Vulnerabilities — Page 10

WordPress Login Flaw Lets Attackers Slip Code Into Every Site Running It
A newly disclosed bug on the WordPress sign-in page affects every version of the software and, in the wrong conditions, can hand attackers full control of the server.

Eighteen-Year-Old Bug in Linux Networking Code Hands Attackers the Keys to the Machine
A flaw in Linux's SCTP networking that has been sitting in the code since 2008 lets a local user become root and break out of a container. Fixed kernels shipped on 3 August.

AI Research Tool Finds New Web Server Attack Tricks and an Apache Zero-Day
PortSwigger's James Kettle put an AI-assisted system called HTTP Terminator against 30,000 sites and turned up fresh HTTP desync attacks plus a previously unknown flaw in Apache Traffic Server.

A Safety Recall on a Truck Brake Controller Was Also Quietly Fixing Security Flaws
Research by the National Motor Freight Traffic Association found that a Bendix EC-80 recall patched serious software vulnerabilities, including one that could let an attacker run their own code on a commercial truck's braking system.

NatJack: New Attack Hijacks TCP Sessions by Abusing Network Address Translation
Researcher Malcolm Stagg showed at Black Hat USA 2026 how to twist NAT tables to steal live connections, fake DNS answers, and unmask hidden users.

NatJack: A New Way to Hijack Internet Traffic by Poisoning Router Memory
Researcher Malcolm Stagg says routers from Microsoft to Linux mishandle connection tracking in ways that let attackers steal live sessions and forge DNS replies.

Microsoft and Apple Rush Out Patches for Flaws That Let Attackers In Without a Password
Several of the Microsoft bugs score a perfect 10 out of 10 for severity. Apple quietly fixed a flaw that lets someone access your screen without logging in.

Google Patches 41 Security Flaws in Chrome 151, Six Rated Critical
The latest Chrome update fixes a cluster of memory-safety bugs that could let attackers crash your browser or run malicious code on your device. Here is what happened and what you should do.

The Security Metric That Lies: Why Knowing Your Vulnerabilities Is Not the Same as Reducing Your Risk
Security teams are drowning in vulnerability reports yet still cannot answer the one question that matters: are we actually harder to attack today than we were last year? A growing number of experts say the old way of measuring risk is the problem.

Zapscape flaw in Linux KVM lets a rogue guest break out to the host
A newly disclosed bug in the Linux kernel's virtualization layer, tracked as CVE-2026-64561, could let an attacker inside a nested virtual machine reach the physical server underneath.

Cisco Patches a Dozen Flaws in SD-WAN and IOS XE, Three Rated Critical
An internal Cisco security review turned up 12 vulnerabilities, including three with a severity score of 9.8 out of 10, in software that runs corporate networks worldwide.

Researchers Sneak Past Spectre v2 by Slipping Between the Kernel's Own Defenses
MIT CSAIL's 'Interrupt Injection' technique re-poisons the branch predictor in the tiny window after the CPU cleans it and before Linux uses it.

ABB Ability Zenon ships with a MongoDB version that hasn't been patched since 2020
Industrial software used in energy, water and manufacturing plants bundles an old database with flaws that can leak memory and bypass access controls.

The Window Between a New Vulnerability and an Active Attack Is Getting Shorter
Security teams are buried in alerts while attackers move faster than ever. The real problem is not a shortage of warnings. It is knowing which ones actually matter before criminals act on them.

Most companies understand CTEM. Almost none of them can run it.
Knowing the five phases of Continuous Threat Exposure Management is the easy part. Building a system that actually proves your defences are improving is where programmes fall apart.