vulnerability

Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks 2026-08-04 at 12:56 By Ionut Arghire Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login. The post Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks Read More »

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers 2026-08-04 at 08:18 By Eduard Kovacs The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000. The post Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers appeared first on SecurityWeek. This article is an excerpt […]

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers Read More »

Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)

Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577) 2026-08-03 at 17:33 By Zeljka Zorz Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) solution widely used by managed service providers, to gain access to managed endpoints. How the flaw was discovered “On July 31, 2026, […]

Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577) Read More »

Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers

Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers 2026-08-03 at 16:51 By Sinisa Markovic A Chinese threat actor operating under the aliases “knaithe” and “KnYuan” used multiple LLMs to automate cyberattacks against internet-facing systems with limited human intervention. Researchers at Palo Alto Networks’ Unit 42 uncovered the operation after the threat actor’s […]

Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers Read More »

N‑able Patches Vulnerability Exploited to Hack N-central Servers

N‑able Patches Vulnerability Exploited to Hack N-central Servers 2026-08-03 at 15:34 By Eduard Kovacs The N‑central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass. The post N‑able Patches Vulnerability Exploited to Hack N-central Servers appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

N‑able Patches Vulnerability Exploited to Hack N-central Servers Read More »

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066) 2026-08-03 at 14:42 By Zeljka Zorz A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web apps, may allow attackers to read sensitive files off a server and, in some cases, take full control of […]

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066) Read More »

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks 2026-08-03 at 13:39 By Ionut Arghire The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement. The post Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks Read More »

Ruby on Rails Patches Critical Vulnerability

Ruby on Rails Patches Critical Vulnerability 2026-08-01 at 14:15 By Ionut Arghire The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Ruby on Rails Patches Critical Vulnerability Read More »

Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace

Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace 2026-07-31 at 13:28 By Ionut Arghire The internet giant has built an agent harness to find vulnerabilities across Chrome’s codebase. The post Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace Read More »

Critical Code Execution Vulnerability Patched in TeamCity 

Critical Code Execution Vulnerability Patched in TeamCity  2026-07-31 at 09:50 By Ionut Arghire Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol. The post Critical Code Execution Vulnerability Patched in TeamCity  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Code Execution Vulnerability Patched in TeamCity  Read More »

Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)

Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897) 2026-07-30 at 17:23 By Zeljka Zorz Russia-affiliated cyber espionage group Laundry Bear (aka Void Blizzard, aka TA488) is exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange, to target US and European government entities and a variety of private sector organizations via email. The […]

Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897) Read More »

Cisco FMC static credentials exploited by attackers (CVE-2026-20316)

Cisco FMC static credentials exploited by attackers (CVE-2026-20316) 2026-07-30 at 13:44 By Zeljka Zorz A static credentials vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC), a platform for centrally managing multiple Cisco Secure Firewall devices across a network, is being leveraged by attackers, CISA warned. Two FMC flaws, one indicator of compromise CVE-2026-20316, reported […]

Cisco FMC static credentials exploited by attackers (CVE-2026-20316) Read More »

Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms 

Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms  2026-07-30 at 12:56 By Ionut Arghire Unauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container. The post Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms  Read More »

Cisco Secure FMC Zero-Day Exploited in the Wild

Cisco Secure FMC Zero-Day Exploited in the Wild 2026-07-30 at 09:31 By Eduard Kovacs The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices.  The post Cisco Secure FMC Zero-Day Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Cisco Secure FMC Zero-Day Exploited in the Wild Read More »

Critical VM Escape Vulnerability Patched in VMware ESXi

Critical VM Escape Vulnerability Patched in VMware ESXi 2026-07-29 at 14:42 By Eduard Kovacs A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion. The post Critical VM Escape Vulnerability Patched in VMware ESXi appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical VM Escape Vulnerability Patched in VMware ESXi Read More »

JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack

JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack 2026-07-29 at 11:46 By Ionut Arghire The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given. The post JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack Read More »

Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe

Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe 2026-07-28 at 17:19 By Eduard Kovacs Apple announced that dozens of vulnerabilities have been patched in each of its operating systems. The post Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe Read More »

Exposed BMCs hand out password hashes before login

Exposed BMCs hand out password hashes before login 2026-07-28 at 15:00 By Sinisa Markovic An attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The exchange is part of the IPMI 2.0 handshake, built on an authentication protocol introduced […]

Exposed BMCs hand out password hashes before login Read More »

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077) 2026-07-28 at 14:04 By Zeljka Zorz JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible. “For those who are unable to do so, we have released a security patch plugin,” noted Daniel Gallo, […]

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077) Read More »

Scroll to Top