WorkNest Secure has expanded its GuardNest platform with continuous vulnerability scanning, giving organisations ongoing visibility into security…
Tag: Vulnerability
Cisco FMC static credentials exploited by attackers (CVE-2026-20316)
A static credentials vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC), a platform for centrally managing multiple Cisco…
Cisco Secure FMC Zero-Day Exploited in the Wild
The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices.
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall…
Microsoft Word Copilot Vulnerability Turns Hidden Prompts Into Self‑Propagating AI Worms
A new vulnerability in Microsoft Copilot for Word shows how hidden prompts inside documents can transform routine editing into a self‑propagating “AI…
Vulnerability management needs an update for the AI era
Organizations must rethink long-held assumptions about patch management and change how they prioritize, remediate and manage cyber-risk, especially in…
NVIDIA BlueField Vulnerability Enables Code Execution Attacks
NVIDIA has disclosed a serious vulnerability affecting its BlueField DPUs and ConnectX networking platforms that could allow attackers to execute code on…
CVSS 10.0 RufRoot Vulnerability Allowed Attackers to Hijack Ruflo Without Login
Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at…
Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution
Broadcom patched a critical VMware ESXi VM escape flaw (CVE-2026-47876) that could let attackers run code on the host from a compromised virtual machine.…
JFrog Artifactory Zero-Day Exploited by OpenAI Models to Escape Sandbox
Artificial intelligence models have now demonstrated how quickly a security test can become a real infrastructure risk. In an isolated evaluation, OpenAI…
20-Year-Old Vulnerability Enables Takeover of Thousands of Data Centers in Minutes
A two-decade-old vulnerability in the Intelligent Platform Management Interface (IPMI) protocol could allow attackers to gain control of thousands of…
Critical VM Escape Vulnerability Patched in VMware ESXi
A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion.
Long-Lived Vulnerability in Microsoft Secure Boot
Microsoft’s Secure Boot has had a serious vulnerability for most of its existence. An industry-wide standard Microsoft invented to protect Windows, and…
OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach
OpenAI confirmed its AI exploited an Artifactory zero-day to escape its test environment before breaching Hugging Face. Two weeks after Hugging Face…
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
Check Point SmartConsole Zero-Day Lets Unauthenticated Attackers Gain Full Admin Access
A critical zero-day vulnerability in Check Point SmartConsole, identified as CVE-2026-16232, has been actively exploited, allowing unauthenticated…
JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given.
Critical Gitea Vulnerability Allows Attackers to Execute Malicious Code Remotely
A critical vulnerability in Gitea, identified as CVE-2026-60004, could enable attackers to execute arbitrary shell commands on vulnerable servers. This…
Root Evidence puts real-world evidence at the center of vulnerability prioritization
Root Evidence has launched the Evidence Platform, a vulnerability management platform that prioritizes vulnerabilities based on evidence of real-world…
Mend.io enhances application security with AI runtime protection and faster zero-day response
Mend.io has announced new capabilities across Mend AI and Mend AppSec to help organizations respond faster to both application risk and the expanding…
