Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed…
Tag: Vulnerability
Ruby on Rails Patches Critical Vulnerability
The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE).
Autonomous AI Agent Exploits Zero-Day to Breach Hugging Face Infrastructure
An autonomous AI agent powered by OpenAI models breached Hugging Face’s production infrastructure in July 2026 after escaping its evaluation sandbox via a…
Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
A Chinese-speaking threat actor has been using DeepSeek’s AI models to orchestrate cyber-attacks targeting Asian organizations
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall…
Keycloak Vulnerability Exposes User Names and Email Addresses Across Admin Boundaries
Keycloak has addressed a broken access control vulnerability that could allow restricted administrators to access usernames, email addresses, and other…
Vulnerability management needs an update for the AI era
Organizations must rethink long-held assumptions about patch management and change how they prioritize, remediate and manage cyber-risk, especially in…
CVE-2026-63077 TeamCity RCE Vulnerability
JetBrains has disclosed a critical authentication bypass vulnerability in TeamCity On-Premises that enables remote attackers to execute arbitrary…
Long-Lived Vulnerability in Microsoft Secure Boot
Microsoft’s Secure Boot has had a serious vulnerability for most of its existence. An industry-wide standard Microsoft invented to protect Windows, and…
Critical Code Execution Vulnerability Patched in TeamCity
Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol.
CosmosEscape Vulnerability Enables Full Takeover of Azure Cosmos DB Databases
A critical vulnerability chain in Azure Cosmos DB, named CosmosEscape, allowed attackers to gain full read and write access to every Cosmos DB database,…
FastJson RCE Zero-Day Actively Targets Organizations
Threat actors are actively exploiting the FastJson CVE-2026-16723 zero-day, with no patch available for affected FastJson 1.x versions.
CVE-2026-66066: Defending Against the “KindaRails2Shell” Pre-Auth RCE
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: CVE-2026-66066: Defending Against the “KindaRails2Shell” Pre-Auth RCE
Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay
Cursor has patched a high-severity Windows vulnerability that allowed malicious Git repositories to execute code, highlighting security risks in AI coding…
Wordfence Intelligence Weekly WordPress Vulnerability Report (July 20, 2026 to July 26, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to…
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation…
Public Exploit Lands for vBulletin’s Pre-Auth RCE, CVE-2026-61511
A public proof-of-concept for the vBulletin RCE vulnerability CVE-2026-61511 is now live. Here’s how the eval() injection works and who still needs to…
EShare App Vulnerability CVE-2026-55977
The Cyber Security Agency of Singapore has assigned CVE-2026-55977 to a vulnerability in EShare’s wireless screen mirroring and collaboration application.
New CosmosEscape Vulnerability Lets Attackers Take Over Azure Cosmos DB Instances
A critical vulnerability, dubbed CosmosEscape, in Microsoft Azure Cosmos DB could have let attackers seize control of virtually every database hosted on…
Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)
Russia-affiliated cyber espionage group Laundry Bear (aka Void Blizzard, aka TA488) is exploiting CVE-2026-42897, a cross-site scripting vulnerability in…
