Back to Feed

Tag

Vulnerabilities

50 items tagged #vulnerabilities

Articles

Data Leakage Vulnerability Patched in OpenSSL

Seven vulnerabilities patched in OpenSSL, including moderate-severity data leakage flaw.

RCE Bug Lurked in Apache ActiveMQ Classic for 13 Years

13-year-old RCE vulnerability in Apache ActiveMQ Classic can be chained with authentication bypass flaw.

Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems

Anthropic's Claude Mythos AI model discovers thousands of zero-day vulnerabilities across major systems.

Related archive contains legit signed WinWord.exe from Microsoft to load a malicious "AppvIsvSubs...

Legitimate signed WinWord.exe used to load malicious AppvIsvSubsystems64.dll

Daily Dose of Dark Web Informer - April 7th, 2026

Daily dark web threat intelligence digest covering breaches, CVEs, and threat actor activity.

Tech giants launch AI-powered ‘Project Glasswing’ to identify critical software vulnerabilities

Tech giants launch Project Glasswing, an AI initiative to identify critical software vulnerabilities before malicious

Russia Hacked Routers to Steal Microsoft Office Tokens

Russia's GRU-linked Forest Blizzard hacks routers to mass-harvest Microsoft Office authentication tokens from 18,000

Max severity Flowise RCE vulnerability now exploited in attacks

Max-severity RCE vulnerability CVE-2025-59528 in Flowise AI platform actively exploited.

Severe StrongBox Vulnerability Patched in Android

Android security updates patch critical DoS flaw and high-severity StrongBox keystore vulnerability.

🚨 The UK has exposed Russian military intelligence targeting vulnerable routers to support cyber...

UK NCSC exposes APT28 exploiting vulnerable routers for DNS hijacking operations.

Medusa Ransomware Fast to Exploit Vulnerabilities, Breached Systems

Medusa ransomware group exploits zero-days and fresh vulnerabilities to breach 300+ organizations within days.

Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed

Flowise AI platform CVE-2025-59528 (CVSS 10.0) RCE under active exploitation; 12,000+ instances exposed.

Fortinet customers confront actively exploited zero-day, with a full patch still pending

Fortinet FortiClient EMS zero-day CVE-2026-35616 actively exploited; hotfix released, full patch pending.

Fortinet Issues Emergency Patch for FortiClient Zero-Day

Fortinet releases emergency patch for FortiClient authentication bypass zero-day CVE-2026-35616.

Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit

Security researcher leaks unpatched BlueHammer Windows privilege escalation zero-day exploit code.

CVE-2026-35616: FortiClient EMS Pre-Auth API Bypass Under Active Exploitation

CVE-2026-35616: FortiClient EMS pre-auth API bypass actively exploited in the wild.

‼️ CVE-2026-35616: FortiClient EMS Pre-Auth API Bypass Under Active Exploitation https://t.co/YN...

CVE-2026-35616 FortiClient EMS pre-auth API bypass actively exploited in the wild.

Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations

Storm-1175 exploits recently disclosed vulnerabilities to deploy Medusa ransomware in high-velocity campaigns.

Google DeepMind Researchers Map Web Attacks Against AI Agents

Google DeepMind researchers identify six classes of web-based attacks against autonomous AI agents.

Fortinet Rushes Emergency Fixes for Exploited Zero-Day

Fortinet patches critical zero-day RCE in FortiClient EMS allowing unauthenticated remote code execution.

New FortiClient EMS flaw exploited in attacks, emergency patch released

Fortinet releases emergency patch for actively exploited FortiClient EMS pre-auth RCE flaw.

Hackers exploit React2Shell in automated credential theft campaign

Hackers exploit React2Shell CVE in Next.js apps to steal credentials from 766 compromised hosts.

Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS

Fortinet patches actively exploited CVE-2026-35616 zero-day in FortiClient EMS.

🚦SentinelOne’s AI EDR autonomously stops a zero-day attack, Axios Supply Chain Attack Spreads Ac...

SentinelOne AI EDR blocks zero-day; Axios supply chain attack hits npm/PyPI; Chrome zero-day exploited.

Double Agents: Exposing Security Blind Spots in GCP Vertex AI

Unit 42 discovers privilege escalation flaw in GCP Vertex AI allowing compromised agents to exfiltrate data.

TrueConf Zero-Day Exploited in Asian Government Attacks

Chinese hackers exploit TrueConf zero-day in Asian government attacks via compromised update server.

In Other News: ChatGPT Data Leak, Android Rootkit, Water Facility Hit by Ransomware

SecurityWeek roundup: Android rootkit, ChatGPT data leak, water facility ransomware, FBI breach.

React2Shell Exploited in Large-Scale Credential Harvesting Campaign

UAT-10608 exploits React2Shell vulnerability to compromise 766 systems and harvest credentials at scale.

Akira ransomware group can achieve initial access to data encryption in less than an hour

Akira ransomware group achieves initial access to encryption in under one hour with polished attack lifecycle.

Residential proxies evaded IP reputation checks in 78% of 4B sessions

Residential proxies evaded IP reputation checks in 78% of 4B malicious sessions over three months.

Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise

Cisco patches critical 9.8 CVSS flaws in IMC and SSM allowing unauthenticated remote system compromise.

Cisco Patches Critical and High-Severity Vulnerabilities

Cisco patches two critical and six high-severity vulnerabilities across multiple products.

Possible US Government iPhone Hacking Tool Leaked - Schneier on Security

Google researchers reveal Coruna, sophisticated iPhone hacking toolkit allegedly developed by US government contractor

Possible US Government iPhone Hacking Tool Leaked https://t.co/3ypPIw1Tq3

Alleged US government iPhone hacking tool reportedly leaked online.

Over 14,000 F5 BIG-IP APM instances still exposed to RCE attacks

Over 14,000 F5 BIG-IP APM instances exposed to actively exploited RCE vulnerability CVE-2025-53521.

Apple expands iOS 18 updates to more iPhones to block DarkSword attacks

Apple expands iOS 18.7.7 availability to block actively exploited DarkSword exploit kit.

Hackers exploit TrueConf zero-day to push malicious software updates

Hackers exploit TrueConf zero-day to push malicious software updates via fake updates.

Apple Pushes Rare iOS 18 Patch for Devices at Risk from DarkSword Exploit

Apple releases iOS 18 patch to block DarkSword exploit affecting older iPhones.

Chrome Zero-Day CVE-2026-5281: A Use-After-Free in Dawn's WebGPU Layer

Google patches CVE-2026-5281, an actively exploited use-after-free in Chrome's WebGPU layer.

‼️ Chrome Zero-Day CVE-2026-5281: A Use-After-Free in Dawn's WebGPU Layer https://t.co/u4AM1BJjPN

Chrome zero-day CVE-2026-5281 use-after-free vulnerability discovered in Dawn WebGPU layer.

FulcrumSec Breaches Unique Computing, ReFocus AI, and Gennet AI Exposing 23,000 Insurance Policyholders, $797M in Premiums, Driver Licenses, SSNs, and Proprietary ML Models From a Single Unpatched AWS Account

FulcrumSec breaches three AI/insurance firms via unpatched CVE, exposes 23K policyholders and $797M in premiums.

‼️🇺🇸 Threat actor "FulcrumSec" claims breach of Unique Computing LLC / https://t.co/Rs6arKdl2E...

Threat actor FulcrumSec claims breach of Unique Computing LLC via unpatched CVE-2025-55182.

Exploited Zero-Day Among 21 Vulnerabilities Patched in Chrome

Google patches Chrome 146 with 21 vulnerabilities including exploited zero-day CVE-2026-5281.

US Charges Uranium Crypto Exchange Hacker

US charges Maryland man for exploiting smart contract bugs to steal $55M from Uranium Finance in 2021.

New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation — Patch Released

Google patches actively exploited Chrome zero-day CVE-2026-5281 use-after-free in WebGPU Dawn.

ImageMagick Zero-Day Enables RCE on Linux and WordPress Servers

ImageMagick zero-day enables RCE via crafted image uploads on Linux and WordPress servers.

Google fixes fourth Chrome zero-day exploited in attacks in 2026

Google patches fourth Chrome zero-day (CVE-2026-5281) exploited in active attacks in 2026.

Google Addresses Vertex Security Issues After Researchers Weaponize AI Agents

Palo Alto researchers weaponize Google Vertex AI agents, exposing excessive service account permissions and insider

Apple Will Push Out Rare ‘Backported’ Patches to Protect iOS 18 Users From DarkSword Hacking Tool

Apple backports iOS 18 patches for DarkSword exploit after widespread abuse by multiple threat actors.

Google's Vertex AI Has an Over-Privileged Problem

Palo Alto researchers reveal over-privileged Vertex AI agents could enable data theft and cloud infrastructure