vulnerability

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager 2026-08-13 at 13:40 By Ionut Arghire The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance. The post Fortinet Patches Authentication Flaws in FortiWeb and FortiManager appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager Read More »

Ivanti EPM Update Patches Remotely Exploitable Flaws

Ivanti EPM Update Patches Remotely Exploitable Flaws 2026-08-12 at 11:14 By Ionut Arghire The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service. The post Ivanti EPM Update Patches Remotely Exploitable Flaws appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Ivanti EPM Update Patches Remotely Exploitable Flaws Read More »

SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform

SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform 2026-08-12 at 10:31 By Ionut Arghire The security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data. The post SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform Read More »

Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

Cisco Patches Firewall Zero-Day Exploited for DoS Attacks 2026-08-12 at 08:10 By Eduard Kovacs CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. The post Cisco Patches Firewall Zero-Day Exploited for DoS Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cisco Patches Firewall Zero-Day Exploited for DoS Attacks Read More »

August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day 2026-08-11 at 21:46 By Ionut Arghire A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges. The post August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day appeared first on SecurityWeek. This article is an excerpt from […]

August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day Read More »

Zoom Patches Zero-Click Code Execution Vulnerability

Zoom Patches Zero-Click Code Execution Vulnerability 2026-08-11 at 18:49 By Ionut Arghire Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine. The post Zoom Patches Zero-Click Code Execution Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Zoom Patches Zero-Click Code Execution Vulnerability Read More »

SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities

SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities 2026-08-11 at 17:14 By Ionut Arghire SAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs. The post SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities Read More »

Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G

Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G 2026-08-11 at 15:10 By Sinisa Markovic Researchers have found that compromised or malicious SIM cards can issue commands to some smartphones and cellular-connected devices, allowing attackers to steal information, disrupt communications, downgrade connections to 2G, and in some cases execute code. Tomasz Piotr […]

Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G Read More »

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC 2026-08-10 at 17:07 By Ionut Arghire Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition. The post Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC Read More »

Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

Critical Flaws Discovered in Belgian eID Software Used by 2 Million People 2026-08-10 at 07:44 By Eduard Kovacs The vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies. The post Critical Flaws Discovered in Belgian eID Software Used by 2 Million People appeared first on SecurityWeek. This article […]

Critical Flaws Discovered in Belgian eID Software Used by 2 Million People Read More »

200 accounts compromised in Swiss government’s Microsoft SharePoint breach

200 accounts compromised in Swiss government’s Microsoft SharePoint breach 2026-08-07 at 15:29 By Sinisa Markovic Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT), compromising the login credentials of around 200 accounts. On July 28, BIT’s security specialists noticed unusual activity on the SharePoint servers. […]

200 accounts compromised in Swiss government’s Microsoft SharePoint breach Read More »

Microsoft, Apple Release Fresh Security Updates

Microsoft, Apple Release Fresh Security Updates 2026-08-07 at 12:09 By Ionut Arghire Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass. The post Microsoft, Apple Release Fresh Security Updates appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft, Apple Release Fresh Security Updates Read More »

Critical Vulnerabilities Patched With Chrome 151 Update

Critical Vulnerabilities Patched With Chrome 151 Update 2026-08-07 at 09:56 By Ionut Arghire The browser refresh eliminates over two dozen memory safety bugs, including critical use-after-free flaws. The post Critical Vulnerabilities Patched With Chrome 151 Update appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Vulnerabilities Patched With Chrome 151 Update Read More »

Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts

Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts 2026-08-06 at 15:54 By Eduard Kovacs Zenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched. The post Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts appeared first […]

Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts Read More »

Critical Paperclip Flaw Allowed Admin Access, Code Execution

Critical Paperclip Flaw Allowed Admin Access, Code Execution 2026-08-06 at 14:09 By Ionut Arghire An attacker could self-register, sign in for board-level API access, and import a new company for code execution. The post Critical Paperclip Flaw Allowed Admin Access, Code Execution appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Critical Paperclip Flaw Allowed Admin Access, Code Execution Read More »

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones 

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones  2026-08-05 at 22:40 By Eduard Kovacs The chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications. The post How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones  Read More »

CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities

CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities 2026-08-05 at 12:44 By Ionut Arghire The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass. The post CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities Read More »

15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic

15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic 2026-08-05 at 12:35 By Mirko Zorz TP-Link prints the serial number of an Omada router on its packaging and on a label attached to the device. Those numbers run in sequence, and feeding a guessed one to the Omada cloud service returns the […]

15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic Read More »

TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover

TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover 2026-08-04 at 15:00 By Eduard Kovacs Forescout researchers have found 15 new vulnerabilities in the TP-Link Omada networking ecosystem. The post TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover Read More »

Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering 2026-08-04 at 13:54 By Ionut Arghire A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent. The post Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering appeared first on SecurityWeek. This […]

Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering Read More »

Scroll to Top