Vulnerabilities — Page 2

Ransomware Gang Exploited Two SonicWall Security Flaws Before a Fix Existed
A group tied to Inc ransomware broke into enterprise networks through a pair of critical holes in SonicWall remote-access devices, stealing credentials and preparing to lock down files.

An 11-byte message can knock OpenSSL servers offline, researchers warn
A newly disclosed flaw nicknamed HollowByte lets attackers exhaust memory on servers running vulnerable versions of OpenSSL, the software that secures most of the web.

OnlyFans Creators Are Accidentally Fixing Government Website Security
Adult content creators filing copyright takedowns are, as a side effect, helping university and government IT teams find hacked pages on their own websites.

Windows 'LegacyHive' zero-day hands ordinary users admin power on fully patched PCs
A researcher published working attack code hours after Microsoft's July 2026 patches, and it still works. Microsoft has no fix yet, and no CVE has been assigned.

Hackers Are Already Exploiting a Critical Microsoft SharePoint Flaw Patched Just Days Ago
CISA has added a newly patched SharePoint vulnerability to its active-exploitation watchlist, giving US federal agencies just three days to apply the fix.

CISA gives federal agencies a weekend to patch two Fortinet flaws already under attack
Two critical bugs in Fortinet's FortiSandbox let intruders run code without a password. Attackers are already trying them. Federal agencies have until Sunday to install the fix.

CISA Flags Three Actively Exploited Bugs in Fortinet and SharePoint
Two Fortinet FortiSandbox flaws and a Microsoft SharePoint deserialization bug are being used in real attacks, the US cyber agency warns.

Zoom patches a flaw that could hand strangers full control of your account
A critical bug in Zoom's Windows software let attackers take over accounts without a password, a click, or any help from the victim. Zoom found it first and patched it. Here is what you need to know.

Siemens Patches Four Flaws in SICAM 8 Grid Kit, Including a Firmware Signing Bypass
The German industrial giant is pushing V26.20 firmware for gear that sits inside power stations. One bug lets an insider install their own firmware.

A malformed packet can knock Rockwell's Flex 5000 Adapter offline until someone power-cycles it
Rockwell Automation has patched a denial-of-service flaw in a widely deployed factory-floor module. The fix ships as firmware 6.012.

The Machines That Run the World Are Running Decades-Old Software
Industrial control systems keep factories, water plants, and power grids alive. They also run code written before Wi-Fi existed. Fixing that is harder than it sounds.

One Hacked Shark Robot Vacuum Can Hand an Attacker the Keys to Every Shark Vacuum in the Region
A researcher pulled a security key off a $500 robot vacuum and used it to run commands on other people's Shark vacuums, including reading their Wi-Fi passwords in plaintext.

Splunk and Zoom Fix Security Flaws That Could Let Hackers Take Over Accounts
Both companies pushed out patches this week. One Zoom flaw scores a near-perfect danger rating and could let a criminal break into accounts without knowing a password.

US government orders emergency patch for critical Oracle finance software flaw
CISA gave federal agencies until Saturday to fix CVE-2026-46817, an Oracle E-Business Suite bug already under attack.

F5 Fixes Serious Security Flaws in NGINX and BIG-IP
Multiple vulnerabilities in two widely used pieces of networking software could have let attackers take control of systems, crash services, or steal data. Patches are now available.