vulnerability

TrueConf Zero-Day Exploited in Asian Government Attacks

TrueConf Zero-Day Exploited in Asian Government Attacks 2026-04-03 at 17:52 By Ionut Arghire A Chinese threat actor exploited the video conferencing platform to perform reconnaissance, escalate privileges, and execute additional payloads. The post TrueConf Zero-Day Exploited in Asian Government Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

TrueConf Zero-Day Exploited in Asian Government Attacks Read More »

Critical ShareFile Flaws Lead to Unauthenticated RCE

Critical ShareFile Flaws Lead to Unauthenticated RCE 2026-04-03 at 17:52 By Ionut Arghire The vulnerabilities can be chained together to bypass authentication and upload arbitrary files to the server. The post Critical ShareFile Flaws Lead to Unauthenticated RCE appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical ShareFile Flaws Lead to Unauthenticated RCE Read More »

Critical Vulnerability in Claude Code Emerges Days After Source Leak

Critical Vulnerability in Claude Code Emerges Days After Source Leak 2026-04-02 at 21:45 By Kevin Townsend Within days of each other, Anthropic first leaked the source code to Claude Code, and then a critical vulnerability was found by Adversa AI. The post Critical Vulnerability in Claude Code Emerges Days After Source Leak appeared first on

Critical Vulnerability in Claude Code Emerges Days After Source Leak Read More »

Cisco Patches Critical and High-Severity Vulnerabilities

Cisco Patches Critical and High-Severity Vulnerabilities 2026-04-02 at 15:36 By Ionut Arghire The bugs could lead to authentication bypass, remote code execution, information disclosure, and privilege escalation. The post Cisco Patches Critical and High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cisco Patches Critical and High-Severity Vulnerabilities Read More »

The Week in Vulnerabilities: AI Frameworks, VMware, and Critical ICS Exposure

The Week in Vulnerabilities: AI Frameworks, VMware, and Critical ICS Exposure 2026-04-02 at 13:24 By Ashish Khaitan Cyble Research & Intelligence Labs (CRIL) tracked 1,452 vulnerabilities last week, reflecting the continued expansion of the global attack surface.   Of these, 222 vulnerabilities have publicly available Proof-of-Concept (PoC) exploits, significantly accelerating the likelihood of exploitation in real-world environments.   Additionally, multiple vulnerabilities surfaced across underground forums,

The Week in Vulnerabilities: AI Frameworks, VMware, and Critical ICS Exposure Read More »

CrewAI Vulnerabilities Expose Devices to Hacking

CrewAI Vulnerabilities Expose Devices to Hacking 2026-03-31 at 16:40 By Ionut Arghire Attackers can exploit the bugs through prompt injection, chaining them together to escape the sandbox and execute arbitrary code. The post CrewAI Vulnerabilities Expose Devices to Hacking appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CrewAI Vulnerabilities Expose Devices to Hacking Read More »

StrongSwan Flaw Allows Unauthenticated Attackers to Crash VPNs

StrongSwan Flaw Allows Unauthenticated Attackers to Crash VPNs 2026-03-31 at 15:43 By Ionut Arghire Remotely exploitable, the integer underflow vulnerability impacts StrongSwan releases spanning 15 years. The post StrongSwan Flaw Allows Unauthenticated Attackers to Crash VPNs appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

StrongSwan Flaw Allows Unauthenticated Attackers to Crash VPNs Read More »

Exploitation of Critical Fortinet FortiClient EMS Flaw Begins

Exploitation of Critical Fortinet FortiClient EMS Flaw Begins 2026-03-31 at 15:43 By Ionut Arghire The SQL injection vulnerability allows unauthenticated attackers to execute arbitrary code remotely, via crafted HTTP requests. The post Exploitation of Critical Fortinet FortiClient EMS Flaw Begins appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Exploitation of Critical Fortinet FortiClient EMS Flaw Begins Read More »

Critical Vulnerability in OpenAI Codex Allowed GitHub Token Compromise 

Critical Vulnerability in OpenAI Codex Allowed GitHub Token Compromise  2026-03-31 at 11:21 By Kevin Townsend Researchers found an OpenAI Codex vulnerability that could have been exploited to compromise GitHub tokens. The post Critical Vulnerability in OpenAI Codex Allowed GitHub Token Compromise  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Vulnerability in OpenAI Codex Allowed GitHub Token Compromise  Read More »

Critical Fortinet FortiClient EMS bug under active attack (CVE-2026-21643)

Critical Fortinet FortiClient EMS bug under active attack (CVE-2026-21643) 2026-03-30 at 15:37 By Zeljka Zorz A critical SQL injection vulnerability (CVE-2026-21643) in Fortinet FortiClient Endpoint Management Server (EMS), a management server for FortiClient endpoint agents on various platforms, is under active exploitation. The warning comes from Defused Cyber, which helps organizations deploy honeypots/fake assets, and

Critical Fortinet FortiClient EMS bug under active attack (CVE-2026-21643) Read More »

Exploitation of Fresh Citrix NetScaler Vulnerability Begins

Exploitation of Fresh Citrix NetScaler Vulnerability Begins 2026-03-30 at 12:32 By Ionut Arghire The critical-severity flaw leaks application memory and can be exploited to obtain authenticated administrative session IDs. The post Exploitation of Fresh Citrix NetScaler Vulnerability Begins appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Exploitation of Fresh Citrix NetScaler Vulnerability Begins Read More »

F5 BIG-IP DoS Flaw Upgraded to Critical RCE, Now Exploited in the Wild

F5 BIG-IP DoS Flaw Upgraded to Critical RCE, Now Exploited in the Wild 2026-03-30 at 10:37 By Ionut Arghire Initially disclosed as a high-severity denial-of-service (DoS), the bug was reclassified as a critical RCE issue. The post F5 BIG-IP DoS Flaw Upgraded to Critical RCE, Now Exploited in the Wild appeared first on SecurityWeek. This

F5 BIG-IP DoS Flaw Upgraded to Critical RCE, Now Exploited in the Wild Read More »

Attackers are exploiting RCE vulnerability in BIG-IP APM systems (CVE-2025-53521)

Attackers are exploiting RCE vulnerability in BIG-IP APM systems (CVE-2025-53521) 2026-03-28 at 11:30 By Zeljka Zorz A critical unauthenticated remote code execution vulnerability (CVE-2025-53521) in F5’s BIG-IP Access Policy Manager (APM) solution is under active exploitation, the US Cybersecurity and Infrastructure Security Agency warned on Friday. CISA added the flaw to its Known Exploited Vulnerabilities

Attackers are exploiting RCE vulnerability in BIG-IP APM systems (CVE-2025-53521) Read More »

TP-Link Patches High-Severity Router Vulnerabilities

TP-Link Patches High-Severity Router Vulnerabilities 2026-03-27 at 13:42 By Ionut Arghire The security defects could be used to bypass authentication, execute arbitrary commands, and decrypt configuration files. The post TP-Link Patches High-Severity Router Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

TP-Link Patches High-Severity Router Vulnerabilities Read More »

CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation

CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation 2026-03-27 at 12:43 By Zeljka Zorz The US Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-33017, a recently disclosed code injection vulnerability in Langflow, an open-source framework for building AI agents and

CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation Read More »

BIND Updates Patch High-Severity Vulnerabilities

BIND Updates Patch High-Severity Vulnerabilities 2026-03-26 at 15:52 By Ionut Arghire Specially crafted domains could be used to cause out-of-memory conditions, leading to memory leaks in the BIND resolvers. The post BIND Updates Patch High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

BIND Updates Patch High-Severity Vulnerabilities Read More »

Cisco Patches Multiple Vulnerabilities in IOS Software

Cisco Patches Multiple Vulnerabilities in IOS Software 2026-03-26 at 15:52 By Ionut Arghire The high- and medium-severity flaws could lead to denial-of-service, secure boot bypass, information disclosure, and privilege escalation. The post Cisco Patches Multiple Vulnerabilities in IOS Software appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cisco Patches Multiple Vulnerabilities in IOS Software Read More »

iOS, macOS 26.4 Roll Out With Fresh Security Patches

iOS, macOS 26.4 Roll Out With Fresh Security Patches 2026-03-25 at 18:18 By Ionut Arghire Apple released security fixes for older devices as well, in iOS 18.7.7, iPadOS 18.7.7, macOS Sequoia 15.7.5, and macOS Sonoma 14.8.5. The post iOS, macOS 26.4 Roll Out With Fresh Security Patches appeared first on SecurityWeek. This article is an

iOS, macOS 26.4 Roll Out With Fresh Security Patches Read More »

Chrome 146 Update Patches High-Severity Vulnerabilities

Chrome 146 Update Patches High-Severity Vulnerabilities 2026-03-24 at 19:53 By Ionut Arghire The software refresh fixes eight memory safety bugs affecting seven Chrome components. The post Chrome 146 Update Patches High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome 146 Update Patches High-Severity Vulnerabilities Read More »

Critical NetScaler ADC, Gateway flaw may soon be exploited (CVE-2026-3055)

Critical NetScaler ADC, Gateway flaw may soon be exploited (CVE-2026-3055) 2026-03-24 at 16:13 By Zeljka Zorz Citrix has fixed two vulnerabilities in NetScaler ADC and NetScaler Gateway, with the more serious flaw (CVE-2026-3055) potentially allowing attackers to extract active session tokens from the memory of affected devices. Anil Shetty, senior VP of Engineering with Cloud

Critical NetScaler ADC, Gateway flaw may soon be exploited (CVE-2026-3055) Read More »

Scroll to Top