Tag: vulnerabilities

Metabase has released security updates after confirming active exploitation of a zero day vulnerability that allows attackers to gain administrator access without authentication.
Research presented at Black Hat USA 2026 demonstrates CSS based attack techniques affecting major webmail services, highlighting risks involving passwords, authentication tokens, and AI connected email workflows.

Unpatched Vulnerabilities Found In FatFs Filesystem Affecting Millions Of Embedded And IoT Devices

Security researchers have disclosed seven vulnerabilities in FatFs filesystem library used in embedded devices, exposing risks across IoT systems including cameras, drones, industrial controllers, and more.

CISA Adds Four Exploited Vulnerabilities To KEV Catalog Sets May 2026 Deadline For Federal Agencies

CISA has added four actively exploited vulnerabilities affecting SimpleHelp, Samsung MagicINFO 9 Server, and D-Link routers to its KEV catalog, setting a May 2026 deadline for federal agencies to act.

CISA Adds Eight Exploited Vulnerabilities To KEV Catalog, Sets Federal Deadlines For Remediation

CISA updates its Known Exploited Vulnerabilities catalog with eight new flaws, including Cisco SD WAN Manager issues, urging federal agencies to patch by April and May 2026.

Apple Expands iOS 18.7.7 Update To Protect Users From DarkSword Exploit

Apple extends iOS 18.7.7 and iPadOS 18.7.7 updates to more devices to block DarkSword exploit, addressing critical vulnerabilities in older iOS versions.

LangChain And LangGraph Vulnerabilities Expose Sensitive Data In Widely Used AI Frameworks

Security researchers reveal critical vulnerabilities in LangChain and LangGraph that could expose files, secrets, and databases, raising concerns for enterprise AI deployments.

AI Security Flaws Discovered In Amazon Bedrock LangSmith And SGLang Raise Data Protection Concerns

Researchers have identified security vulnerabilities in Amazon Bedrock, LangSmith, and SGLang that could enable data exfiltration, account takeover, and remote code execution in AI environments.

React2Shell Exploitation Expands As New Malware Families Target Vulnerable Systems

React2Shell vulnerability continues to face extensive exploitation, with multiple malware families and automated attack activity targeting organizations worldwide.

Gladinet CentreStack And Triofox Flaw Actively Exploited Through Hard Coded Cryptographic Keys

Huntress reports active exploitation of a newly uncovered Gladinet CentreStack and Triofox vulnerability linked to hard coded cryptographic keys, enabling unauthorized access and remote code execution across affected systems.

Fortinet Ivanti And SAP Address Critical Vulnerabilities In Enterprise Software

Fortinet, Ivanti, and SAP have released security updates to fix critical vulnerabilities in their products, including authentication bypass, code execution, and JavaScript injection flaws, urging organizations to patch promptly.

Zero-Day Exploits Breach MITRE’s Unclassified Research Network

The MITRE Corporation, a non-profit spearheading federally funded cybersecurity research, disclosed a data breach impacting its unclassified research network. This incident, attributed to a...

Recent articles

spot_img