vulnerability

CISA review makes the case for eliminating vulnerability classes

CISA review makes the case for eliminating vulnerability classes 2026-09-01 at 18:23 By Zeljka Zorz For years, the security industry has treated vulnerabilities as an endless queue of individual fixes. A recent CISA review argues that this is precisely why attackers keep winning. The solution to this problem, they believe, is eliminating entire categories of […]

CISA review makes the case for eliminating vulnerability classes Read More »

Hackers Start Exploiting Critical Langflow Vulnerability

Hackers Start Exploiting Critical Langflow Vulnerability 2026-09-01 at 15:07 By Ionut Arghire Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely. The post Hackers Start Exploiting Critical Langflow Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hackers Start Exploiting Critical Langflow Vulnerability Read More »

Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild

Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild 2026-09-01 at 12:59 By Eduard Kovacs Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure. The post Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild Read More »

WatchGuard Patches Critical Vulnerabilities

WatchGuard Patches Critical Vulnerabilities 2026-09-01 at 11:50 By Ionut Arghire Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely. The post WatchGuard Patches Critical Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

WatchGuard Patches Critical Vulnerabilities Read More »

PaperCut Exploitation Escalates to Active Intrusions

PaperCut Exploitation Escalates to Active Intrusions 2026-09-01 at 08:27 By Eduard Kovacs CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog. The post PaperCut Exploitation Escalates to Active Intrusions appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

PaperCut Exploitation Escalates to Active Intrusions Read More »

Attackers plant remote access tools on compromised PaperCut servers

Attackers plant remote access tools on compromised PaperCut servers 2026-08-31 at 17:54 By Zeljka Zorz The threat actor targeting internet-facing PaperCut Application Servers is covertly installing legitimate remote access software on them, PaperCut Software shared in the most recent update on the ongoing attack campaign. PaperCut zero-days exploited to deploy remote access tools The vendor […]

Attackers plant remote access tools on compromised PaperCut servers Read More »

Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit

Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit 2026-08-31 at 17:32 By Eduard Kovacs Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product. The post Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit Read More »

ServiceNow Patches 3 Critical Code Injection Vulnerabilities

ServiceNow Patches 3 Critical Code Injection Vulnerabilities 2026-08-31 at 16:59 By Ionut Arghire Attackers could exploit the security defects to execute arbitrary code and access or tamper with data. The post ServiceNow Patches 3 Critical Code Injection Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

ServiceNow Patches 3 Critical Code Injection Vulnerabilities Read More »

Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs 2026-08-31 at 14:24 By Ionut Arghire Named KindaRails2Shell, the arbitrary file read flaw allows attackers to extract secrets and execute arbitrary code remotely. The post Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs Read More »

More Details Emerge on Exploited PaperCut Vulnerabilities

More Details Emerge on Exploited PaperCut Vulnerabilities 2026-08-31 at 09:51 By Eduard Kovacs PaperCut has released a second emergency patch for the exploited vulnerabilities, which are now tracked as CVE-2026-82078 and CVE-2026-81578. The post More Details Emerge on Exploited PaperCut Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

More Details Emerge on Exploited PaperCut Vulnerabilities Read More »

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems 2026-08-28 at 15:36 By Eduard Kovacs CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents. The post OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems appeared first on SecurityWeek. This article is an […]

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems Read More »

PaperCut Releases Emergency Patch for Exploited Zero-Day

PaperCut Releases Emergency Patch for Exploited Zero-Day 2026-08-28 at 11:40 By Eduard Kovacs A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations. The post PaperCut Releases Emergency Patch for Exploited Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

PaperCut Releases Emergency Patch for Exploited Zero-Day Read More »

Unknown PaperCut NG/MF vulnerability is under active attack

Unknown PaperCut NG/MF vulnerability is under active attack 2026-08-27 at 14:59 By Zeljka Zorz A yet unspecified vulnerability affecting print management solutions PaperCut NG and PaperCut MF is being exploited by attackers, PaperCut Software warned today. “We are aware of confirmed customer incidents and are treating this matter with the highest priority,” the vendor said. […]

Unknown PaperCut NG/MF vulnerability is under active attack Read More »

Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)

Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452) 2026-08-27 at 12:58 By Sinisa Markovic CISA added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a previously patched Citrix NetScaler ADC and Gateway flaw, tracked as CVE-2026-8452, that is being exploited in the wild. The agency published the alert on August […]

Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452) Read More »

Recent Citrix NetScaler Vulnerability Exploited in the Wild

Recent Citrix NetScaler Vulnerability Exploited in the Wild 2026-08-27 at 07:39 By Eduard Kovacs CISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452. The post Recent Citrix NetScaler Vulnerability Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Recent Citrix NetScaler Vulnerability Exploited in the Wild Read More »

Adobe and Nvidia Patch Dozens of Vulnerabilities

Adobe and Nvidia Patch Dozens of Vulnerabilities 2026-08-26 at 15:39 By Eduard Kovacs Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products. The post Adobe and Nvidia Patch Dozens of Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Adobe and Nvidia Patch Dozens of Vulnerabilities Read More »

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) 2026-08-26 at 13:59 By Zeljka Zorz Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The KEV entry does not contain or point to details […]

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) Read More »

Chrome 152 Patches Over 300 Vulnerabilities

Chrome 152 Patches Over 300 Vulnerabilities 2026-08-26 at 12:50 By Eduard Kovacs Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities. The post Chrome 152 Patches Over 300 Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome 152 Patches Over 300 Vulnerabilities Read More »

CISA Warns of Exploited Gitea Vulnerability

CISA Warns of Exploited Gitea Vulnerability 2026-08-26 at 08:17 By Eduard Kovacs CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1. The post CISA Warns of Exploited Gitea Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Warns of Exploited Gitea Vulnerability Read More »

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities 2026-08-25 at 16:33 By Eduard Kovacs CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Read More »

Scroll to Top