend Researchers warn that a flaw in Anthropic’s Model Context Protocol allows unsanitized commands to execute silently, enabling full system compromise across widely used AI environments. The post ‘By Design’ Flaw in MCP Could Enable Widespread AI Supply […]

‘By Design’ Flaw in MCP Could Enable Widespread AI Supply Chain Attacks Read More »

Two Vulnerabilities Patched in Ivanti Neurons for ITSM 

Two Vulnerabilities Patched in Ivanti Neurons for ITSM  2026-04-15 at 16:07 By Ionut Arghire The flaws could allow a remote attacker to maintain access after their account has been disabled and to access information from other user sessions. The post Two Vulnerabilities Patched in Ivanti Neurons for ITSM  appeared first on SecurityWeek. This article is

Two Vulnerabilities Patched in Ivanti Neurons for ITSM  Read More »

Fortinet Patches Critical FortiSandbox Vulnerabilities

Fortinet Patches Critical FortiSandbox Vulnerabilities 2026-04-15 at 14:29 By Ionut Arghire The flaws could allow attackers to bypass authentication or execute arbitrary code or commands via HTTP requests. The post Fortinet Patches Critical FortiSandbox Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Fortinet Patches Critical FortiSandbox Vulnerabilities Read More »

Juniper Networks Patches Dozens of Junos OS Vulnerabilities

Juniper Networks Patches Dozens of Junos OS Vulnerabilities 2026-04-10 at 17:22 By Ionut Arghire A critical-severity flaw could be exploited remotely, without authentication, to take over a vulnerable device. The post Juniper Networks Patches Dozens of Junos OS Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Juniper Networks Patches Dozens of Junos OS Vulnerabilities Read More »

Orthanc DICOM Vulnerabilities Lead to Crashes, RCE

Orthanc DICOM Vulnerabilities Lead to Crashes, RCE 2026-04-10 at 15:05 By Ionut Arghire Attackers could exploit these vulnerabilities in denial-of-service, information disclosure, and arbitrary code execution attacks. The post Orthanc DICOM Vulnerabilities Lead to Crashes, RCE appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Orthanc DICOM Vulnerabilities Lead to Crashes, RCE Read More »

Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000

Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000 2026-04-10 at 14:45 By Eduard Kovacs The critical vulnerabilities affect Chrome’s WebML component and they have been reported by anonymous researchers. The post Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000 appeared first on SecurityWeek. This article is an excerpt from

Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000 Read More »

Critical Marimo Flaw Exploited Hours After Public Disclosure

Critical Marimo Flaw Exploited Hours After Public Disclosure 2026-04-10 at 14:45 By Ionut Arghire Within nine hours, a hacker built an exploit from the unauthenticated bug’s advisory and started using it in the wild. The post Critical Marimo Flaw Exploited Hours After Public Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Critical Marimo Flaw Exploited Hours After Public Disclosure Read More »

Microsoft Finds Vulnerability Exposing Millions of Android Crypto Wallet Users

Microsoft Finds Vulnerability Exposing Millions of Android Crypto Wallet Users 2026-04-10 at 10:37 By Eduard Kovacs The security hole affected an EngageLab SDK and it was reported by Microsoft to the vendor one year ago. The post Microsoft Finds Vulnerability Exposing Millions of Android Crypto Wallet Users appeared first on SecurityWeek. This article is an

Microsoft Finds Vulnerability Exposing Millions of Android Crypto Wallet Users Read More »

Claude helps researcher dig up decade-old Apache ActiveMQ RCE vulnerability (CVE-2026-34197)

Claude helps researcher dig up decade-old Apache ActiveMQ RCE vulnerability (CVE-2026-34197) 2026-04-09 at 16:17 By Zeljka Zorz In the latest demonstration of how AI assistants can help with bug hunting, Horizon3.ai researcher Naveen Sunkavally used Claude to unearth CVE-2026-34197, a remote code execution vulnerability in Apache ActiveMQ that’s been introduced in the codebase 13 years

Claude helps researcher dig up decade-old Apache ActiveMQ RCE vulnerability (CVE-2026-34197) Read More »

Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities

Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities 2026-04-09 at 15:44 By Ionut Arghire The bugs could allow attackers to modify protected resources and escalate their privileges to administrator. The post Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities Read More »

The Week in Vulnerabilities: OpenClaw, FreeBSD, F5 BIG-IP, and Critical ICS Bugs

The Week in Vulnerabilities: OpenClaw, FreeBSD, F5 BIG-IP, and Critical ICS Bugs 2026-04-09 at 14:24 By Mihir Bagwe Cyble Research & Intelligence Labs (CRIL) weekly vulnerability report tracked 1,960 vulnerabilities last week, reflecting a continued surge in vulnerability disclosures across enterprise and cloud ecosystems. Of these, 248 vulnerabilities have publicly available Proof-of-Concept (PoC) exploits, significantly

The Week in Vulnerabilities: OpenClaw, FreeBSD, F5 BIG-IP, and Critical ICS Bugs Read More »

Adobe Reader Zero-Day Exploited for Months: Researcher

Adobe Reader Zero-Day Exploited for Months: Researcher 2026-04-09 at 12:00 By Eduard Kovacs Reputable researcher Haifei Li has come across what appears to be a PDF designed to exploit an unpatched vulnerability. The post Adobe Reader Zero-Day Exploited for Months: Researcher appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Adobe Reader Zero-Day Exploited for Months: Researcher Read More »

Data Leakage Vulnerability Patched in OpenSSL

Data Leakage Vulnerability Patched in OpenSSL 2026-04-08 at 18:47 By Eduard Kovacs A total of seven vulnerabilities, most of which can be exploited for DoS attacks, have been patched in OpenSSL. The post Data Leakage Vulnerability Patched in OpenSSL appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Data Leakage Vulnerability Patched in OpenSSL Read More »

RCE Bug Lurked in Apache ActiveMQ Classic for 13 Years

RCE Bug Lurked in Apache ActiveMQ Classic for 13 Years 2026-04-08 at 17:32 By Ionut Arghire The vulnerability requires authentication for successful exploitation, but another flaw exposes the Jolokia API without authentication. The post RCE Bug Lurked in Apache ActiveMQ Classic for 13 Years appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

RCE Bug Lurked in Apache ActiveMQ Classic for 13 Years Read More »

Anthropic’s new AI model finds and exploits zero-days across every major OS and browser

Anthropic’s new AI model finds and exploits zero-days across every major OS and browser 2026-04-08 at 08:12 By Anamarija Pogorelec Automated vulnerability discovery tools have existed for decades, and the gap between finding a bug and building a working exploit has always slowed attackers. That gap is now substantially narrower. Anthropic’s Claude Mythos Preview, a

Anthropic’s new AI model finds and exploits zero-days across every major OS and browser Read More »

Severe StrongBox Vulnerability Patched in Android

Severe StrongBox Vulnerability Patched in Android 2026-04-07 at 20:31 By Eduard Kovacs A critical DoS vulnerability in the Framework component of Android has also been fixed with the latest update. The post Severe StrongBox Vulnerability Patched in Android appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Severe StrongBox Vulnerability Patched in Android Read More »

Critical Flowise Vulnerability in Attacker Crosshairs

Critical Flowise Vulnerability in Attacker Crosshairs 2026-04-07 at 18:34 By Ionut Arghire The improper validation of user-supplied JavaScript code allows attackers to execute arbitrary code and access the file system. The post Critical Flowise Vulnerability in Attacker Crosshairs appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Flowise Vulnerability in Attacker Crosshairs Read More »

Fortinet Rushes Emergency Fixes for Exploited Zero-Day

Fortinet Rushes Emergency Fixes for Exploited Zero-Day 2026-04-06 at 12:42 By Ionut Arghire The improper access control bug in FortiClient EMS allows unauthenticated attackers to execute arbitrary code remotely. The post Fortinet Rushes Emergency Fixes for Exploited Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Fortinet Rushes Emergency Fixes for Exploited Zero-Day Read More »

Cisco IMC auth bypass vulnerability allows attackers to alter user passwords (CVE-2026-20093)

Cisco IMC auth bypass vulnerability allows attackers to alter user passwords (CVE-2026-20093) 2026-04-03 at 17:52 By Zeljka Zorz Cisco has fixed ten vulnerabilities affecting its Integrated Management Controller (IMC), the most critical of which (CVE-2026-20093) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. Cisco ICM riddled

Cisco IMC auth bypass vulnerability allows attackers to alter user passwords (CVE-2026-20093) Read More »

Scroll to Top