Cisco Patches a Dozen Critical Vulnerabilities
Cisco has released security updates to address 35 vulnerabilities across its products, including over a dozen critical issues.
90 article(s) in our index mention this organisation.
Cisco has released security updates to address 35 vulnerabilities across its products, including over a dozen critical issues.
Threat actors are actively exploiting a critical vulnerability (CVE-2026-21589) in Atlassian’s self-hosted Data Center products, specifically Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd,…
Atlassian has released patches for a directory traversal vulnerability (CVE-2026-21589) that allows attackers to read arbitrary files within their web applications. The vulnerability is triggered by a specific pattern us…
A critical security flaw in Atlassian Data Center products has been actively exploited within two hours of public disclosure. Atlassian has released patches and temporary mitigations, urging customers to prioritize patch…
Atlassian has released patches for a critical vulnerability (CVE-2026-21589, CVSS 9.3) affecting eight of its products – Bitbucket, Bamboo, Crowd, Confluence, Fisheye, Jira Service Management, and Jira.
A critical vulnerability (CVE-2026-21589) in eight Atlassian Data Center products allows unauthenticated attackers to read specific files in the web application root directory. The vulnerability is similar to a previousl…
Atlassian has issued a critical security advisory urging users to patch its datacenter products due to a vulnerability that could allow unauthenticated attackers to access specific files. This follows a series of decisio…
A vulnerability in Atlassian products allows an attacker to access arbitrary files, potentially leading to a data breach. Users are advised to consult the Atlassian security bulletin for patches.
A vulnerability has been identified in GitLab's AI Gateway, specifically in older versions. Users are advised to consult the GitLab security bulletin for available patches.
A critical vulnerability (CVE-2026-90970) in GitLab's AI Gateway allows a logged-in user with Duo Agent Platform access to execute arbitrary commands on self-hosted gateways. Self-managed users should immediately update…
Multiple vulnerabilities have been discovered in GitLab, allowing an attacker to compromise data confidentiality and bypass security policies. Users are advised to apply the patches released by GitLab.
Russian state-sponsored hackers, known as Star Blizzard, are using fake event invitations to deliver a backdoor onto Windows computers. They use various techniques, including phishing emails, exploit kits (like DarkSword…
Multiple vulnerabilities have been discovered in GitLab, allowing for data integrity compromise, data confidentiality issues, and remote code injection (XSS). The security bulletin from GitLab provides details on how to…
GitLab's incoming email addresses, designed for creating project issues, have been found to contain highly privileged access tokens that can be publicly exposed. GitLab has since updated its UI and documentation to refle…
A leaked email address within GitLab allows anyone to push code and run CI/CD jobs as another user, including commits to protected branches like main. GitLab has acknowledged the issue and made minor documentation change…
A financially motivated threat actor, claiming to be a bug bounty hunter, has been linked to the development and distribution of PhantomRaven, a JavaScript information stealer, via the npm package registry. The malware u…
The data broker Radaris.com has been embroiled in a legal battle with Atlas Data Privacy Corp over its practice of failing to remove personal information of law enforcement officials and government personnel from its peo…
A critical GitLab vulnerability (CVE-2026-85706) is being actively exploited, putting organizations' software supply chains at risk. Threat actors are leveraging this path traversal flaw to steal sensitive data, includin…
A vulnerability in Perfect-10 GitLab, a component used by various software applications, is being actively exploited. Despite a patch being released, attackers are leveraging the flaw to gain unauthorized access to syste…
The volume of disclosed vulnerabilities is increasing dramatically, but the number of those actually exploited in the wild remains relatively low. Traditional methods like relying solely on CVSS scores are insufficient b…