Vulnerabilities — Page 13

A glowing server rack in a dark data center, one rack unit pulsing with deep red light indicating a fault or intrusion, surrounded by cold blue ambient light fr
Vulnerabilities

Schneider Electric patches a nasty file-parsing bug in its industrial control software

A booby-trapped design file could let attackers run code inside IGSS, the SCADA tool used to monitor factories, energy sites and manufacturing plants worldwide.

3 min read
Aerial view of a large industrial fuel storage facility at dusk, rows of cylindrical metal tanks reflecting low amber light, pressure gauges and pipe networks v
Vulnerabilities

NASA's Core Flight System has a flaw that can crash spacecraft software

A researcher found that NASA's open-source flight software can be knocked offline by a single malformed command, and the patch for an earlier version of the same bug did not fully close the hole.

4 min read
Photoreal news-editorial image of a darkened enterprise server rack with one rack unit displaying a red status LED, others showing amber and green, shallow dept
Vulnerabilities

Mitsubishi Electric Factory Gear Vulnerable to Network Tampering Attack

A flaw in the CC-Link IE TSN protocol lets a nearby attacker knock dozens of industrial products offline. Mitsubishi has not shipped a fix.

3 min read
Full-frame photoreal editorial shot of a high-voltage electrical substation at dusk, rows of transformers and steel gantries under a deep blue sky, a small illu
Vulnerabilities

Forgotten DNS Records Could Become a Nation-State Weapon, Researchers Warn

A technique called 'dangling DNS' has lurked in security circles for years. Researchers now say AI could automate it at a scale that threatens governments, banks and supply chains.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a dark server rack in a data centre with a single amber warning light glowing on one rack unit, cool b
Vulnerabilities

North Korea-Linked Hackers Booby-Trap Korean Websites to Push Backdoors via AnySign4PC Flaw

A state-sponsored crew hijacked trusted South Korean sites and abused a weakness in a widely installed banking security tool to plant SIGNBT and COPPERHEDGE malware, no click required.

4 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Vulnerabilities

One in Five Data Centre Systems Is One Step Away From Hackers, Research Finds

A study of 174,000 data centre infrastructure devices found that roughly 32,000 sit just one network hop from the open internet, putting cooling, power and fire systems within easier reach of attackers than most operators realise.

3 min read
Photoreal news-editorial overhead shot of a darkened security operations center desk, multiple monitors glowing blue with abstract vulnerability dashboards and
Vulnerabilities

Google Patches 370 Security Flaws in Chrome 151, Including Seven Critical Bugs

The browser update is one of Google's largest single releases of the year, fixing flaws that could let attackers take control of your browser or crash it entirely.

3 min read
A digital lock symbol over a network diagram, representing cybersecurity
Vulnerabilities

Cisco firewall manager had a hidden password. Attackers found it first.

A built-in account in Cisco Secure Firewall Management Center was exploited as a zero-day in July, and Cisco is telling customers to patch and hunt for a specific log entry.

4 min read
Photoreal editorial shot of a dimly lit server rack with a single glowing amber warning light, faint reflections of code on the metal, shallow depth of field, c
Vulnerabilities

A Rails Bug Lets Strangers Read Your Server's Secrets Through a Photo Upload

CVE-2026-66066 in Active Storage scores a 9.5 out of 10 for severity, and no login is required to exploit it.

3 min read
Macro photograph of smooth river stones arranged in a row on a wooden surface, each stone casting a soft shadow, warm neutral tones, shallow depth of field, edi
Vulnerabilities

The Security Scanners Protecting Your Code Could Be the Way Hackers Get In

A researcher found that five unnamed security vendors' own scanning tools could be tricked into handing over cloud passwords, production databases, and developer credentials, just by feeding them a rigged code repository.

4 min read
Close-up top-down view of a glowing green circuit board with complex layered traces and chips illuminated by cool blue ambient light, sharp focus on solder join
Vulnerabilities

Broadcom Patches Three Critical VMware Bugs, Including a vCenter Login Bypass

One flaw lets an attacker skip the login screen on vCenter entirely. Two more allow code execution and virtual machine escape across ESX, Workstation and Fusion.

3 min read
A close-up, photoreal, news-editorial image of tangled fiber optic cables glowing with intense orange and red light against a dark server room background, with
Vulnerabilities

Windows 11 gets a 42-fix preview update with quieter alerts and better voice control

Microsoft's optional KB5101684 preview for Windows 11 24H2 and 25H2 clears up File History backup errors, a DFS drive quirk that scared File Explorer, and a compliance bug that locked new work laptops out of company resources.

4 min read
A network diagram showing a supply chain attack with compromised npm packages affecting developer systems
Vulnerabilities

One Click on a Bad Web Page Was Enough to Break Firefox and Tor

Researchers at Nebula Security say a now-patched Firefox flaw let attackers run code just by loading a page, and it worked against Tor Browser too.

3 min read
Photoreal news-editorial overhead shot of a darkened server room aisle, blue and amber rack indicator LEDs glowing along both walls, faint condensation haze nea
Vulnerabilities

Broadcom Patches Critical 'VM Escape' Flaw in VMware ESXi, Plus Four More Vulnerabilities

Five security flaws, three rated critical, have been fixed across VMware's most widely-used virtualisation products. One lets an attacker break out of a contained virtual machine and reach the underlying server it runs on.

3 min read
Macro photograph of tangled fiber optic cables glowing in deep blue and green light against a dark server room background, sharp focus on the glass fiber tips w
Vulnerabilities

Gitea Patches Critical Flaw That Lets Repo Users Run Shell Commands

CVE-2026-60004 carries a 9.8 CVSS score and is fixed in Gitea 1.27.1. Anyone running an older self-hosted instance should update now.

3 min read
© 2026 Threat Vectr