Articles tagged "Vulnerability"

Found 1435 articles

Last week, it was reported that a pre-authentication remote code execution (RCE) vulnerability in ServiceNow was actively exploited in the wild. This vulnerability allows attackers to execute arbitrary code on affected systems without needing to authenticate, posing significant risks to organizations using the platform. In a separate incident, Hugging Face, a popular AI community, experienced a data breach, although details about the extent of the breach and the data compromised have not been fully disclosed. These incidents highlight ongoing security challenges for companies leveraging AI and cloud services, as they must remain vigilant against potential exploits that can have serious consequences for their operations and data integrity.

Read Original

Security researchers have released exploit code for a vulnerability in GitLab that allows authenticated users to execute commands as the 'git' user on certain self-managed servers. This flaw affects GitLab version 18.11.3 and earlier, which had a patch issued on June 10, 2023. If a user can push to a project, they can exploit the vulnerability by committing a specially crafted Jupyter notebook. This action reveals sensitive heap memory data, enabling unauthorized command execution. Organizations using vulnerable versions of GitLab should prioritize applying the patch to prevent potential abuse of this exploit, especially in environments where multiple users have access to project repositories.

Read Original

Researchers have discovered multiple remote code execution (RCE) vulnerabilities in several versions of Redis, a widely used in-memory data structure store. The vulnerabilities affect Redis versions 6.2.22, 7.4.9, 8.6.4, and 8.8.0, with specific exploitation chains requiring commands like RESTORE, EVAL, and XGROUP. Redis confirmed that these memory flaws could allow attackers to execute arbitrary code remotely. In response, Redis released seven security updates on July 23 to address these issues, including versions 6.2.23, 7.2.15, and 7.4.10. Users of these affected versions need to update their systems promptly to protect against potential exploitation.

Read Original

A Russian espionage group known as Laundry Bear has been exploiting a zero-day vulnerability in Zimbra for five months before it was patched in July 2025. Despite the patch, the group continues to target vulnerable systems to steal sensitive data from Western countries. This ongoing activity raises concerns about the security of email platforms and the potential for data breaches that could affect numerous organizations. As companies rely on these systems for communication, the implications of such attacks could be significant, leading to unauthorized access to confidential information. Organizations using Zimbra should prioritize updating their systems to protect against this threat.

Read Original

U.S. officials and their allies have reported that Russian hackers successfully accessed email accounts belonging to government and private sector organizations without using social engineering tactics. This incident raises concerns as it indicates a sophisticated level of technical skill and planning, allowing attackers to infiltrate systems without tricking users into revealing their credentials. The breach reportedly involved the exploitation of a vulnerability in a widely used software, though specific details about the software have not been disclosed. This attack could pose risks to sensitive information and disrupt operations within affected organizations. The incident emphasizes the ongoing threat posed by state-sponsored cyber actors and the need for enhanced cybersecurity measures across various sectors.

Read Original

Russian hackers have reportedly launched a state-backed campaign targeting Western organizations by exploiting a serious vulnerability in the Zimbra Collaboration Suite. This 'zero-click' attack allows hackers to gain access without any user interaction, making it particularly dangerous. International agencies have issued a joint alert, urging organizations using Zimbra to take immediate precautions. The vulnerability is significant, as it can lead to unauthorized access to sensitive data. Companies and users utilizing this software need to stay vigilant and ensure their systems are updated to protect against potential breaches.

Read Original

Researchers have discovered a serious vulnerability in Anthropic's Claude Cowork that allows the AI agent to escape its Linux virtual machine (VM) environment. This flaw could enable the agent to access and manipulate files stored on the host Mac, potentially compromising user data. Approximately 500,000 macOS users are affected by this issue, as the vulnerability could be exploited by malicious actors. The implications are significant because it undermines the security measures designed to isolate applications from sensitive information on users' machines. Users are advised to stay alert for updates and patches that address this vulnerability.

Read Original
High
Rockwell Automation ThinManager

All CISA Advisories

Rockwell Automation's ThinManager software has a significant vulnerability that allows authenticated attackers to write files to restricted directories outside the intended application area. This issue affects several versions, specifically ThinManager versions 13.0.0 through 14.0.2. Users who cannot upgrade to the patched versions—13.1.6, 13.2.5, and 14.0.3—are advised to follow security best practices provided by Rockwell. The vulnerability, classified as a path traversal issue, has a high severity score of 8.1. Although no known active exploitation of this vulnerability has been reported, organizations should remain vigilant and implement defensive measures to protect their control systems.

Read Original

Johnson Controls has reported significant vulnerabilities in its C-CURE 9000 and Victor application server software that could allow attackers to execute arbitrary code remotely. Specifically, versions of the C-CURE 9000 and Victor applications up to v2.90_v3.0 and Victor Web versions up to v7.1 are impacted. An attacker on an adjacent network could exploit these flaws to compromise physical security controls and access sensitive information. The vulnerabilities have been assigned high to critical severity scores, highlighting the urgency for affected users to take action. Johnson Controls recommends upgrading to the latest versions and implementing various security measures to mitigate risks.

Read Original
Actively Exploited

Check Point Software, an Israeli cybersecurity firm, has reported a zero-day vulnerability in its SmartConsole admin panel that is currently being exploited by attackers. This flaw allows unauthorized access to the graphical user interface, potentially leading to significant security breaches. Organizations using SmartConsole are at risk, as the vulnerability could enable attackers to manipulate settings or extract sensitive information. The firm has urged users to take immediate action to protect their systems, highlighting the urgency of the situation. It's crucial for affected users to stay informed and implement any necessary security measures to mitigate potential risks.

Read Original

Check Point has issued security updates to fix several vulnerabilities affecting its Security Management and Multi-Domain Management (MDSM) products. Among these is a serious flaw, identified as CVE-2026-16232, which has a CVSS score of 9.3 and allows attackers to bypass authentication in the SmartConsole login process. This vulnerability is particularly concerning as it is currently being exploited in the wild, meaning malicious actors can gain full administrative access to affected systems. Companies using Check Point's management products need to apply these updates promptly to protect their environments from unauthorized access. The timely response to this patch is crucial for maintaining security integrity.

Read Original

A ransomware attack on a Japanese food and logistics company has severely disrupted the supply of frozen food to thousands of clients, including well-known franchises like Kentucky Fried Chicken. The attack has caused significant delays and shortages, affecting the availability of products in various locations. This incident highlights the vulnerability of food supply chains to cyber threats, which can have wide-reaching consequences on businesses and consumers alike. Companies in the food industry are now faced with the challenge of enhancing their cybersecurity measures to prevent similar attacks in the future. The situation is ongoing, and more details about the attack and its impact are expected to emerge.

Read Original

Researchers have identified a significant security flaw in the snap-confine tool used in Ubuntu desktop environments. This local privilege escalation vulnerability, tracked as CVE-2026-8933, allows unprivileged users to gain root access on default installations of Ubuntu Desktop versions 24.04, 25.10, and 26.04. With a CVSS score of 7.8, the flaw is considered high severity, meaning it poses a serious risk to affected systems. If exploited, an attacker could take full control of the system, potentially leading to data breaches or system compromise. Users of these Ubuntu versions should be aware of this vulnerability and take necessary precautions while awaiting a fix.

Read Original

Cybersecurity researchers have identified a serious vulnerability in the Adobe Acrobat Chrome extension, which has around 314 million users. This flaw, known as HermeticReader and tracked as CVE-2026-48294, could allow malicious websites to access users' WhatsApp Web data without their knowledge. The vulnerability has a CVSS score of 7.4, indicating it poses a significant risk. Adobe has patched this issue, but it raises concerns about the security of extensions and the potential for data breaches. Users of the Adobe Acrobat extension should ensure they have updated to the latest version to protect their data.

Read Original
Critical
First-Person Identity Theft Story

Schneier on Security

Actively Exploited

The article recounts the experience of an individual who fell victim to identity theft after inadvertently providing a two-factor authentication code to a scammer. This mistake allowed the attacker to gain control of the victim's email account, leading to a cascade of security issues. The story illustrates a critical vulnerability many people face: the security of their online accounts often hinges on the protection of their email. When scammers compromise an email account, they can reset passwords and access sensitive information across various platforms. This incident serves as a cautionary tale about the importance of safeguarding personal information and being vigilant against phishing attempts.

Read Original
Page 1 of 96Next