The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication.
Category: securityweek
Astrana Health Data Breach Impacts Private, Confidential Information
Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers.
US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks
Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims.
Critical WordPress Vulnerability Exploited Immediately After Disclosure
Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code.
IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU Decoder
IonQ’s new single processor quantum error decoder minimizes the classical computing overhead in quantum error correction.
IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin
IonQ’s new single processor quantum error decoder minimizes the classical computing overhead in quantum error correction.
Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios
The idea that AI could break away and work toward its own agenda is looking increasingly plausible to researchers and experts.
Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare
Only 21% of industrial security leaders report a complete OT asset inventory, even as 88% call their programs mature.
Adobe Patches Critical Flaws in Connect, AEM Forms
The nine critical security defects could be exploited for arbitrary code execution and privilege escalation.
AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft
The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets.
Chrome 154 Patches 108 Vulnerabilities
The browser update resolves several critical-severity memory safety and memory corruption flaws.
Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm
Emerging from stealth with $16 million in pre-seed funding, Outerlimit offers a decentralized authorization layer designed to discover, observe, and block…
A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk
Debates over the plausibility of these doomsday scenarios have heated up since several executives endorsed slowing the technology’s development for safety…
Arista Urges Immediate Patching of Exploited VCO Zero-Day
Remote attackers could trigger the critical-severity flaw to access privileged internal functionality.
Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution.
ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
The cybercrime group is unhappy with its description in an FBI report and threatens to leak stolen information.
Check Point Patches Exploited Management Server Zero-Day
The critical-severity flaw could allow unauthenticated attackers to upload and execute arbitrary scripts.
BigCommerce Data Stolen via Ribon Apps Hack
The attackers used a compromised BigCommerce application key held by Ribon to access customer data.
Cyera Raises $400 Million at $12+ Billion Valuation
The data security company received the new investment from Goldman Sachs Alternatives, extending its Series G funding round.
Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity
Abdelhamid Naceri, a former Microsoft Germany employee, is the exploit leaker Nightmare Eclipse, aka Chaotic Eclipse.
