vulnerability

Android Update Patches Exploited Qualcomm Zero-Day

Android Update Patches Exploited Qualcomm Zero-Day 2026-03-03 at 15:07 By Ionut Arghire An integer overflow or wraparound in the Qualcomm graphics component, the bug leads to memory corruption. The post Android Update Patches Exploited Qualcomm Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Android Update Patches Exploited Qualcomm Zero-Day Read More »

Vulnerability in MS-Agent AI Framework Can Allow Full System Compromise

Vulnerability in MS-Agent AI Framework Can Allow Full System Compromise 2026-03-03 at 13:58 By Ionut Arghire Improper input sanitization in the framework can be exploited through the Shell tool, allowing attackers to modify system files and steal data. The post Vulnerability in MS-Agent AI Framework Can Allow Full System Compromise appeared first on SecurityWeek. This

Vulnerability in MS-Agent AI Framework Can Allow Full System Compromise Read More »

Vulnerability Allowed Hijacking Chrome’s Gemini Live AI Assistant

Vulnerability Allowed Hijacking Chrome’s Gemini Live AI Assistant 2026-03-02 at 17:46 By Ionut Arghire Malicious extensions could hijack the Gemini Live in Chrome feature to spy on users and steal their files. The post Vulnerability Allowed Hijacking Chrome’s Gemini Live AI Assistant appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Vulnerability Allowed Hijacking Chrome’s Gemini Live AI Assistant Read More »

OpenClaw Vulnerability Allowed Websites to Hijack AI Agents

OpenClaw Vulnerability Allowed Websites to Hijack AI Agents 2026-03-02 at 16:57 By Ionut Arghire Malicious websites could open a WebSocket connection to localhost on the OpenClaw gateway port, brute force passwords, and take control of the agent. The post OpenClaw Vulnerability Allowed Websites to Hijack AI Agents appeared first on SecurityWeek. This article is an

OpenClaw Vulnerability Allowed Websites to Hijack AI Agents Read More »

Juniper Networks PTX Routers Affected by Critical Vulnerability 

Juniper Networks PTX Routers Affected by Critical Vulnerability  2026-02-27 at 12:47 By Eduard Kovacs An out-of-band security update for Junos OS Evolved patches the remote code execution vulnerability CVE-2026-21902. The post Juniper Networks PTX Routers Affected by Critical Vulnerability  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Juniper Networks PTX Routers Affected by Critical Vulnerability  Read More »

Critical Flaws Exposed Gardyn Smart Gardens to Remote Hacking

Critical Flaws Exposed Gardyn Smart Gardens to Remote Hacking 2026-02-27 at 10:17 By Eduard Kovacs CISA has released an advisory to warn about four vulnerabilities discovered by a researcher in Gardyn Home and Gardyn Studio. The post Critical Flaws Exposed Gardyn Smart Gardens to Remote Hacking appeared first on SecurityWeek. This article is an excerpt

Critical Flaws Exposed Gardyn Smart Gardens to Remote Hacking Read More »

Claude Code Flaws Exposed Developer Devices to Silent Hacking

Claude Code Flaws Exposed Developer Devices to Silent Hacking 2026-02-26 at 19:37 By Eduard Kovacs Anthropic has patched vulnerabilities whose impact was demonstrated by Check Point via malicious configuration files. The post Claude Code Flaws Exposed Developer Devices to Silent Hacking appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Claude Code Flaws Exposed Developer Devices to Silent Hacking Read More »

Zyxel Patches Critical Vulnerability in Many Device Models

Zyxel Patches Critical Vulnerability in Many Device Models 2026-02-26 at 14:40 By Ionut Arghire The issue impacts the UPnP function of multiple device models and could be exploited for remote code execution. The post Zyxel Patches Critical Vulnerability in Many Device Models appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Zyxel Patches Critical Vulnerability in Many Device Models Read More »

Trend Micro Patches Critical Apex One Vulnerabilities

Trend Micro Patches Critical Apex One Vulnerabilities 2026-02-26 at 12:27 By Eduard Kovacs TrendAI has fixed eight critical and high-severity issues in Windows and macOS endpoint security products. The post Trend Micro Patches Critical Apex One Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Trend Micro Patches Critical Apex One Vulnerabilities Read More »

Cisco Patches Catalyst SD-WAN Zero-Day Exploited by Highly Sophisticated Hackers

Cisco Patches Catalyst SD-WAN Zero-Day Exploited by Highly Sophisticated Hackers 2026-02-26 at 11:52 By Ionut Arghire Already added to CISA’s KEV catalog, the flaw allows attackers to bypass authentication and gain administrative privileges. The post Cisco Patches Catalyst SD-WAN Zero-Day Exploited by Highly Sophisticated Hackers appeared first on SecurityWeek. This article is an excerpt from

Cisco Patches Catalyst SD-WAN Zero-Day Exploited by Highly Sophisticated Hackers Read More »

SolarWinds Patches Four Critical Serv-U Vulnerabilities

SolarWinds Patches Four Critical Serv-U Vulnerabilities 2026-02-25 at 17:30 By Ionut Arghire The four security defects could be exploited for remote code execution but require administrative privileges. The post SolarWinds Patches Four Critical Serv-U Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

SolarWinds Patches Four Critical Serv-U Vulnerabilities Read More »

The Week in Vulnerabilities: WordPress, BeyondTrust, and Critical ICS Bugs

The Week in Vulnerabilities: WordPress, BeyondTrust, and Critical ICS Bugs 2026-02-25 at 15:20 By Ashish Khaitan Cyble Research & Intelligence Labs (CRIL) tracked 1,102 vulnerabilities last week. Of these, 166 vulnerabilities already have publicly available Proof-of-Concept (PoC) exploits, significantly increasing the likelihood of real-world attacks. A total of 49 vulnerabilities were rated critical under CVSS v3.1, while 32 received critical

The Week in Vulnerabilities: WordPress, BeyondTrust, and Critical ICS Bugs Read More »

CISA flags exploited FileZen command injection bug, patch now! (CVE-2026-25108)

CISA flags exploited FileZen command injection bug, patch now! (CVE-2026-25108) 2026-02-25 at 12:14 By Zeljka Zorz CISA has added CVE-2026-25108, an OS command injection vulnerability in Soliton Systems’ FileZen secure file transfer solution, to its Known Exploited Vulnerabilities (KEV) catalog. The vendor has confirmed active exploitation, stating it has received multiple reports of damage caused

CISA flags exploited FileZen command injection bug, patch now! (CVE-2026-25108) Read More »

VMware Aria Operations Vulnerability Could Allow Remote Code Execution

VMware Aria Operations Vulnerability Could Allow Remote Code Execution 2026-02-24 at 16:42 By Eduard Kovacs Broadcom has patched several vulnerabilities in VMware Aria Operations, including high-severity flaws. The post VMware Aria Operations Vulnerability Could Allow Remote Code Execution appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

VMware Aria Operations Vulnerability Could Allow Remote Code Execution Read More »

GitHub Issues Abused in Copilot Attack Leading to Repository Takeover

GitHub Issues Abused in Copilot Attack Leading to Repository Takeover 2026-02-24 at 14:26 By Ionut Arghire Attackers can inject malicious instructions in a GitHub Issue that are automatically processed by Copilot when launching a Codespace from that issue. The post GitHub Issues Abused in Copilot Attack Leading to Repository Takeover appeared first on SecurityWeek. This

GitHub Issues Abused in Copilot Attack Leading to Repository Takeover Read More »

The Week in Vulnerabilities: SolarWinds, Ivanti, and Critical ICS Exposure

The Week in Vulnerabilities: SolarWinds, Ivanti, and Critical ICS Exposure 2026-02-19 at 14:07 By Ashish Khaitan Cyble Research & Intelligence Labs (CRIL) tracked 1,158 vulnerabilities last week. Of these, 251 vulnerabilities already have publicly available Proof-of-Concept (PoC) exploits, significantly increasing the likelihood of real-world attacks.  A total of 94 vulnerabilities were rated critical under CVSS v3.1, while 43 were rated

The Week in Vulnerabilities: SolarWinds, Ivanti, and Critical ICS Exposure Read More »

Ransomware group breached SmarterTools via flaw in its SmarterMail deployment

Ransomware group breached SmarterTools via flaw in its SmarterMail deployment 2026-02-09 at 17:18 By Zeljka Zorz SmarterTools, the company behind the popular Microsoft Exchange alternative SmarterMail, has been breached by a ransomware-wielding group that leveraged a recently fixed vulnerability in that solution. How did the SmarterTools breach happen? Derek Curtis, the firm’s Chief Operating Officer,

Ransomware group breached SmarterTools via flaw in its SmarterMail deployment Read More »

BeyondTrust fixes easy-to-exploit pre-auth RCE vulnerability in remote access tools (CVE-2026-1731)

BeyondTrust fixes easy-to-exploit pre-auth RCE vulnerability in remote access tools (CVE-2026-1731) 2026-02-09 at 13:36 By Zeljka Zorz BeyondTrust fixed a critical remote code execution vulnerability (CVE-2026-1731) in its Remote Support (RS) and Privileged Remote Access (PRA) solutions and is urging self-hosted customers to apply the patch as soon a possible. Unlike the Remote Support zero-day

BeyondTrust fixes easy-to-exploit pre-auth RCE vulnerability in remote access tools (CVE-2026-1731) Read More »

New Paper and Tool Help Security Teams Move Beyond Blind Reliance on CISA’s KEV Catalog

New Paper and Tool Help Security Teams Move Beyond Blind Reliance on CISA’s KEV Catalog 2026-02-09 at 11:10 By Kevin Townsend The KEV list is useful but largely misunderstood. KEVology explains what it is, and how best to use it. The post New Paper and Tool Help Security Teams Move Beyond Blind Reliance on CISA’s

New Paper and Tool Help Security Teams Move Beyond Blind Reliance on CISA’s KEV Catalog Read More »

Critical SmarterMail Vulnerability Exploited in Ransomware Attacks

Critical SmarterMail Vulnerability Exploited in Ransomware Attacks 2026-02-06 at 09:54 By Ionut Arghire The security defect allows unauthenticated attackers to execute arbitrary code remotely via malicious HTTP requests. The post Critical SmarterMail Vulnerability Exploited in Ransomware Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical SmarterMail Vulnerability Exploited in Ransomware Attacks Read More »

Scroll to Top