Vulnerabilities — Page 7

Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
Vulnerabilities

CISA flags four actively exploited flaws in Microsoft, VMware and Apple products

The US cyber agency has told federal bodies to patch fast after seeing real attacks against SharePoint, vCenter, macOS and a Windows networking service.

3 min read
Extreme close-up of a glowing green terminal screen filled with cascading lines of package dependency text and vulnerability identifiers, shot from a low angle
Vulnerabilities

Six flaws in CISA's own Malcolm network tool let low-level users run code and slip past access checks

The US cyber agency's open-source traffic analyzer, used by defenders worldwide, shipped with a file-upload bug that hands attackers a shell as the web user, plus two authorization gates that fall open on a simple URL trick.

4 min read
Full-frame photoreal editorial image of a rack-mounted network security appliance in a dimly lit server room, blue and amber status LEDs glowing, ethernet cable
Vulnerabilities

Patching Once a Month Is No Longer Enough, Rapid7 Warns

Security firm Rapid7 says the old model of fixing software flaws on a fixed schedule is breaking down, as the number of new vulnerabilities grows faster than most organisations can respond.

3 min read
Photoreal news-editorial shot of a dimly lit server rack in an enterprise data center, amber status LEDs glowing on rack-mounted servers, faint blue ambient lig
Vulnerabilities

Ransomware crews jump on a Windows Task Host bug that hands over full control of the PC

CISA says criminals are now using CVE-2025-60710, a Windows privilege escalation flaw Microsoft patched in November, to seize SYSTEM-level access on unpatched Windows 11 and Server 2025 machines.

3 min read
A glowing browser window open on a dark desk, its interface showing cascading lines of code in shades of blue and green, an ominous amber warning glow emanating
Vulnerabilities

Microsoft pulls a 30-year-old Windows tool that hackers loved

WMIC, a command-line utility abused by ransomware crews to wipe backups and disable antivirus, is gone from fresh installs of Windows 11 24H2 and 25H2.

4 min read
A dimly lit server room with rows of dark racks, one panel glowing red with warning indicator lights, thin blue fibre-optic cables running along the ceiling, sh
Vulnerabilities

CISA Adds Actively Exploited Ray AI Framework Flaw to Must-Patch List

The bug in Ray, a popular open-source tool for running AI workloads, is being abused in the wild. CISA gave federal agencies a deadline to fix it.

3 min read
Full-frame photoreal editorial image of a dimly lit enterprise server room with rows of blue-lit rack units, one cabinet door open showing status LEDs, faint re
Vulnerabilities

Apple Patches Dozens of WebKit Flaws That Could Let Attackers Crash or Spy on Your iPhone and Mac

A wave of security fixes landed for iPhones and Macs, closing holes in the browser engine that powers Safari. Some bugs were serious enough to let criminals steal data or break out of the software's built-in safety walls.

3 min read
Photoreal news-editorial shot of a stack of rack-mounted network appliances in a dim server room, faint amber status LEDs reflecting off polished floor tiles, s
Vulnerabilities

Critical GitLab Flaw Lets Attackers Wipe Public Projects Without Logging In

GitLab has patched a flaw rated 9.4 out of 10 that let unauthenticated attackers alter or delete public projects and user data through the platform's GraphQL interface.

3 min read
Full-frame close-up, 16:9, of a small circuit board with a USB stick partially inserted, warm amber and cool blue lighting, shallow depth of field, faint solder
Vulnerabilities

A booby-trapped GitHub ticket could have stolen Snowflake's internal Jira keys

Researchers at Wiz found a flaw in a Snowflake code repository that let anyone on the internet run commands inside its automated build system, exposing credentials to the company's private issue tracker.

4 min read
Photoreal news-editorial overhead shot of a darkened security operations center desk, multiple monitors glowing blue with abstract vulnerability dashboards and
Vulnerabilities

Forminator WordPress Plugin Carries Critical Flaw Rated 9.8; 600,000 Sites Affected

A newly disclosed vulnerability in the Forminator plugin lets attackers upload malicious files without logging in, putting hundreds of thousands of WordPress sites at risk of full takeover.

4 min read
Photoreal news-editorial shot of a darkened server room with a single Windows laptop open on a rack shelf, screen glowing pale blue with abstract registry-tree
Vulnerabilities

Certighost: The Windows Certificate Flaw That Hands Attackers the Keys to the Kingdom

A newly disclosed bug, CVE-2026-54121, lets any ordinary staff account quietly promote itself to top-level control of a Windows network by abusing the company's certificate server.

4 min read
Full-frame overhead photoreal shot of an Android smartphone on a wooden cafe table, screen glowing with a generic VPN connection interface, faint reflection of
Vulnerabilities

A Video Call Can Now Hand Attackers the Keys to Your Android Phone

Researchers say a two-stage exploit against Unisoc modem chips turns a VoLTE video call into full kernel access, and there is no patch.

4 min read
Extreme close-up of a glowing smartphone screen showing a software update progress bar, deep shadows around the device, cool blue-white light from the screen il
Vulnerabilities

Dutch cyber agency warns of live attacks on macOS Screen Sharing flaw

Hackers are breaking into Mac computers exposed to the internet, seizing top-level control, and quietly mining Monero cryptocurrency.

4 min read
Photoreal news-editorial photograph, 16:9 framing, edge-to-edge composition
Vulnerabilities

Oracle Releases Free Database Security Tool Amid Growing Pressure From AI-Powered Bug Hunters

Oracle Database Security Central gives organisations a single place to spot risky database settings and unusual access patterns. It is free until February 2027, though the window that prompted its creation is already closing.

3 min read
A visual representation of a digital storm hitting a Drupal logo, symbolizing a security vulnerability
Vulnerabilities

Hackers Are Already Probing a Dangerous, Unpatched Flaw in GeoServer

A newly public security hole in popular mapping software is drawing hundreds of attack attempts within hours. No fix exists yet.

3 min read
© 2026 Threat Vectr