vulnerability

Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection

Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection 2026-07-08 at 13:30 By Ionut Arghire Researchers show how attackers can use a crafted public GitHub Issue to trick AI-powered workflows into exposing data from private repositories without authentication. The post Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection appeared first on SecurityWeek. This article […]

Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection Read More »

Critical Gitea Flaw Under Active Exploitation, Researchers Warn

Critical Gitea Flaw Under Active Exploitation, Researchers Warn 2026-07-07 at 20:17 By Ionut Arghire Attackers are exploiting the critical Gitea vulnerability CVE-2026-20896 to bypass authentication with a single HTTP header and access vulnerable repositories and secrets. The post Critical Gitea Flaw Under Active Exploitation, Researchers Warn appeared first on SecurityWeek. This article is an excerpt […]

Critical Gitea Flaw Under Active Exploitation, Researchers Warn Read More »

Critical Adobe ColdFusion Vulnerability Exploited in Attacks

Critical Adobe ColdFusion Vulnerability Exploited in Attacks 2026-07-07 at 15:38 By Ionut Arghire Hackers are exploiting a recently patched critical vulnerability (CVE-2026-48282) in Adobe ColdFusion that carries a CVSS score of 10/10. The post Critical Adobe ColdFusion Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Adobe ColdFusion Vulnerability Exploited in Attacks Read More »

Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282)

Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282) 2026-07-07 at 15:03 By Zeljka Zorz CVE-2026-48282, one of the maximum severity vulnerabilities patched in Adobe ColdFusion on June 30, 2026, has been targeted by attackers in the wild. Exploitation attempts were detected on July 2, through the honeypot sensors of cybersecurity threat-intelligence service KEVIntel, mere minutes after […]

Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282) Read More »

Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817)

Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817) 2026-06-30 at 16:58 By Zeljka Zorz Exploitation attempts targeting a critical vulnerability (CVE-2026-46817) in Oracle Payments, the payment-processing module within Oracle’s E-Business Suite (EBS), have been spotted over the weekend, threat intelligence company Defused warned on Monday. The detected exploitation attempts (Source: Defused) “On 27 June 2026 […]

Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817) Read More »

Exploitation of Recent Oracle E-Business Suite Vulnerability Begins

Exploitation of Recent Oracle E-Business Suite Vulnerability Begins 2026-06-30 at 14:29 By Ionut Arghire The critical-severity defect allows unauthenticated attackers to take over the E-Business Suite’s Payments product. The post Exploitation of Recent Oracle E-Business Suite Vulnerability Begins appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Exploitation of Recent Oracle E-Business Suite Vulnerability Begins Read More »

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) 2026-06-30 at 13:25 By Zeljka Zorz Attackers are exploiting CVE-2026-48558, a recently patched authentication bypass vulnerability in SimpleHelp RMM, to drop the novel Djinn Stealer malware on victim computers. The malware is capable of targeting Windows, macOS, and Linux systems, and “collects credentials associated with cloud […]

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) Read More »

Critical SimpleHelp Vulnerability Exploited for Malware Delivery

Critical SimpleHelp Vulnerability Exploited for Malware Delivery 2026-06-30 at 11:43 By Ionut Arghire The threat actor is focused on collecting credentials, SSH keys, cryptocurrency wallets, and development tooling. The post Critical SimpleHelp Vulnerability Exploited for Malware Delivery appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical SimpleHelp Vulnerability Exploited for Malware Delivery Read More »

AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes begin

AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes begin 2026-06-30 at 09:15 By Mirko Zorz Phones and laptops ship with a feature that sends files to nearby devices over the air, with no cables, accounts, or prior pairing. Apple calls its version AirDrop. Google and Samsung call theirs Quick Share. […]

AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes begin Read More »

New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking

New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking 2026-06-30 at 08:04 By Eduard Kovacs CISA has published an advisory to inform organizations about three vulnerabilities found by a researcher in Daktronics controllers. The post New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking appeared first on SecurityWeek. This article is […]

New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking Read More »

JSP webshells being dropped on unpatched PTC Windchill instances

JSP webshells being dropped on unpatched PTC Windchill instances 2026-06-29 at 19:18 By Zeljka Zorz The US Cybersecurity and Infrastructure Security Agency (CISA) added a vulnerability (CVE-2026-12569) in Windchill and FlexPLM, two product lifecycle management software platforms developed by PTC, to its Known Exploited Vulnerabilities (KEV) catalog. Entries in the KEV catalog don’t contain links […]

JSP webshells being dropped on unpatched PTC Windchill instances Read More »

Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories

Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories 2026-06-26 at 18:23 By Eduard Kovacs AWS has patched the vulnerability and published its own advisory to inform customers about the potential impact.  The post Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories appeared first on SecurityWeek. This article is an excerpt from […]

Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories Read More »

Linux Foundation Unveils New Open Source Security Project Akrites

Linux Foundation Unveils New Open Source Security Project Akrites 2026-06-26 at 14:28 By Ionut Arghire It will provide the tools and channels to report, patch, and disclose open source software vulnerabilities. The post Linux Foundation Unveils New Open Source Security Project Akrites appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Linux Foundation Unveils New Open Source Security Project Akrites Read More »

Synology issues critical fix for MailPlus Server vulnerabilities

Synology issues critical fix for MailPlus Server vulnerabilities 2026-06-26 at 13:57 By Zeljka Zorz Synology has has fixed critical vulnerabilities in MailPlus Server, a software package used to run private email infrastructure on Synology NAS devices. The security update fixes three flaws: CVE-2026-13136, stemming from faulty authorization checks, may allow remote attackers to read or […]

Synology issues critical fix for MailPlus Server vulnerabilities Read More »

First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild

First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild 2026-06-26 at 11:15 By Eduard Kovacs CISA has added the remote code execution flaw CVE-2026-12569 to its Known Exploited Vulnerabilities catalog. The post First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild Read More »

GitLab Patches Code Execution, Information Disclosure Vulnerabilities

GitLab Patches Code Execution, Information Disclosure Vulnerabilities 2026-06-25 at 14:10 By Ionut Arghire The latest GitLab CE/EE updates address 13 vulnerabilities, including three high-severity defects. The post GitLab Patches Code Execution, Information Disclosure Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

GitLab Patches Code Execution, Information Disclosure Vulnerabilities Read More »

Chrome 149 Update Resolves 18 Severe Vulnerabilities

Chrome 149 Update Resolves 18 Severe Vulnerabilities 2026-06-25 at 10:56 By Ionut Arghire More than half of the bugs are use-after-free defects, which can potentially lead to remote code execution. The post Chrome 149 Update Resolves 18 Severe Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome 149 Update Resolves 18 Severe Vulnerabilities Read More »

Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs

Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs 2026-06-24 at 15:32 By Ionut Arghire The flaws allow remote, unauthenticated attackers to make system changes, access underlying accounts, and inject commands. The post Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs Read More »

Scroll to Top