Vulnerabilities — Page 6

The 'CDN Tsunami' Attack Turns a Trickle of Traffic Into a Flood at the Origin
Researchers show how the way big content delivery networks translate modern HTTP/3 requests into older HTTP/1.1 can multiply a small attack stream by up to 350 times against the website behind them.

'Zombie Card' Attack Brings Expired Visa Contactless Cards Back to Life
UMass Amherst researchers show how to rewrite the expiry date a payment terminal sees, letting dead cards buy real goods.

Atlassian and Splunk Push Patches for More Than 250 Flaws, Including Critical Bugs
Two major software vendors dropped sweeping security updates this week. Here is what changed, what could go wrong without the fix, and what ordinary users should know.

Cisco Patches Four Maximum-Severity Flaws in Crosswork Network Software
Fifteen vulnerabilities fixed across Cisco products, with three scoring a perfect 10 out of 10 on the standard severity scale. None are known to be exploited yet.

NASA Spacecraft Control Software Has a Critical Flaw Attackers Could Use Remotely
Researchers at Cycode found a chain of bugs in AIT-GUI, a NASA/JPL tool used to talk to spacecraft, that lets outsiders send commands with no login required.

Poland's CERT warns of active attacks on critical Zimbra email flaw
CERT Polska says attackers are exploiting CVE-2026-73570 in Zimbra Collaboration Suite. Zimbra patched the bug in version 10.1.20 on July 20.

Citrix Patches Critical Login-Bypass Flaw in NetScaler, Attacks Expected Soon
A security hole rated 9.3 out of 10 lets criminals walk straight past the login screen on widely used corporate network gear. Patches are out now, and researchers say exploitation is a matter of when, not if.

Microsoft probes Windows 11 August update after gamers report crashes in ARC Raiders and The Finals
The KB5121003 patch is under investigation after players on 24H2 and 25H2 reported freezes, access-violation errors and sudden reboots.

Four Critical Security Flaws Exploited in Apple, Microsoft, and VMware Products
CISA warns of active exploitation of severe vulnerabilities in popular software, affecting millions globally.

Windows Defender Crashed Mid-Scan After Buggy Update, Microsoft Ships Fix
A faulty signature update knocked out Microsoft's built-in antivirus on Windows 10 and 11 machines this week, leaving scans failing and some users reinstalling their operating system before a patch arrived.

CISA Orders Urgent Fixes for Four Actively Exploited Flaws in Windows, VMware, and macOS
Four security holes, all being actively abused by real attackers right now, need patches immediately. Two hit Microsoft, one VMware, one Apple.

Oracle Pushes 943 Security Fixes in August 2026 Patch Update
Oracle's latest monthly security release covers more than 1,000 flaws across two dozen products, including nearly 90 critical bugs that score almost perfectly on the industry's severity scale.

Firefox and Chrome Rush Out Patches for Dozens of Security Flaws
Mozilla fixed 58 vulnerabilities in Firefox 154, while Google addressed 15 in Chrome 151, including two critical bugs that could let attackers run malicious code on your device.

CISA flags four actively exploited flaws in Microsoft, VMware and Apple products
The US cyber agency has told federal bodies to patch fast after seeing real attacks against SharePoint, vCenter, macOS and a Windows networking service.

Six flaws in CISA's own Malcolm network tool let low-level users run code and slip past access checks
The US cyber agency's open-source traffic analyzer, used by defenders worldwide, shipped with a file-upload bug that hands attackers a shell as the web user, plus two authorization gates that fall open on a simple URL trick.