Vulnerabilities — Page 6

Full-frame 16:9 photoreal editorial image of a dimly lit server rack in a data center, focused on a single rack unit with a glowing amber status LED, shallow de
Vulnerabilities

The 'CDN Tsunami' Attack Turns a Trickle of Traffic Into a Flood at the Origin

Researchers show how the way big content delivery networks translate modern HTTP/3 requests into older HTTP/1.1 can multiply a small attack stream by up to 350 times against the website behind them.

4 min read
Full-frame edge-to-edge 16:9 photoreal news-editorial shot of a dimly lit e-commerce warehouse server rack with a single red status LED glowing, faint motion bl
Vulnerabilities

'Zombie Card' Attack Brings Expired Visa Contactless Cards Back to Life

UMass Amherst researchers show how to rewrite the expiry date a payment terminal sees, letting dead cards buy real goods.

4 min read
Photoreal news-editorial style 16:9 image of a large server room with rows of illuminated rack-mounted servers casting cool blue and amber light across a polish
Vulnerabilities

Atlassian and Splunk Push Patches for More Than 250 Flaws, Including Critical Bugs

Two major software vendors dropped sweeping security updates this week. Here is what changed, what could go wrong without the fix, and what ordinary users should know.

3 min read
Photoreal news-editorial shot of a dimly lit enterprise telecom server rack with VoIP gateway hardware and blinking amber status LEDs, blue-green ambient light
Vulnerabilities

Cisco Patches Four Maximum-Severity Flaws in Crosswork Network Software

Fifteen vulnerabilities fixed across Cisco products, with three scoring a perfect 10 out of 10 on the standard severity scale. None are known to be exploited yet.

3 min read
Photoreal news-editorial image of a darkened enterprise server rack with one chassis status light glowing amber, fiber cables trailing into shadow, faint blue r
Vulnerabilities

NASA Spacecraft Control Software Has a Critical Flaw Attackers Could Use Remotely

Researchers at Cycode found a chain of bugs in AIT-GUI, a NASA/JPL tool used to talk to spacecraft, that lets outsiders send commands with no login required.

3 min read
A close-up, editorial-style photograph of a rack of illuminated server hardware in a dark data centre, cooling fans visible, status LEDs casting blue and amber
Vulnerabilities

Poland's CERT warns of active attacks on critical Zimbra email flaw

CERT Polska says attackers are exploiting CVE-2026-73570 in Zimbra Collaboration Suite. Zimbra patched the bug in version 10.1.20 on July 20.

4 min read
Close-up overhead view of dense rack-mounted network hardware in a dimly lit server room, indicator lights glowing amber and red across multiple units, cables b
Vulnerabilities

Citrix Patches Critical Login-Bypass Flaw in NetScaler, Attacks Expected Soon

A security hole rated 9.3 out of 10 lets criminals walk straight past the login screen on widely used corporate network gear. Patches are out now, and researchers say exploitation is a matter of when, not if.

3 min read
Photoreal news-editorial shot of a modern laptop on a clean desk showing a Windows-style update progress screen with a soft blue glow, wireless earbuds and a sm
Vulnerabilities

Microsoft probes Windows 11 August update after gamers report crashes in ARC Raiders and The Finals

The KB5121003 patch is under investigation after players on 24H2 and 25H2 reported freezes, access-violation errors and sudden reboots.

4 min read
Close-up top-down view of a sleek aluminum laptop keyboard and trackpad on a matte desk surface, soft cool studio lighting casting subtle shadows, a faint abstr
Vulnerabilities

Four Critical Security Flaws Exploited in Apple, Microsoft, and VMware Products

CISA warns of active exploitation of severe vulnerabilities in popular software, affecting millions globally.

2 min read
Photoreal news-editorial style, 16:9, a cracked glass surface with two distinct reflections distorted and fragmented, cold blue and steel grey tones, harsh over
Vulnerabilities

Windows Defender Crashed Mid-Scan After Buggy Update, Microsoft Ships Fix

A faulty signature update knocked out Microsoft's built-in antivirus on Windows 10 and 11 machines this week, leaving scans failing and some users reinstalling their operating system before a patch arrived.

3 min read
A glowing red countdown timer overlaid on a rack of web hosting servers in a dark data center, lighting, shallow depth of field, sense of urgency
Vulnerabilities

CISA Orders Urgent Fixes for Four Actively Exploited Flaws in Windows, VMware, and macOS

Four security holes, all being actively abused by real attackers right now, need patches immediately. Two hit Microsoft, one VMware, one Apple.

4 min read
Overhead photoreal editorial shot of a server rack room bathed in cold blue-white fluorescent light, dense cables running between black rack units, a single amb
Vulnerabilities

Oracle Pushes 943 Security Fixes in August 2026 Patch Update

Oracle's latest monthly security release covers more than 1,000 flaws across two dozen products, including nearly 90 critical bugs that score almost perfectly on the industry's severity scale.

3 min read
Close-up top-down view of a sleek laptop keyboard with a shallow depth of field, the screen faintly glowing blue-white with an abstract grid of hexagonal shapes
Vulnerabilities

Firefox and Chrome Rush Out Patches for Dozens of Security Flaws

Mozilla fixed 58 vulnerabilities in Firefox 154, while Google addressed 15 in Chrome 151, including two critical bugs that could let attackers run malicious code on your device.

3 min read
Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
Vulnerabilities

CISA flags four actively exploited flaws in Microsoft, VMware and Apple products

The US cyber agency has told federal bodies to patch fast after seeing real attacks against SharePoint, vCenter, macOS and a Windows networking service.

3 min read
Extreme close-up of a glowing green terminal screen filled with cascading lines of package dependency text and vulnerability identifiers, shot from a low angle
Vulnerabilities

Six flaws in CISA's own Malcolm network tool let low-level users run code and slip past access checks

The US cyber agency's open-source traffic analyzer, used by defenders worldwide, shipped with a file-upload bug that hands attackers a shell as the web user, plus two authorization gates that fall open on a simple URL trick.

4 min read
© 2026 Threat Vectr