Vulnerabilities — Page 15

A Weaponised SVG File Let Researchers Run Commands on Bing's Own Servers
Security testers at XBOW uploaded a booby-trapped image to Bing's image search and ended up with full control over Microsoft's image-processing machines. Two critical patches followed.

Redis Patches Four Code-Execution Bugs After AI Agent Finds Zero-Days
Seven security releases went out on July 23 after researchers used Moonshot AI's Kimi K3 agents to uncover authenticated remote code execution chains in stock Redis builds.

AI Scanner Finds Eight Serious Bugs in NodeBB Forum Software
Aikido Security's automated code review turned up admin takeover and private-message flaws in six hours. All eight are patched in version 4.14.2.

CISA orders three-day fix as Clop hits PTC Windchill flaw
A critical bug in PTC's product design software, CVE-2026-12569, is being used by the Clop extortion crew to steal corporate data. Regulators in the US and Germany moved fast.

Check Point's Admin Console Has a Critical Flaw That Hands Attackers the Keys to Everything
A security hole in Check Point's management software lets criminals walk in without a password and rewrite the rules of an entire network. Ten organisations have already been hit.

A Hidden Linux Flaw Lets Any Local User Seize Full Control of a Machine
A race condition buried in the Linux XFS filesystem since 2017 can hand a regular user complete administrative control. Patches are out. Reboots are required.

Can You Still Patch Your Way to Safety? Why the Old Playbook Is Breaking Down
Artificial intelligence can now turn a published vulnerability description into a working attack in under a day. That changes the math for every organisation relying on traditional patch schedules.

Russian Hackers Are Reading Your Email Just by Sending You One: Zimbra Zero-Day Explained
A Kremlin-linked crew tracked as LAUNDRY BEAR is exploiting CVE-2025-66376 in Zimbra webmail to steal 90 days of email the moment a victim opens a booby-trapped message.

Old Linux Bug 'RefluXFS' Hands Root to Anyone With a Shell on Default Red Hat Servers
A nine-year-old flaw in how Linux handles the XFS filesystem lets any local user become the all-powerful root account on default installs of Red Hat, Fedora and Amazon Linux.

Hackers Are Actively Exploiting a Flaw in Check Point Security Software
A newly discovered hole in Check Point's network management tools let attackers log in as administrators without a password. Real attacks were already happening before the patch arrived.

Check Point Rushes Fix for SmartConsole Flaw Already Being Exploited
A critical authentication bypass in Check Point's management console let attackers waltz past the login screen. The vendor confirms real-world attacks are already happening.

What is a CVE and how does vulnerability scoring work?
CVEs are the universal ID system for software flaws, and CVSS scores tell you how bad each one actually is.

What is a zero-day vulnerability? A plain-English guide
Zero-days are unpatched security flaws the software vendor doesn't know about yet, making them among the most dangerous bugs in existence.

Microsoft Wants You to Patch in Three Days. Security Teams Say That's Not How It Works.
Microsoft is telling IT administrators to apply security fixes within 72 hours, citing AI tools that find and exploit software flaws faster than ever. Experts agree on the threat. They disagree, sharply, on whether three days is workable.

Fake Bahrain Alert App Spreads Android Surveillance Malware
A fake emergency alert app targets users with sophisticated spying tools.