A two-decade-old vulnerability in the Intelligent Platform Management Interface (IPMI) protocol could allow attackers to gain control of thousands of…
Tag: Vulnerability
Critical VM Escape Vulnerability Patched in VMware ESXi
A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion.
Long-Lived Vulnerability in Microsoft Secure Boot
Microsoft’s Secure Boot has had a serious vulnerability for most of its existence. An industry-wide standard Microsoft invented to protect Windows, and…
OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach
OpenAI confirmed its AI exploited an Artifactory zero-day to escape its test environment before breaching Hugging Face. Two weeks after Hugging Face…
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
Check Point SmartConsole Zero-Day Lets Unauthenticated Attackers Gain Full Admin Access
A critical zero-day vulnerability in Check Point SmartConsole, identified as CVE-2026-16232, has been actively exploited, allowing unauthenticated…
JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given.
Critical Gitea Vulnerability Allows Attackers to Execute Malicious Code Remotely
A critical vulnerability in Gitea, identified as CVE-2026-60004, could enable attackers to execute arbitrary shell commands on vulnerable servers. This…
Root Evidence puts real-world evidence at the center of vulnerability prioritization
Root Evidence has launched the Evidence Platform, a vulnerability management platform that prioritizes vulnerabilities based on evidence of real-world…
Mend.io enhances application security with AI runtime protection and faster zero-day response
Mend.io has announced new capabilities across Mend AI and Mend AppSec to help organizations respond faster to both application risk and the expanding…
JFrog Patches Artifactory Zero-Days After OpenAI Models Escape Sandbox
Multiple zero-day vulnerabilities in self-hosted Artifactory after OpenAI’s frontier models autonomously exploited them to escape a sandboxed research…
FastJson RCE Zero-Day Actively Targets Organizations
Threat actors are actively exploiting the FastJson CVE-2026-16723 zero-day, with no patch available for affected FastJson 1.x versions.
Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay
Cursor has patched a high-severity Windows vulnerability that allowed malicious Git repositories to execute code, highlighting security risks in AI coding…
Nginx Buffer Overflow Vulnerability Allows Attackers to Execute Arbitrary Code – PoC Released
A high-severity heap buffer overflow in NGINX Plus and NGINX Open Source can let unauthenticated attackers crash worker processes and, under certain…
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation…
Public Exploit Lands for vBulletin’s Pre-Auth RCE, CVE-2026-61511
A public proof-of-concept for the vBulletin RCE vulnerability CVE-2026-61511 is now live. Here’s how the eval() injection works and who still needs to…
EShare App Vulnerability CVE-2026-55977
The Cyber Security Agency of Singapore has assigned CVE-2026-55977 to a vulnerability in EShare’s wireless screen mirroring and collaboration application.
JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)
JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon…
Hackers Exploiting Arista VeloCloud Orchestrator 0-Day Vulnerability in the Wild
Arista Networks has issued a security advisory for CVE-2026-16812, a critical command injection vulnerability affecting on-premises VeloCloud Orchestrator…
AI-Discovered Linux Kernel Zero-Day Enables Root Privilege Escalation
A researcher recently disclosed an AI-assisted Linux kernel zero-day vulnerability, tracked as CVE-2026-53264, which allows local privilege escalation to…