Tag

Vulnerabilities

All articles tagged with #vulnerabilities

Citrix pushes urgent NetScaler patches to close two critical flaws
technology4 days ago

Citrix pushes urgent NetScaler patches to close two critical flaws

Citrix is urging admins to urgently patch NetScaler ADC and Gateway to fix two high-severity flaws (CVE-2026-19490 auth bypass and CVE-2026-19489 DoS via SIP ALG). Upgrades to specific builds (14.1-73.32+, 13.1-63.21+, including FIPS/NDcPP variants) are advised; admins should review the security bulletin, assess exposure, and apply updates promptly, as past NetScaler CVEs have been exploited in the wild and millions of instances remain exposed.

Galaxy security patch tightens defenses with 56 fixes in August 2026
technology19 days ago

Galaxy security patch tightens defenses with 56 fixes in August 2026

Samsung’s August 2026 security patch fixes 56 vulnerabilities across Galaxy devices (38 Google CVEs and 18 Samsung SVEs), with most fixes targeting Android 14–16 and core apps like Contacts, Dialer, Messages, and Galaxy Themes. Google delivers eight critical and 30 high-priority fixes, while Samsung adds two high, 14 moderate, and two undisclosed-priority fixes; nine Google fixes aren’t part of this patch (one already included in July 2026, eight not applicable). A worldwide rollout could begin soon.

Apple Tightens Bug-Bounty Submissions After AI-Generated Flood
technology20 days ago

Apple Tightens Bug-Bounty Submissions After AI-Generated Flood

Apple has limited the number of open bug-bounty submissions after a surge of AI-generated, low-quality reports clogs its review system. A security firm using ChatGPT surfaced dozens of macOS bugs but was limited by Apple’s caps, though researchers can request higher limits for critical issues. While AI helps parse submissions, Apple maintains large rewards for real exploits, with prizes up to $2 million and potential bonuses over $5 million; the company notes AI has both aided discovery and auditing of reports.

Chrome Patches 1,442 Flaws Across Three Releases, Accelerating AI-Driven Security Pace
technology24 days ago

Chrome Patches 1,442 Flaws Across Three Releases, Accelerating AI-Driven Security Pace

Google patched 1,442 Chrome vulnerabilities across three releases (149–151), including 370 fixes in Chrome 151, amid an AI-driven surge in bug reports; the company is pushing faster biweekly security updates, exploring dynamic patching that can minimize restarts, and hardening the codebase with memory-safe languages and automated release notes to shorten the window between discovery and disclosure.

AI-Driven Bug Boom Triggers Chrome to Patch Twice Weekly
technology25 days ago

AI-Driven Bug Boom Triggers Chrome to Patch Twice Weekly

Google Chrome’s security team is accelerating patch cadence to twice-weekly updates after AI-assisted vulnerability discovery flagged a flood of bugs, with June alone delivering fixes for 1,072 vulnerabilities—the most in a single period—and signaling a shift toward AI-driven triage, structural hardening (e.g., Rust rewrites), and a new normal of frequent security updates.

WordPress under attack: chained flaws enable pre-auth remote code execution after patches
technology1 month ago

WordPress under attack: chained flaws enable pre-auth remote code execution after patches

After WordPress released patches for CVE-2026-60137 (SQL injection) and CVE-2026-63030 (REST API route confusion), attackers quickly weaponized both flaws to enable unauthenticated remote code execution. Public PoCs and AI-assisted tooling spurred rapid exploitation, with tens of thousands of attempts and hundreds of backdoor admin accounts, fake plugins, and attempts to fetch tools like Overlord RAT. WordPress also forced auto-updates for affected sites. Patches are in WordPress 6.9.5 and 7.1 Beta 2 (6.8.6 for the SQLi; older versions affected differently). Admins should patch immediately and audit for backdoors and suspicious plugins.

Major updates patch critical flaws across Firefox, Chrome, Adobe apps, and VMware
technology1 month ago

Major updates patch critical flaws across Firefox, Chrome, Adobe apps, and VMware

Mozilla patched two critical Firefox flaws (CVE-2026-15718/15719) with exploit code public; Google Chrome fixed 15 bugs including two critical Ozone use-after-free issues (CVE-2026-15764/15765). Adobe released security updates addressing 88 vulnerabilities across ColdFusion, Commerce/Magento, Experience Manager, and Illustrator (with several high-severity CVEs). Broadcom also fixed a critical authentication-bypass in VMware Avi Load Balancer (CVE-2026-47865). None are listed as actively exploited yet, but updates are advised as attackers often weaponize these flaws.

Actively Exploited SharePoint Flaws Prompt Urgent Patch Alert
technology1 month ago

Actively Exploited SharePoint Flaws Prompt Urgent Patch Alert

CISA warns that three on‑premises SharePoint Server flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) are being actively exploited to bypass authentication and run remote code, with attackers targeting unpatched systems. Microsoft also patched CVE-2026-55040 and CVE-2026-58644. Shadowserver reports thousands of exposed SharePoint servers, prompting urgent patching, hardened logging, AMSI/Defender integration, and limiting internet exposure. Federal agencies have a July 17 deadline under BOD 26-04 to patch CVE-2026-56164. Since 2021, CISA has flagged 11 exploited Microsoft SharePoint vulnerabilities (7 linked to ransomware).

SonicWall SMA1000 Zero-Days Exploited; Critical Patch Released
security1 month ago

SonicWall SMA1000 Zero-Days Exploited; Critical Patch Released

SonicWall warns that two SMA1000 flaws (CVE-2026-15409 SSRF and CVE-2026-15410 code execution) are being actively exploited in zero-day attacks; a patch is now available for affected SMA1000 models (6210, 7210, 8200v) via hotfix releases, with IOCs provided to detect compromise; if compromised, reimage or redeploy, reset passwords and rotate TOTP tokens; there are no mitigations outside applying the hotfix; CISA added the flaws to KEV and federal agencies must patch by July 17, 2026 under BOD 26-04.

technology-security1 month ago

Microsoft patches a record 570 flaws in AI-augmented Patch Tuesday

Microsoft released a record Patch Tuesday fixing at least 570 vulnerabilities across Windows and related software, driven by AI-driven vulnerability discovery; about 60 are critical and three zero-days are already being exploited. Highlights include CVE-2026-56155 (Active Directory Federation Services), CVE-2026-56164 (SharePoint), and CVE-2026-50661 (BitLocker bypass), plus a Copilot remote code execution flaw (CVE-2026-48561). Industry experts warn exploitability ratings may lag AI-enabled discovery as patch cadences rise across vendors. Users are advised to back up systems and consider delaying updates if stability is a concern.

AI-Driven Flaw Hunting to Drive More Windows Security Patches
technology1 month ago

AI-Driven Flaw Hunting to Drive More Windows Security Patches

Microsoft says AI-powered vulnerability discovery is accelerating the identification of Windows flaws, leading to more security updates in each Patch Tuesday. Its MDASH system scans critical Windows binaries, validates findings with multiple AI models, and reduces false positives before engineers review and ship fixes. The company is also updating Secure Development Lifecycle practices to account for AI-enabled attacks, and CISA is using Anthropic's Fable AI for government software audits, highlighting a broader trend toward AI-assisted cybersecurity.

Emergency Chrome Patch Closes In-the-Wild Zero-Day Exploit
cyber-security2 months ago

Emergency Chrome Patch Closes In-the-Wild Zero-Day Exploit

Google issued an emergency Chrome security update (Windows/macOS: 149.0.7827.102/103; Linux: 149.0.7827.102) patching 74 vulnerabilities, including a critical zero-day in the V8 engine that was observed exploited in the wild (CVE-2026-11645). The release also fixes 17 Critical flaws across core subsystems after a broad security audit, with many use-after-free memory issues that could enable remote code execution. An external researcher “303f06e3” discovered the zero-day, for which Google awarded $55,000; update guidance is to manually install the patch now via Help → About Google Chrome and relaunch, with enterprise admins urged to push the update to endpoints promptly as automatic rollout continues.