Vulnerabilities — Page 22

Photoreal news-editorial image of a dim server room with a single rack illuminated in red emergency lighting, cables neatly running along the floor, subtle haze
Vulnerabilities

Unpatched Flaw in Alibaba's XQUIC Lets Anyone Crash HTTP/3 Servers With 260 Bytes

A researcher at FoxIO disclosed the bug on 8 July. There is no fix, no login required, and no malformed packets involved.

3 min read
Photoreal news-editorial full-frame 16:9 image of a small metal cryptocurrency hardware wallet resting on a dark wooden desk beside a handwritten paper card wit
Vulnerabilities

'Ill Bloom' Wallet Flaw Drains $3.1 Million as Weak Recovery Phrases Give Thieves the Keys

Security firm Coinspect says attackers are already sweeping wallets whose recovery words were generated with predictable randomness.

3 min read
Photoreal news-editorial photograph, 16:9 framing, edge-to-edge composition
Vulnerabilities

Security Debt Is Growing Faster Than Companies Can Fix It. Here Is What That Means.

Eight in ten organisations are sitting on a backlog of unresolved security flaws that stretch back more than a year. A practical framework, first outlined in CSO Online, explains how to turn that problem into a board-level conversation.

3 min read
Full-frame photoreal editorial image of a close-up Windows laptop screen showing a generic blue security shield icon glowing, with faint reflection on a dark de
Vulnerabilities

Microsoft Patches 'RoguePlanet' Defender Flaw a Month After Public Disclosure

The privilege escalation bug in the Malware Protection Engine sat exposed for weeks before Redmond shipped a fix.

3 min read
Close-up top-down view of a sleek laptop keyboard with a shallow depth of field, the screen faintly glowing blue-white with an abstract grid of hexagonal shapes
Vulnerabilities

Google Patches 27 Chrome Flaws, Two Rated Critical

Chrome 150 arrives with fixes for a string of memory-related bugs, most of them found by Google's own engineers rather than outside researchers.

3 min read
Full-frame close-up of a modern laptop screen glowing blue in a dim office, showing an abstract Windows security shield icon partly fractured, dust motes catchi
Vulnerabilities

Microsoft patches 'RoguePlanet' Defender flaw after researcher publishes exploit in disclosure spat

The zero-day let attackers hand themselves the keys to a fully patched Windows machine. It was revealed by a researcher publicly feuding with Microsoft.

4 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Vulnerabilities

A Secret Backdoor in Tenda Home Routers Lets Strangers Take Control, and There Is No Fix

A hidden login trick buried in Tenda networking gear gives anyone who knows the magic password full administrative control. The maker has not responded, and no patch exists.

3 min read
Photoreal news-editorial shot of a rack of white networking access points and small gateway boxes mounted on a modern office ceiling, soft cool blue LEDs glowin
Vulnerabilities

Ubiquiti Rushes Fixes for a 10-out-of-10 Flaw Across UniFi Gear

The networking vendor patched serious holes in UniFi Connect, Talk, Access, Protect and the underlying UniFi OS. One bug scores a perfect 10 on the severity scale.

3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Vulnerabilities

U.S. Government Gives Agencies Two Weeks to Patch Four Actively Exploited Flaws

Critical security holes in Adobe ColdFusion, Langflow, and Joomla extensions are already being used by attackers. Federal agencies have until July 10 to fix them.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a darkened server rack in a data centre, blue and amber status lights glowing, one drawer pulled sligh
Vulnerabilities

US cyber agency gives federal staff four days to patch Langflow AI tool being actively hacked

CISA added an authorisation bypass in the popular AI-agent builder Langflow to its must-patch list after Sysdig spotted attackers stealing cloud keys and hijacking servers.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit server room with rows of dark rack-mounted servers, blue and amber status LEDs reflecting
Vulnerabilities

CISA Flags Four Live-Exploited Bugs in Adobe, Joomla and Langflow

The US cyber agency gave federal agencies until early December to patch a critical Adobe ColdFusion flaw and three others already being abused in the wild.

3 min read
Full-frame close-up of a dark server room aisle, rows of black rack-mounted machines with faint green and amber status LEDs, one open server tray showing a bare
Vulnerabilities

GhostLock: A 15-Year-Old Linux Bug Hands Any User Root Access

Researchers say CVE-2026-43499 has sat in the Linux kernel since 2011 and needs nothing more than a normal login to seize full control.

3 min read
Full-frame photoreal editorial shot of an open industrial control cabinet inside a substation, showing a ruggedised ethernet switch with blue and green status L
Vulnerabilities

Siemens tells industrial customers to patch RUGGEDCOM switches now, cites dozens of flaws in SINEC OS

The German engineering giant has shipped version 4.0 of its ruggedised network operating system to close a long list of bugs, including one rated 9.8 out of 10.

3 min read
Photoreal editorial shot of a dense server rack in a cool-lit data centre, rows of blinking green and amber status LEDs, one rack panel showing a faint red warn
Vulnerabilities

16-Year-Old Linux Bug Lets Attackers Escape Virtual Machines on Intel and AMD

Researcher Hyunwoo Kim's 'Januscape' flaw (CVE-2026-53359) sat in KVM for over a decade and threatens shared cloud servers at Google Cloud, AWS and beyond.

4 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Vulnerabilities

A 16-Year-Old Linux Flaw Lets Attackers Break Out of Virtual Machines

A newly disclosed bug in the Linux kernel has sat unnoticed since 2009, and it lets criminals escape the virtual walls that are supposed to keep cloud servers separate and safe.

3 min read
© 2026 Threat Vectr