Vulnerabilities — Page 11

Vulnerabilities

Non-Admin macOS Accounts Can Chain Native OS Features to Blind Endpoint Security Tools

No exploit required. Researchers found that standard user privileges are enough to chain macOS weaknesses and silently kill endpoint security agents — no vulnerability needed.

2 min read
Vulnerabilities

Cordyceps Flaw Class Hands Attackers the Keys to 300+ GitHub Repos

A newly catalogued CI/CD weakness lets attackers hijack workflows at Microsoft, Google and Apache projects, researchers say.

2 min read
Vulnerabilities

Cisco Unified CM SSRF Flaw Hits Active Exploitation Three Weeks After Patch Drop

A file-write chain rooted in CVE-2026-20230 is now being probed in the wild. PoC was already public when Cisco shipped the fix.

2 min read
Vulnerabilities

Cisco Unified CM Bug Under Active Exploit After PoC Drops Root File-Write Chain

CVE-2026-20230 (CVSS 8.6) lets unauthenticated attackers smuggle crafted HTTP requests into Unified CM. Cisco's PSIRT confirms in-the-wild attempts following public PoC release.

2 min read
Vulnerabilities

FFmpeg Vulnerability 'PixelSmash' Threatens Media Applications

A critical flaw in FFmpeg's MagicYUV decoder reveals the fragility of software supply chains.

2 min read
Vulnerabilities

GitHub Hardens actions/checkout Against Pwn Request Exploits

Blocking malicious code execution from pull_request_target workflows.

2 min read
Vulnerabilities

Samsung KNOX Use-After-Free Bug Sat in Galaxy Devices for Eight Years Before Patch

A high-severity kernel-level flaw in Samsung's KNOX security framework affected Galaxy handsets from the S9 through the S25 — a product window spanning nearly a decade.

2 min read
Vulnerabilities

GitHub Tightens Security to Counter Pwn Request Attacks

GitHub introduces actions/checkout v7 to block insecure pull request workflows.

2 min read
Vulnerabilities

PixelSmash Bug in FFmpeg Decoder Opens RCE Path on Jellyfin

A newly disclosed flaw in FFmpeg's PixletVideo decoder enables remote code execution against Jellyfin under specific conditions, with denial-of-service fallout for Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio.

3 min read
Vulnerabilities

Squidbleed: A 1997 FTP Parsing Bug Is Still Leaking Cleartext HTTP in Squid Proxies

A heap over-read disclosed by Calif.io exposes other users' requests — credentials and session tokens included — to anyone permitted to send traffic through the same proxy.

3 min read
Vulnerabilities

Usbliter8: The iPhone Boot Exploit That Can't Be Patched

A proof-of-concept is now public for a hardware-level vulnerability that bypasses Apple's boot defenses on millions of iPhones — and there's no software fix coming.

2 min read
Vulnerabilities

Gravity SMTP Flaw Under Active Exploitation, Leaks API Keys and OAuth Tokens

CVE-2026-4020 lets unauthenticated attackers pull secrets from roughly 100,000 WordPress installs running the mail plugin.

2 min read
Vulnerabilities

usbliter8 Burns a Permanent Hole in A12 and A13 SecureROM

Paradigm Shift's tethered exploit reaches code burned into the silicon, putting a years-long tail on iPhone XS through SE2 boot-chain trust.

3 min read
Vulnerabilities

Briefing: Apple Fixes Beats Bug, GCP Config Connector Flaw Enables Account Takeover, Velvet Ant's Decade in the Shadows

A Bluetooth eavesdropping patch, a quietly dangerous GCP misconfiguration vulnerability, and a threat actor that spent ten years undetected — here's what you may have missed.

2 min read
Vulnerabilities

June Patch Tuesday Breaks OLE Automation, Leaves Word and Excel Silent on Failure

A Windows update shipped June 9 quietly severed the OLE bridge between Office apps and dozens of third-party tools. No error message. Just nothing.

2 min read
© 2026 Threat Vectr