A security researcher known as Nightmare-Eclipse, who also goes by the names Chaotic Eclipse and MSNightmare, has released a project that claims to take…
Tag: Vulnerability
Google Unveils Gemini 3.8 Flash Cyber for Autonomous Vulnerability Discovery and Automated Patching
Google has introduced Gemini 3.8 Flash Cyber, a specialized AI model focused on cybersecurity. This model is designed to autonomously identify software…
OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI
OpenAI says Astra can autonomously find zero-days and build exploits, marking its first model to reach the “Critical” cyber risk level. Astra is now…
Black Duck brings AI-powered vulnerability scanning into Claude with new Signal integration
Application security vendor Black Duck has launched its Signal vulnerability scanning engine as an MCP server in the Claude Directory, giving developers…
Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin
On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with more…
SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs
SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released…
OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days
The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems.
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)
Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans…
Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)
A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and…
Exploit Published for Fresh Cleo Harmony Vulnerability
The security defect allows remote attackers to bypass authentication through argument bearer manipulation.
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been…
SonicWall SMA 1000 appliances under attack via zero-day flaws
Attackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor…
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415…
Hackers Chain Two New SonicWall Zero-Day Vulnerabilities
SonicWall has urged customers to patch two new zero-day vulnerabilities being exploited in the wild
Hackers Target Langflow in CVE-2026-0768 Attacks
Hackers are exploiting a critical Langflow flaw that lets unauthenticated attackers remotely execute Python code on vulnerable systems. Hackers have…
Fable 5.1 released, USPS “untested” IT, Exchange hijack vulnerability
Anthropic announces safety changes and new models USPS installs “untested” IT systems for mail-in ballots Thousands of Exchange servers vulnerable to…
OpenAI’s New Astra AI Can Discover Zero-Day Security Flaws and Build Exploits
OpenAI says its upcoming Astra model has reached the company’s Critical cybersecurity capability threshold, meaning it can independently discover unknown…
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution.
Critical Ruby on Rails Vulnerability Under Active Attack | CVE-2026-66066
Cyber threat actors have begun actively exploiting a critical-severity in Ruby on Rails vulnerability, months after security researchers…
Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms
On August 9th, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, discovered an Arbitrary File Upload vulnerability in Gravity…
