Security Cisco serves up yet another perfect 10 bug with Secure Workload admin flaw Switchzilla says attackers could access sensitive data and make configuration changes across tenant boundaries through vulnerable internal APIs
Security Clear your calendar, Drupal user: You have a critically urgent patch to install The org’s staying mum on the details, but Wednesday’s fixes reach back to unsupported 8.9 branches
Security NGINX Rift attackers waste no time targeting exposed servers Researchers say 18-year-old flaw already being probed and exploited just days after disclosure
Cyber-crime First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed Exploitation was underway before patches landed, at least one victim reports ransomware demand
Patches Bug of the year (so far): Nasty cPanel vulnerability probably exploited as a 0-day Emergency patches out now for those managing the millions of domains assumed to be affected
Security CISA flags data-theft bug in NSA-built OT networking tool GrassMarlin leaks sensitive information, provided your targeting phishing skills are sharp enough
Security GitHub: Zounds, a genuinely helpful AI-assisted bug report that isn't total slop! Here, Wiz, take this wad of cash Claude ploughs through months of work in rapid time, helps Wiz researchers nab lucrative award
Security Nobody knows how many CVEs Anthropic's Project Glasswing has actually found Like the majority of the companies participating, it remains a mystery
Patches Ancient Excel bug comes out of retirement for active attacks Vuln old enough to drive lands on CISA's exploited list
OSes Adobe finally patches PDF pest after months of abuse Reader and Acrobat flaw let booby-trapped documents profile targets and hijack machines
Security Project Glasswing and open source software: The good, the bad, and the ugly Just what FOSS developers need – a flood of AI-discovered vulnerabilities
Cyber-crime Months-old Adobe Reader zero-day uses PDFs to size up targets Malicious PDFs abuse legit features to harvest system data and decide which victims get a 2nd-stage payload
Patches Citrix NetScaler bug exploited in days, may be multiple flaws in a trench coat Researchers say attackers are already looting vulnerable boxes
Cyber-crime AFC Ajax drops ball as flaws let hackers play admin with tickets and bans Vulns in Dutch football club's systems didn't just expose data – they let outsiders play with accounts, and even lift stadium bans
Patches Google rushes Chrome update fixing two zero-days already under attack Skia graphics lib and V8 JavaScript engine brings browser's tally of actively exploited bugs to three in 2026
Cyber-crime CISA warns max-severity n8n bug is being exploited in the wild No rest for project maintainers battered by slew of vulnerability disclosures
Cyber-crime Crooks compromise WordPress sites to push infostealers via fake CAPTCHA prompts Rapid7 says crims broke into more than 250 sites globally, including a US Senate candidate’s campaign page
AI + ML Microsoft Azure CTO set Claude on his 1986 Apple II code, says it found vulns This isn't just a nostalgia trip – billions of legacy microcontrollers may be at risk
Cyber-crime Cisco warns of two more SD-WAN bugs under active attack Switchzilla says flaws could allow file overwrites or privilege escalation
Security Chrome Gemini panel became privilege escalator for rogue extensions High-severity flaw let malicious add-ons access system via browser's embedded AI feature
Patches CISA gives federal agencies three days to patch actively exploited Dell bug Hardcoded credential flaw in RecoverPoint already abused in espionage campaign
Security Google patches Chrome zero-day as in-the-wild exploits surface High-severity CSS flaw let malicious webpages run code inside the sandbox
Cyber-crime Apple patches decade-old iOS zero-day, possibly exploited by commercial spyware Flaw abused 'in an extremely sophisticated attack against specific targeted individuals'
Security Were telcos tipped off to *that* ancient Telnet bug? Cyber pros say the signs stack up Curious port filtering and traffic patterns suggest advisories weren’t the earliest warning signals sent
Security Notepad's new Markdown powers served with a side of remote code execution Smug faces across all those who opposed the WordPad-ification of Microsoft's humble text editor
Security More than 135,000 OpenClaw instances exposed to internet in latest vibe-coded disaster By default, the bot listens on all network interfaces, and many users never change it
CSO CISA updated ransomware intel on 59 bugs last year without telling defenders GreyNoise's Glenn Thorpe counts the cost of missed opportunities
Security January blues return as Ivanti coughs up exploited EPMM zero-days Consider yourselves compromised, experts warn
Security Fortinet unearths another critical bug as SSO accounts borked post-patch More work for admins on the cards as they await a full dump of fixes
Security Old Windows quirks help punch through new admin defenses Google researcher sits on UAC bypass for ages, only for it to become valid with new security feature
CSO Fortinet admits FortiGate SSO bug still exploitable despite December patch Fix didn't quite do the job – attackers spotted logging in
Patches Ancient telnet bug happily hands out root to attackers Critical vuln flew under the radar for a decade
Cyber-crime RondoDox botnet linked to large-scale exploit of critical HPE OneView bug Check Point observes 40K+ attack attempts in 4 hours, with government organizations under fire
Virtualization China-linked cybercrims abused VMware ESXi zero-days a year before disclosure Huntress analysis suggests VM escape bugs were already weaponized in the wild
Cyber-crime CISA flags actively exploited Office relic alongside fresh HPE flaw Max-severity OneView hole joins a PowerPoint bug that should've been retired years ago
Patches Maximum-severity n8n flaw lets randos run your automation server Unauthenticated RCE means anyone on the network can seize full control
Security Trump admin sends heart emoji to commercial spyware makers with lifted Predator sanctions Also, Korean Air hacked, EmEditor installer hijacked, a perfect 10 router RCE vuln, and more
Security Brit lands invite-only Aussie visa after uncovering vuln in government systems Jacob Riggs is set to swap London for Sydney some time in the next year
Patches An early end to the holidays: 'Heartbleed of MongoDB' is now under active exploit You didn't think you'd get to enjoy your time off without a major cybersecurity incident, did you?
Security Google sends Dark Web Report to its dead services graveyard PLUS: Texas sues alleged TV spies; The Cloud is full of holes; Hospital leaked its own data; And more
Cyber-crime Another bad week for SonicWall as SMA 1000 zero-day under active exploit Flaw in remote-access appliance lets attackers chain bugs for root-level takeover
Security Honeypots can help defenders, or damn them if implemented badly PLUS: Crims could burn your AI budgets thanks to weak defaults; CISA's top 25 vulns for 2025; And more
Cyber-crime Half of exposed React servers remain unpatched amid active exploitation Wiz says React2Shell attacks accelerating, ranging from cryptominers to state-linked crews
Security Microsoft won't fix .NET RCE bug affecting slew of enterprise apps, researchers say Devs and users should know better, Microsoft tells watchTowr
Patches Microsoft quietly shuts down Windows shortcut flaw after years of espionage abuse Silent Patch Tuesday mitigation ends ability to hide malicious commands in .lnk files
CSO CISA orders feds to patch Oracle Identity Manager zero-day after signs of abuse Agencies have until December 12 to mitigate flaw that was likely exploited before Big Red released fix
Security AMD red-faced over random-number bug that kills cryptographic security Local privileges required to exploit flaw in Ryzen and Epyc CPUs. Some patches available, more on the way
Security Invasion of the message body snatchers! Teams flaw allowed crims to impersonate the boss Check Point lifts lid on a quartet of Teams vulns that made it possible to fake the boss, forge messages, and quietly rewrite history
Patches Docker Compose vulnerability opens door to host-level writes – patch pronto Windows Desktop installer also fixed after DLL hijack flaw rated 8.8 severity
Research Researchers exploit OpenAI's Atlas by disguising prompts as URLs NeuralTrust shows how agentic browser can interpret bogus links as trusted user commands
Cyber-crime Ex-CISA head thinks AI might fix code so fast we won't need security teams Jen Easterly says most breaches stem from bad software, and smarter tech could finally clean it up
Patches Microsoft drops surprise Windows Server patch before weekend downtime You didn't have plans, did you?
Patches Forking confusing: Vulnerable Rust crate exposes uv Python packager Forks of forks of forks, but which ones are patched?
Cybersecurity Month MCP attack abuses predictable session IDs to hijack AI agents The vuln affects the Oat++ MCP implementation
Cyber-crime Feds flag active exploitation of patched Windows SMB vuln CISA adds high-severity flaw to KEV list, urges swift updating
Security Microsoft kills 9.9-rated ASP.NET Core bug – 'our highest ever' score Flaw in Kestrel web server allowed request smuggling, impact depends on hosting setup and application code
Cybersecurity Month Zero-day in file-sharing software leads to RCE, and attacks are ongoing Usually we’d say patch up… not this time
Cybersecurity Month Hacking contest kerfuffle over copied rules pits Wiz against ZDI 'Seems like you should at least run that through ChatGPT to reword it'
Patches ‘An attacker's playground:’ Crims exploit GoAnywhere perfect-10 bug Researchers say tens of thousands of instances remain publicly reachable
Patches UK and US security agencies order urgent fixes as Cisco firewall bugs exploited in wild CISA gives feds 24 hours to patch, NCSC urges rapid action as flaws linked to ArcaneDoor spies
Security OnePlus leaves researchers on read over Android bug that exposes texts Rapid7 warns flaw could let any app peek at your SMS, but smartphone vendor won't pick up
Patches Ding ding: Fortra rings the perfect-10 bell over latest GoAnywhere MFT bug Outside experts say the vulnerability has probably already been exploited
Security One token to pwn them all: Entra ID bug could have granted access to every tenant Until Microsoft lobbed it into a virtual volcano
Patches Commvault releases patches for two nasty bug chains after exploits proven Researchers disclosing their findings said 'it's as bad as it sounds'
Personal Tech Intel ghosts researcher who found web apps spilled 270K staff records Chipzilla quietly fixed the problems without responding to the person who found them
Patches Chained bugs in Nvidia's Triton Inference Server lead to full system compromise Wiz Research details flaws in Python backend that expose AI models and enable remote code execution
Patches Microsoft patches critical SharePoint 2016 zero-days amid active exploits Admins urged to rotate machine keys, restart IIS after emergency fix
Patches CVSS 10 RCE in Wing FTP exploited within 24 hours, security researchers warn Intruders looked up how to use curl mid-attack - rookie errors kept damage minimal
Research Cl0p cybercrime gang's data exfiltration tool found vulnerable to RCE attacks Experts say they don't expect the MOVEit menace to do much about it
Datacenter Networking Nexus Cisco fixes two critical make-me-root bugs on Identity Services Engine components A 10.0 and a 9.8 – these aren’t patches to dwell on
Security The vulnerability management gap no one talks about If an endpoint goes ping but isn't on the network, does anyone hear it?
Security Asana's cutting-edge AI feature ran into a little data leakage problem New MCP server was shut down for nearly two weeks
Patches Veeam patches third critical RCE bug in Backup & Replication in space of a year Version 13 can’t come soon enough
Patches Sitecore CMS flaw let attackers brute-force 'b' for backdoor Hardcoded passwords and path traversals keeping bug hunters in work
Security Apple fixes zero-click exploit underpinning Paragon spyware attacks Zero-day potentially tied to around 100 suspected infections in 2025 and a spyware scandal on the continent
Datacenter Networking Nexus Ivanti makes dedicated fans of Chinese spies who just can't resist attacking its buggy kit If it ain't broke?
Patches Freshly discovered bug in OpenPGP.js undermines whole point of encrypted comms Update before that proof-of-concept comes to bite
Patches Ivanti patches two zero-days under active attack as intel agency warns customers Vendor says vulns are linked with 2 mystery open source libraries integrated into EPMM product
Security As US vuln-tracking falters, EU enters with its own security bug database EUVD comes into play not a moment too soon
Security Curl project founder snaps over deluge of time-sucking AI slop bug reports Lead dev likens flood to 'effectively being DDoSed'
Research Enterprise tech dominates zero-day exploits with no signs of slowdown As Big Tech gets used to the pain, smaller vendors urged to up their game
Security Samsung admits Galaxy devices can leak passwords through clipboard wormhole PLUS: Microsoft fixes messes China used to attack it; Mitre adds ESXi advice; Employee-tracking screenshots leak; and more!
CSO Amid CVE funding fumble, 'we were mushrooms, kept in the dark,' says board member What next for US-bankrolled vulnerability tracker? It's edging closer to a more independent, global future
Patches Emergency patch for potential SAP zero-day that could grant full system control German software giant paywalls details, but experts piece together the clues
CSO Bug hunter tricked SSL.com into issuing cert for Alibaba Cloud domain in 5 steps 10 other certificates 'were mis-issued and have now been revoked'
Spotlight on RSAC CVE fallout: The splintering of the standard vulnerability tracking system has begun MITRE, EUVD, GCVE … WTF?
CSO CVE program gets last-minute funding from CISA – and maybe a new home Uncertainty is the new certainty
CSO Uncle Sam kills funding for CVE program. Yes, that CVE program Because vulnerability management has nothing to do with national security, right?
Security Old Fortinet flaws under attack with new method its patch didn't prevent PLUS: Chinese robodogs include backdoor; OpenAI helps spammer; A Dutch data disaster; And more!
Software Panic averted: It was just a bug in Atop after all Warning of possible problems sparks controversy: Was it OverDAtop?
Security CrushFTP CEO's feisty response to VulnCheck's CVE for critical make-me-admin bug Screenshot shows company head unhappy, claiming 'real CVE is pending'
Security Two simple give-me-control security bugs found in Optigo network switches used in critical manufacturing
Cyber-crime Fortinet's week to forget: Critical vulns, disclosure screw-ups, and that toothbrush DDoS attack claim