Cisco Patches a Dozen Critical Vulnerabilities
Cisco has released security updates to address 35 vulnerabilities across its products, including over a dozen critical issues.
25 article(s) in our index mention this organisation.
Cisco has released security updates to address 35 vulnerabilities across its products, including over a dozen critical issues.
SonicWall and Splunk have released patches to address multiple critical and high-severity vulnerabilities in their products. There is currently no evidence of exploitation of these flaws.
This week saw a surge in high-impact cyberattacks and vulnerabilities, highlighting the increasing sophistication and speed of threat actors. AI is now being weaponized to craft exploit scripts targeting Siemens PLCs, wh…
A critical type confusion vulnerability in the isolated-vm Node.js library is being exploited to achieve remote code execution (RCE) on the host system. The vulnerability stems from a flawed data transfer mechanism withi…
Atlassian and Splunk have released patches to address over 250 vulnerabilities across their products, including numerous critical and high-severity flaws in third-party dependencies. These updates aim to mitigate risks s…
Multiple vulnerabilities have been discovered in Splunk products, including remote code execution, privilege escalation, and data confidentiality breaches. Several of these vulnerabilities can be exploited to achieve rem…
Zoom has released patches to address four critical vulnerabilities, including a zero-click remote code execution flaw that could allow an attacker to take control of any participant’s machine without any user interaction…
Tenet security researchers have demonstrated a novel ‘Ghostjacking’ attack that leverages poisoned logs to manipulate AI agents, effectively turning them into malicious tools. The attack exploits trust in AI agents by in…
This week's Threat Source newsletter highlights a significant spike in authentication abuse and sophisticated phishing tactics, driven by attackers leveraging QR codes and advanced platforms like ARToken to bypass multi-…
This article is a promotional piece from Cisco Talos highlighting their Humans of Talos series, a podcast showcasing the diverse backgrounds of threat intelligence professionals. It announces their presence at Black Hat…
The article argues that AI-powered exploit discovery tools like Mythos are compressing the time between vulnerability disclosure and exploitation, but the real problem isn't faster patching – it's that most security team…
Cisco Talos will be at Black Hat USA 2026, showcasing research and demonstrations focused on AI-driven security challenges and threat hunting. They'll cover topics like AI-powered threat actor prompting, securing enterpr…
CISOs are facing increased pressure and job insecurity due to the rapid and often chaotic adoption of AI within companies. A recent Splunk survey revealed that 26% of top security executives are considering leaving their…
Splunk and Zoom have released patches to address several critical and high-severity vulnerabilities in their respective products. These flaws could allow attackers to steal credentials, access sensitive data, and potenti…
Multiple vulnerabilities have been discovered in Splunk products, including Splunk Cloud Platform and Enterprise versions. These vulnerabilities allow for data confidentiality and integrity breaches, as well as the poten…
Cribl, a telemetry processing platform, has acquired CardinalOps to bolster its security operations capabilities. This acquisition will allow Cribl customers to map their existing detection rules and security controls to…
Palo Alto Networks has released advisories detailing 13 vulnerabilities across its products, including a critical buffer overflow that could lead to arbitrary code execution. While the company reports no active exploitat…
This article profiles Tarah Wheeler, CISO at TPO Group and previously holding leadership roles at Red Queen Technologies and EFF. It highlights her unique background, blending her passion for social science and writing w…
Cisco is bolstering its security offerings by acquiring Astrix Security and WideField Security, both focused on managing the growing number of non-human identities (NHIs) created by AI agents. This strategy reflects a sh…
A critical vulnerability, dubbed PixelSmash, has been identified in FFmpeg, a widely used media processing framework. The flaw allows for remote code execution (RCE) via crafted media files, potentially impacting a broad…