vulnerability

Cisco Launches Low-Cost AI Models for Source Code Security

Cisco Launches Low-Cost AI Models for Source Code Security 2026-07-21 at 20:44 By Kevin Townsend The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models. The post Cisco Launches Low-Cost AI Models for Source Code Security appeared first on SecurityWeek. This […]

Cisco Launches Low-Cost AI Models for Source Code Security Read More »

Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data

Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data 2026-07-21 at 13:19 By Eduard Kovacs A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure. The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Read More »

Exploitation of ServiceNow Vulnerability Seen Days After Disclosure

Exploitation of ServiceNow Vulnerability Seen Days After Disclosure 2026-07-21 at 11:41 By Eduard Kovacs The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution. The post Exploitation of ServiceNow Vulnerability Seen Days After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Exploitation of ServiceNow Vulnerability Seen Days After Disclosure Read More »

Zimbra Update Patches Critical Vulnerabilities

Zimbra Update Patches Critical Vulnerabilities 2026-07-21 at 11:20 By Ionut Arghire The latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects. The post Zimbra Update Patches Critical Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Zimbra Update Patches Critical Vulnerabilities Read More »

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) 2026-07-20 at 17:32 By Zeljka Zorz Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code injection

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) Read More »

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability 2026-07-20 at 15:32 By Ionut Arghire Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Read More »

Chrome 150 Update Patches Severe Memory Safety Bugs

Chrome 150 Update Patches Severe Memory Safety Bugs 2026-07-20 at 11:12 By Ionut Arghire The fresh security update resolves six critical and high-severity use-after-free vulnerabilities. The post Chrome 150 Update Patches Severe Memory Safety Bugs appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome 150 Update Patches Severe Memory Safety Bugs Read More »

WP2Shell WordPress Vulnerabilities Exploited in the Wild

WP2Shell WordPress Vulnerabilities Exploited in the Wild 2026-07-20 at 08:21 By Eduard Kovacs Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure. The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

WP2Shell WordPress Vulnerabilities Exploited in the Wild Read More »

Two new high severity WordPress vulnerabilities, patch immediately!

Two new high severity WordPress vulnerabilities, patch immediately! 2026-07-18 at 17:57 By Help Net Security The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60137

Two new high severity WordPress vulnerabilities, patch immediately! Read More »

Fresh SharePoint Vulnerability Exploited Soon After Disclosure

Fresh SharePoint Vulnerability Exploited Soon After Disclosure 2026-07-17 at 10:15 By Ionut Arghire The critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server. The post Fresh SharePoint Vulnerability Exploited Soon After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Fresh SharePoint Vulnerability Exploited Soon After Disclosure Read More »

Splunk, Zoom Patch Critical Vulnerabilities

Splunk, Zoom Patch Critical Vulnerabilities 2026-07-16 at 13:54 By Ionut Arghire The flaws could allow attackers to access credentials and data, take over accounts, and escalate their privileges. The post Splunk, Zoom Patch Critical Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Splunk, Zoom Patch Critical Vulnerabilities Read More »

Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities

Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities 2026-07-16 at 09:08 By Eduard Kovacs The cybersecurity companies patched critical and high-severity vulnerabilities in some of their products. The post Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities Read More »

Unpatched Cursor Vulnerability Exposes Users to Code Execution

Unpatched Cursor Vulnerability Exposes Users to Code Execution 2026-07-15 at 17:37 By Ionut Arghire An attacker can create a malicious repository containing a git.exe in the project root, and Cursor executes it automatically. The post Unpatched Cursor Vulnerability Exposes Users to Code Execution appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Unpatched Cursor Vulnerability Exposes Users to Code Execution Read More »

Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow

Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow 2026-07-15 at 14:02 By Ionut Arghire A critical security defect in the ServiceNow AI platform could allow remote attackers to execute arbitrary code. The post Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow Read More »

Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates

Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates 2026-07-15 at 10:24 By Ionut Arghire Public exploit code targeting the Firefox flaws exists, but no in-the-wild exploitation has been observed. The post Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates Read More »

Adobe Patches Critical ColdFusion Vulnerabilities

Adobe Patches Critical ColdFusion Vulnerabilities 2026-07-14 at 20:06 By Ionut Arghire The ColdFusion security defects could allow attackers to execute arbitrary code or elevate their privileges. The post Adobe Patches Critical ColdFusion Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Adobe Patches Critical ColdFusion Vulnerabilities Read More »

7 Severe Vulnerabilities Patched in VMware Avi Load Balancer

7 Severe Vulnerabilities Patched in VMware Avi Load Balancer 2026-07-14 at 16:55 By Eduard Kovacs The flaws can be exploited for authentication bypass, remote code execution, privilege escalation, and directory traversal. The post 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

7 Severe Vulnerabilities Patched in VMware Avi Load Balancer Read More »

Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar

Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar 2026-07-14 at 16:00 By Eduard Kovacs A ClaudeBleed-linked vulnerability reportedly persists across eight patches, exposing potentially sensitive data to other extensions.  The post Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar Read More »

SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud

SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud 2026-07-14 at 14:17 By Ionut Arghire The flaws could allow attackers to access and modify data, and cause system unavailability and request-response desynchronization. The post SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud Read More »

No one knows how many old shims can still bypass UEFI Secure Boot

No one knows how many old shims can still bypass UEFI Secure Boot 2026-07-14 at 13:26 By Mirko Zorz The vast majority of UEFI computers carry a Microsoft certificate that will trust a small first-stage loader called a shim, a program Microsoft signs so that Linux and assorted boot tools can run with Secure Boot

No one knows how many old shims can still bypass UEFI Secure Boot Read More »

Scroll to Top