vulnerability Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable Thermo Fisher Scientific has patched a critical vulnerability in its Applied Biosystems human identification software that could allow attackers to tamper with DNA analysis files without detection. The flaw, tracked as C… The Hacker News · Aug 3, 2026 Critical CVE-2026-17583dnaforensicsdata integrity
vulnerability Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code Three high-severity vulnerabilities have been discovered in Hugging Face's Diffusers library, allowing attackers to execute arbitrary code within AI model repositories. These flaws bypass the existing security mechanism,… The Hacker News · Aug 3, 2026 High CVE-2026-44827CVE-2026-45804CVE-2026-44513aisecuritypython
vulnerability ISC Stormcast For Monday, August 3rd, 2026 https://isc.sans.edu/podcastdetail/10034, (Mon, Aug 3rd) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j, potentially allowing attackers to execute arbitrary code through a specially crafted log message. This vulnerability, along… SANS Internet Storm Center · Aug 3, 2026 Critical log4jrcejndi
vulnerability Multiples vulnérabilités dans Papercut (03 août 2026) A series of vulnerabilities have been discovered in PaperCut NG/MF, allowing attackers to compromise data confidentiality and bypass security policies. The vulnerabilities are centered around versions prior to 26.0.3 and… CERT-FR · Aug 3, 2026 Medium CVE-2026-8793CVE-2026-8794vulnerabilitypatchsecurity
vulnerability Multiples vulnérabilités dans Microsoft Edge (03 août 2026) Multiple vulnerabilities have been discovered in Microsoft Edge. Some of these allow an attacker to cause arbitrary code execution, data confidentiality breaches, and data integrity issues. These vulnerabilities are part… CERT-FR · Aug 3, 2026 High CVE-2026-17650CVE-2026-17651CVE-2026-17652vulnerabilitysecuritymicrosoft
vulnerability Vulnérabilité dans Microsoft Office (03 août 2026) A remote code execution vulnerability has been identified in Microsoft Office, allowing attackers to execute arbitrary code. This affects various versions of Office 365, Excel, and Office LTSC, requiring immediate patchi… CERT-FR · Aug 3, 2026 High CVE-2026-62870remotecodeexecution
vulnerability Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes A flaw in Coldcard hardware wallets, manufactured by Coinkite, was exploited to steal $70 million in Bitcoin within 41 minutes. The vulnerability stems from a deterministic PRNG used during seed generation, allowing an a… The Hacker News · Aug 1, 2026 Critical hardware walletseed generationbitcoin
vulnerability Ruby on Rails Patches Critical Vulnerability A critical vulnerability in Ruby on Rails, specifically related to image processing using the libvips library, has been patched. Attackers could potentially read arbitrary files and expose secrets, leading to remote code… SecurityWeek · Aug 1, 2026 Critical CVE-2026-66066rubyrailslibvips
vulnerability Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction Adobe has released critical security updates for Campaign Classic and Adobe Bridge to address vulnerabilities that could allow attackers to execute arbitrary code without user interaction, potentially leading to a comple… The Hacker News · Aug 1, 2026 Critical CVE-2026-48449CVE-2026-48448CVE-2026-48395vulnerabilityarbitrary code executioncampaign classic
vulnerability Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined Google has significantly increased its pace of Chrome security updates, releasing a combined 1,442 fixes across multiple versions (149, 150, and 151). This surge is driven by a rapid increase in vulnerability discovery,… The Hacker News · Jul 31, 2026 High CVE-2026-3545vulnerabilitysecuritypatch
vulnerability Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace Google has significantly increased its use of AI, specifically a Gemini-powered agent harness, to identify and patch security vulnerabilities in Chrome at a dramatically accelerated rate. This initiative led to the disco… SecurityWeek · Jul 31, 2026 High CVE-2026-3545aisecuritychrome
vulnerability Critical Flaw Led to Azure Cosmos DB Pwnage A critical vulnerability, dubbed CosmosEscape, in Azure Cosmos DB allowed attackers to obtain a platform-wide key, enabling them to compromise all databases on the service. Wiz researchers exploited this flaw by bypassin… SecurityWeek · Jul 31, 2026 Critical vulnerabilitycode executiondatabase
vulnerability Critical Code Execution Vulnerability Patched in TeamCity JetBrains has released patches to address a critical vulnerability (CVE-2026-63077) in TeamCity On-Premises, allowing unauthenticated attackers to execute code on the server. This flaw can lead to data breaches, configur… SecurityWeek · Jul 31, 2026 Critical CVE-2026-63077rcevulnerabilitypatch
vulnerability ISC Stormcast For Friday, July 31st, 2026 https://isc.sans.edu/podcastdetail/10032, (Fri, Jul 31st) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging a newly discovered vulnerability in a popular PDF reader. Attackers are using this vulnerabil… SANS Internet Storm Center · Jul 31, 2026 Critical pdfphishingvulnerability
vulnerability Multiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026) Multiple vulnerabilities have been discovered in the SUSE Linux kernel. Several of these vulnerabilities can lead to data confidentiality and integrity breaches, as well as the circumvention of security policies and deni… CERT-FR · Jul 31, 2026 High CVE-2023-20585CVE-2025-10263CVE-2025-39894kernelpatchsecurity
vulnerability Multiples vulnérabilités dans PHP (31 juillet 2026) Multiple vulnerabilities have been discovered in PHP versions 8.2, 8.3, 8.4, and 8.5, including SQL injection and denial of service attacks. Users are strongly advised to apply the security updates released by PHP’s publ… CERT-FR · Jul 31, 2026 Medium CVE-2026-17543CVE-2026-17544CVE-2026-7260phpvulnerabilitysql injection
vulnerability Multiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Ubuntu. Some of these vulnerabilities allow for privilege escalation, data confidentiality breaches, and data integrity compromise. These vulnerabiliti… CERT-FR · Jul 31, 2026 High CVE-2022-48816CVE-2022-49803CVE-2022-49961linuxsecurityvulnerability
vulnerability Multiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026) Multiple vulnerabilities have been discovered within the Linux kernel of Debian LTS. These vulnerabilities include potential for data confidentiality breaches, denial of service attacks, and privilege escalation. Several… CERT-FR · Jul 31, 2026 High CVE-2025-23131CVE-2026-23272CVE-2026-23278vulnerabilitylinuxdebian
vulnerability Vulnérabilité dans Microsoft Azure (31 juillet 2026) A critical vulnerability has been identified in Microsoft Azure's Cosmos DB, allowing attackers to execute arbitrary code remotely. This could lead to significant data compromise and system control for malicious actors. CERT-FR · Jul 31, 2026 Critical CVE-2026-66803azureremote code executiondatabase
vulnerability Multiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026) Multiple vulnerabilities have been discovered in Progress MOVEit Transfer, allowing attackers to inject code remotely and bypass security policies. These flaws are impacting versions of the software prior to 2026.0.3 and… CERT-FR · Jul 31, 2026 High CVE-2026-10697CVE-2026-15966CVE-2026-15967cvexsssecurity