Vulnerabilities — Page 5

Marimo Patches Notebook Flaw That Let Hidden Commands Run on Open
A high-severity bug in the Marimo notebook app could quietly run attacker-supplied commands when a user opened a booby-trapped file in edit mode.

Nucleus Security says its new tools can spot a vulnerability before your scanner even knows it exists
A new early-warning feature aims to cut the days-long gap between a software flaw going public and security teams being able to scan for it.

CISA Flags Critical Oracle WebLogic Flaw as Attackers Hit Unpatched Servers
The bug, rated a perfect 10 on the severity scale, lets attackers reach sensitive data without needing a password.

Delhi's Electric Rickshaws Are Being Hacked via Bluetooth, and Nobody Has to Be a Programmer to Do It
Scammers with a free app are killing electric rickshaw engines in Delhi traffic, exposing a gap in India's push to clean up one of the world's most polluted cities.

Calix Home Routers Have a Hole That Lets Strangers Punch Into Your Network
A flaw in Calix GS7 XGS routers, handed out by several U.S. internet providers, lets anyone on the internet quietly open doors into a customer's home network. No patch yet.

Hackers Chain Two miniOrange WordPress Plugin Bugs to Log in as Admin
Paid editions of the popular SAML single sign-on plugin were quietly patched in July but never got a public warning, and now attackers are forging login sessions on sites that never updated.

Microsoft's August .NET patch broke printing in Windows apps. Here's what to do.
A security fix shipped this month is causing crashes when Windows Presentation Foundation apps try to print or export to PDF using common fonts like Calibri.

91 Security Flaws Fixed in Spring, the Java Framework Powering Hundreds of Thousands of Apps
One critical flaw lets attackers silently alter user records. Over 200 vulnerabilities have already been patched in Spring this year alone, a sharp rise tied to Broadcom's push into AI.

Windows Named Pipes: The Hidden Back Channel Attackers Keep Prying Open
A quiet feature that lets Windows programs talk to each other becomes a privilege-escalation problem when developers skip the access checks.

Microsoft's Own Antivirus Driver Can Be Turned Into a Weapon at Boot
Check Point researchers show how BTR.sys, the trusted cleanup tool inside Microsoft Defender, can be steered to wipe files and registry keys before Windows even finishes starting.

CISA gives federal agencies two weeks to fix TrueConf video server flaws already being abused
Two critical bugs in the self-hosted conferencing platform let attackers run code without a password. Hacktivists have been using them since July.

Microsoft Pushes 22 Security Fixes, Six Rated Maximum Severity
A batch of patches covers Microsoft's cloud and identity products, with six flaws scoring a perfect 10 out of 10 on the severity scale. Most fixes apply automatically, but one Defender vulnerability is still waiting for a patch.

Weekly Roundup: Trusted Software Turned Against Defenders, Plus a Critical Gogs Flaw
From signed drivers hijacked to disable antivirus tools, to a code-execution bug in the Gogs source-code platform, this week's threats show how attackers keep lowering the bar.

Rust developers hit by supply-chain attack on arrayref crate
Attackers hijacked a maintainer account and slipped credential-stealing malware into three popular Rust libraries during a 1.5-hour window on August 20.

A Flaw in N-able's Passportal Handed Any Malicious Website the Keys to Every Password a Business Stored
A researcher found that Passportal's browser extension trusted every message it received without question, letting any webpage silently drain a company's entire vault of login credentials.