Tag

Vulnerabilities

All articles tagged with #vulnerabilities

Security researchers claim OpenAI breach via chained flaws, heightening AI-safety fears
technology20 days ago

Security researchers claim OpenAI breach via chained flaws, heightening AI-safety fears

A small cybersecurity firm Hacktron says it breached OpenAI earlier this year by chaining two unknown vulnerabilities—one in the third‑party Discourse platform and one in how OpenAI validates employees—giving access to ChatGPT accounts. OpenAI patched the flaws and paid Hacktron a $6,500 bug bounty; no harm was done. The disclosure comes as AI safety concerns surge and regulators and experts warn about security risks in AI ecosystems.

Microsoft Patch Tuesday Sets a 974-Vulnerability Record With Two Actively Exploited Windows Zero-Days
security1 month ago

Microsoft Patch Tuesday Sets a 974-Vulnerability Record With Two Actively Exploited Windows Zero-Days

Microsoft’s September Patch Tuesday patches a record 974 vulnerabilities across Windows, Office, SQL, and Developer Tools, including two zero-days actively exploited in the wild (CVE-2026-85880 and CVE-2026-81963). The fixes bring the total resolved vulnerabilities to 999 (including 25 non-Microsoft CVEs), with over 110 rated critical and the bulk involving privilege escalation, remote code execution, and information disclosure. CISA added both CVEs to the Known Exploited Vulnerabilities catalog, ordering federal agencies to apply updates by September 22, 2026. Despite the high volume, attackers’ exploitation rates remain limited, so organizations should prioritize remediation based on exposure and relevance.

Microsoft's September patch blitz shatters vulnerability records amid AI-driven bug hunting
technology1 month ago

Microsoft's September patch blitz shatters vulnerability records amid AI-driven bug hunting

Microsoft's September patch release fixes a record ~972 vulnerabilities (997 with Edge/Chromium), including 112 critical flaws and two zero-days in Windows Update and Windows Local Procedure; AI-assisted vulnerability discovery is driving these record numbers as the industry braces for AI-enabled exploits, though active exploitation remains limited so far.

Microsoft fixes 966 flaws in September 2026 Patch Tuesday, including two zero-days
technology1 month ago

Microsoft fixes 966 flaws in September 2026 Patch Tuesday, including two zero-days

Microsoft’s September 2026 Patch Tuesday addresses 966 vulnerabilities across a wide range of products, including two zero-days. Flaws span .NET, ASP.NET Core, Windows components (DNS, Kerberos, HTTP.sys, Win32K, etc.), Office, Exchange Server, SQL Server, Azure services, PowerShell, Visual Studio, and more. Flaws include remote code execution, elevation of privilege, information disclosure, and denial-of-service vectors, with several critical issues affecting important attack surfaces. Organizations should apply these patches promptly to reduce risk from both the two zero-days and the large variety of other vulnerabilities disclosed.

PaperCut Flaw Chain Enables Unauthenticated Remote Code Execution, Prompting Emergency Patch
security1 month ago

PaperCut Flaw Chain Enables Unauthenticated Remote Code Execution, Prompting Emergency Patch

Hackers chained two PaperCut NG/MF flaws—CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (unsafe dynamic class loading)—to trigger unauthenticated remote code execution and alter server configuration; after an emergency patch with further hardening, exploitation appears limited but active, with attackers using Base64-encoded commands to identify the victim and a Java class to enumerate processes and files. Organizations should remove public exposure, apply the latest patches, and restrict access to trusted networks while monitoring logs for compromise indicators.

Citrix pushes urgent NetScaler patches to close two critical flaws
technology1 month ago

Citrix pushes urgent NetScaler patches to close two critical flaws

Citrix is urging admins to urgently patch NetScaler ADC and Gateway to fix two high-severity flaws (CVE-2026-19490 auth bypass and CVE-2026-19489 DoS via SIP ALG). Upgrades to specific builds (14.1-73.32+, 13.1-63.21+, including FIPS/NDcPP variants) are advised; admins should review the security bulletin, assess exposure, and apply updates promptly, as past NetScaler CVEs have been exploited in the wild and millions of instances remain exposed.

Galaxy security patch tightens defenses with 56 fixes in August 2026
technology2 months ago

Galaxy security patch tightens defenses with 56 fixes in August 2026

Samsung’s August 2026 security patch fixes 56 vulnerabilities across Galaxy devices (38 Google CVEs and 18 Samsung SVEs), with most fixes targeting Android 14–16 and core apps like Contacts, Dialer, Messages, and Galaxy Themes. Google delivers eight critical and 30 high-priority fixes, while Samsung adds two high, 14 moderate, and two undisclosed-priority fixes; nine Google fixes aren’t part of this patch (one already included in July 2026, eight not applicable). A worldwide rollout could begin soon.

Apple Tightens Bug-Bounty Submissions After AI-Generated Flood
technology2 months ago

Apple Tightens Bug-Bounty Submissions After AI-Generated Flood

Apple has limited the number of open bug-bounty submissions after a surge of AI-generated, low-quality reports clogs its review system. A security firm using ChatGPT surfaced dozens of macOS bugs but was limited by Apple’s caps, though researchers can request higher limits for critical issues. While AI helps parse submissions, Apple maintains large rewards for real exploits, with prizes up to $2 million and potential bonuses over $5 million; the company notes AI has both aided discovery and auditing of reports.

Chrome Patches 1,442 Flaws Across Three Releases, Accelerating AI-Driven Security Pace
technology2 months ago

Chrome Patches 1,442 Flaws Across Three Releases, Accelerating AI-Driven Security Pace

Google patched 1,442 Chrome vulnerabilities across three releases (149–151), including 370 fixes in Chrome 151, amid an AI-driven surge in bug reports; the company is pushing faster biweekly security updates, exploring dynamic patching that can minimize restarts, and hardening the codebase with memory-safe languages and automated release notes to shorten the window between discovery and disclosure.

AI-Driven Bug Boom Triggers Chrome to Patch Twice Weekly
technology2 months ago

AI-Driven Bug Boom Triggers Chrome to Patch Twice Weekly

Google Chrome’s security team is accelerating patch cadence to twice-weekly updates after AI-assisted vulnerability discovery flagged a flood of bugs, with June alone delivering fixes for 1,072 vulnerabilities—the most in a single period—and signaling a shift toward AI-driven triage, structural hardening (e.g., Rust rewrites), and a new normal of frequent security updates.

WordPress under attack: chained flaws enable pre-auth remote code execution after patches
technology2 months ago

WordPress under attack: chained flaws enable pre-auth remote code execution after patches

After WordPress released patches for CVE-2026-60137 (SQL injection) and CVE-2026-63030 (REST API route confusion), attackers quickly weaponized both flaws to enable unauthenticated remote code execution. Public PoCs and AI-assisted tooling spurred rapid exploitation, with tens of thousands of attempts and hundreds of backdoor admin accounts, fake plugins, and attempts to fetch tools like Overlord RAT. WordPress also forced auto-updates for affected sites. Patches are in WordPress 6.9.5 and 7.1 Beta 2 (6.8.6 for the SQLi; older versions affected differently). Admins should patch immediately and audit for backdoors and suspicious plugins.

Major updates patch critical flaws across Firefox, Chrome, Adobe apps, and VMware
technology2 months ago

Major updates patch critical flaws across Firefox, Chrome, Adobe apps, and VMware

Mozilla patched two critical Firefox flaws (CVE-2026-15718/15719) with exploit code public; Google Chrome fixed 15 bugs including two critical Ozone use-after-free issues (CVE-2026-15764/15765). Adobe released security updates addressing 88 vulnerabilities across ColdFusion, Commerce/Magento, Experience Manager, and Illustrator (with several high-severity CVEs). Broadcom also fixed a critical authentication-bypass in VMware Avi Load Balancer (CVE-2026-47865). None are listed as actively exploited yet, but updates are advised as attackers often weaponize these flaws.

Actively Exploited SharePoint Flaws Prompt Urgent Patch Alert
technology2 months ago

Actively Exploited SharePoint Flaws Prompt Urgent Patch Alert

CISA warns that three on‑premises SharePoint Server flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) are being actively exploited to bypass authentication and run remote code, with attackers targeting unpatched systems. Microsoft also patched CVE-2026-55040 and CVE-2026-58644. Shadowserver reports thousands of exposed SharePoint servers, prompting urgent patching, hardened logging, AMSI/Defender integration, and limiting internet exposure. Federal agencies have a July 17 deadline under BOD 26-04 to patch CVE-2026-56164. Since 2021, CISA has flagged 11 exploited Microsoft SharePoint vulnerabilities (7 linked to ransomware).

SonicWall SMA1000 Zero-Days Exploited; Critical Patch Released
security2 months ago

SonicWall SMA1000 Zero-Days Exploited; Critical Patch Released

SonicWall warns that two SMA1000 flaws (CVE-2026-15409 SSRF and CVE-2026-15410 code execution) are being actively exploited in zero-day attacks; a patch is now available for affected SMA1000 models (6210, 7210, 8200v) via hotfix releases, with IOCs provided to detect compromise; if compromised, reimage or redeploy, reset passwords and rotate TOTP tokens; there are no mitigations outside applying the hotfix; CISA added the flaws to KEV and federal agencies must patch by July 17, 2026 under BOD 26-04.