Vulnerabilities — Page 11

ABB Ability Zenon ships with a MongoDB version that hasn't been patched since 2020
Industrial software used in energy, water and manufacturing plants bundles an old database with flaws that can leak memory and bypass access controls.

The Window Between a New Vulnerability and an Active Attack Is Getting Shorter
Security teams are buried in alerts while attackers move faster than ever. The real problem is not a shortage of warnings. It is knowing which ones actually matter before criminals act on them.

Most companies understand CTEM. Almost none of them can run it.
Knowing the five phases of Continuous Threat Exposure Management is the easy part. Building a system that actually proves your defences are improving is where programmes fall apart.

iCloud Private Relay Has a Leak: Researchers Show How Safari's Privacy Shield Can Spill Real IPs
A flaw in how Apple's WebKit handles certain web requests lets sites see the IP address Private Relay was meant to hide.

A 12-year-old flaw in a popular crypto library drained $5.7 million from wallets
Security firm Coinspect traced a wave of wallet thefts to a weak random number generator inside CryptoJS, a JavaScript library used by five cryptocurrency wallet apps to create recovery phrases.

Patched Doesn't Mean Safe: Why Security Teams Need to Test After They Fix
A new survey of 750 security leaders finds that fewer than one in three organisations check whether a fix actually stopped an attacker. The gap between completing work and reducing risk is where breaches still happen.

Cisco Patches 24 Flaws, Including a Perfect-Score Bug That Hands Attackers Full Control
A flaw in Cisco's firewall management software scores a rare 10 out of 10 on the severity scale, meaning a remote criminal needs no password to take complete control of an affected system.

Hackers Are Actively Exploiting a Critical Flaw in JetBrains TeamCity
A software tool used by thousands of development teams worldwide has a severe security hole that attackers are already using. The US government is telling federal agencies they have three days to fix it.

Why Modern Hackers Walk In Through the Front Door of Your Website
Security teams have spent years locking up their networks and servers. A new wave of attacks shows that criminals are now coming in through web applications instead, and most defences are not keeping up.

Fixing One Hole at a Time Is No Longer Enough: Why Security Must Follow the Full Attack Path
Criminals no longer stop at the front door. They chain together weaknesses across your apps, accounts, and cloud systems, and security teams testing each piece in isolation are missing the bigger picture.

Your Email's Design Layer Can Steal Your Password. No Suspicious Attachment Required.
Security researcher Gareth Heyes found that CSS, the code responsible for how emails look on screen, can be turned into a data-theft tool inside popular webmail services. No malicious files. No links to click.

15 Flaws in TP-Link Kit Put Automatic Network Setup at Risk
Security researchers found 15 vulnerabilities in TP-Link's Omada networking system and warn that the convenient "zero-touch" setup process that millions of organisations rely on could hand criminals the keys to an entire network.

Researchers Cracked Samsung Phones Wide Open by Turning Bixby Against Its Own Device
A five-step exploit chain using Bixby, Samsung Members, and Samsung Account could hand a stranger complete control of your Galaxy phone. Patches are out, but older devices may still be exposed.

CISA gives federal agencies three days to patch Langflow, N-central and Tomcat flaws under active attack
Three separate bugs, three sets of criminals, one very short deadline. Here is what is being exploited and who should care.

Veeam Console Bug Hands Over Agent Credentials; Terraform MCP Server Leaks Tokens Between Users
Eleven fixes across HashiCorp, Veeam and Django include a 9.5-rated Veeam flaw and a cross-tenant Terraform MCP Server bug that reuses one customer's cloud token for the next.