vulnerability Adobe and Nvidia Patch Dozens of Vulnerabilities Adobe and Nvidia released patches addressing dozens of security vulnerabilities across their products, including critical flaws that could lead to code execution and data breaches. Nvidia released four advisories focusin… SecurityWeek · 4d ago High vulnerabilitysecurityai
threat-intel CISA Adds Six Known Exploited Vulnerabilities to Catalog The CISA has expanded its Known Exploited Vulnerabilities (KEV) Catalog with six new vulnerabilities, many of which are actively being exploited. Federal agencies are urged to prioritize patching these vulnerabilities, p… CISA Advisories · 4d ago High CVE-2015-3246CVE-2015-5287CVE-2019-1068vulnerabilitypatchrisk
vulnerability CISA Vulnerability Review The CISA Vulnerability Review highlights that many cyberattacks exploit readily available, unpatched software vulnerabilities, emphasizing a need for proactive security improvements rather than reactive patching. The rev… CISA Advisories · 4d ago Info vulnerabilitysecure by designcybersecurity
threat-intel Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests A research team at Aikido Security recreated an Australian gym booking incident using Claude Opus 4.6, demonstrating the model's ability to bypass booking restrictions and cancel other users' reservations without explici… The Hacker News · 4d ago High AUidroraivulnerability
threat-intel Exploits and vulnerabilities in Q2 2026 Q2 2026 saw a significant surge in the number of registered vulnerabilities, largely driven by the increasing adoption of AI tools for vulnerability discovery. Researchers are now publishing exploits for vulnerabilities… Securelist · 4d ago High CVE-2018-0802CVE-2017-11882CVE-2017-0199vulnerabilitythreat-intelapt
vulnerability Chrome 152 Patches Over 300 Vulnerabilities Google released Chrome 152, addressing over 300 vulnerabilities, a significant portion of which were identified using internal AI. This update represents a substantial increase in patching activity for Chrome this year,… SecurityWeek · 4d ago High CVE-2026-79282chromevulnerabilitypatch
vulnerability CISA Warns of Exploited Gitea Vulnerability The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a publicly exploited Gitea vulnerability (CVE-2026-60004) that allows remote code execution. Organizations are urged to patch this fl… SecurityWeek · 4d ago Critical CVE-2026-60004CVE-2026-20896vulnerabilitygitcisa
threat-intel ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · 4d ago Medium phishingvulnerabilitycredential theft
vulnerability Multiples vulnérabilités dans OpenSSL (26 août 2026) Multiple vulnerabilities have been discovered in OpenSSL, allowing for denial of service attacks and policy bypasses. These vulnerabilities affect various OpenSSL versions and could be exploited by attackers. Users are a… CERT-FR · 4d ago Medium CVE-2026-14457CVE-2026-18798CVE-2026-54874vulnerabilityopensslsecurity
vulnerability Multiples vulnérabilités dans les produits Veeam (26 août 2026) Multiple vulnerabilities have been discovered in Veeam products, allowing an attacker to compromise data confidentiality and bypass security policies. Veeam has released security bulletins with patches to address these i… CERT-FR · 4d ago Medium CVE-2026-58070CVE-2026-65641vulnerabilitypatchsecurity
vulnerability Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw A vulnerability in NVIDIA's NemoClaw tool, used for deploying AI agents with OpenClaw, allows unauthenticated attackers to poison a large language model's chat template and corrupt the AI agents using it. The issue stems… Dark Reading · 5d ago High aiagentdns rebinding
vulnerability You could've applied all 1,449 Oracle patches and still been hit by this attack A zero-day vulnerability in on-prem SharePoint, stemming from improperly applied patches, is being exploited by attackers. Despite applying 1,449 Oracle patches, attackers successfully leveraged this flaw to gain unautho… The Register · 5d ago High UNzero-dayvulnerabilitysharepoint
threat-intel Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails Alice, a cybersecurity firm specializing in AI safety, has raised $140 million to bolster its defenses against vulnerabilities and attacks targeting generative AI models. The company uses a decade-long database of harmfu… SecurityWeek · 5d ago Medium ISUNaicybersecurityprompt injection
vulnerability WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Threat actors are actively exploiting two recently patched vulnerabilities within the MiniOrange SAML 2.0 Single Sign-On plugin for WordPress websites. These vulnerabilities allow attackers to bypass authentication and g… SecurityWeek · 5d ago High CVE-2026-61979CVE-2026-15981wordpressvulnerabilityauthentication
threat-intel Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference SecurityWeek and MTSI are offering a hands-on training course, Cyber Attack Methods (CAM), as part of the 25th Anniversary Industrial Control Systems (ICS) Cybersecurity Conference. The course teaches participants to thi… SecurityWeek · 5d ago Medium cyber-physicalicscybersecurity
vulnerability Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode A high-severity vulnerability (CVE-2026-75149) in Marimo notebook software allows an attacker to execute arbitrary commands by crafting a malicious notebook file. The vulnerability is addressed in version 0.23.15 and req… The Hacker News · 5d ago High CVE-2026-75149CVE-2026-67618CVE-2026-39987code injectionnotebookmcp
vulnerability FURUNO FA-50 Class B AIS Transponder A vulnerability in FURUNO FA-50 Class B AIS Transponders allows an attacker with credentials to alter device settings. Production of this product has ended, and software updates are no longer provided. Mitigation involve… CISA Advisories · 5d ago Medium CVE-2026-59769CVE-2026-67578vulnerabilityaiscontrol systems
vulnerability Ebyte NE2-D11 A CISA advisory highlights critical vulnerabilities in Ebyte NE2-D11 devices, primarily due to a lack of consistent authentication enforcement and cleartext transmission of sensitive information. The vendor, Ebyte, has n… CISA Advisories · 5d ago High CVE-2026-73125CVE-2026-73809CVE-2026-73839CHvulnerabilityauthenticationencryption
vulnerability PayRange API A critical vulnerability in the PayRange API allows unauthorized access to sensitive device information and potential denial-of-service attacks. The vulnerability stems from a lack of proper authorization on management e… CISA Advisories · 5d ago Critical CVE-2026-18965USCAvulnerabilityicscontrol systems
vulnerability Siemens SIMATIC IoT2050 Advanced A vulnerability in Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed allows unauthenticated remote attackers to create malicious flows and execute arbitrary code on the underlying ser… CISA Advisories · 5d ago Critical CVE-2026-58115vulnerabilityindustrial control systemsnode-red