Vulnerabilities — Page 7

CISA flags four actively exploited flaws in Microsoft, VMware and Apple products
The US cyber agency has told federal bodies to patch fast after seeing real attacks against SharePoint, vCenter, macOS and a Windows networking service.

Six flaws in CISA's own Malcolm network tool let low-level users run code and slip past access checks
The US cyber agency's open-source traffic analyzer, used by defenders worldwide, shipped with a file-upload bug that hands attackers a shell as the web user, plus two authorization gates that fall open on a simple URL trick.

Patching Once a Month Is No Longer Enough, Rapid7 Warns
Security firm Rapid7 says the old model of fixing software flaws on a fixed schedule is breaking down, as the number of new vulnerabilities grows faster than most organisations can respond.

Ransomware crews jump on a Windows Task Host bug that hands over full control of the PC
CISA says criminals are now using CVE-2025-60710, a Windows privilege escalation flaw Microsoft patched in November, to seize SYSTEM-level access on unpatched Windows 11 and Server 2025 machines.

Microsoft pulls a 30-year-old Windows tool that hackers loved
WMIC, a command-line utility abused by ransomware crews to wipe backups and disable antivirus, is gone from fresh installs of Windows 11 24H2 and 25H2.

CISA Adds Actively Exploited Ray AI Framework Flaw to Must-Patch List
The bug in Ray, a popular open-source tool for running AI workloads, is being abused in the wild. CISA gave federal agencies a deadline to fix it.

Apple Patches Dozens of WebKit Flaws That Could Let Attackers Crash or Spy on Your iPhone and Mac
A wave of security fixes landed for iPhones and Macs, closing holes in the browser engine that powers Safari. Some bugs were serious enough to let criminals steal data or break out of the software's built-in safety walls.

Critical GitLab Flaw Lets Attackers Wipe Public Projects Without Logging In
GitLab has patched a flaw rated 9.4 out of 10 that let unauthenticated attackers alter or delete public projects and user data through the platform's GraphQL interface.

A booby-trapped GitHub ticket could have stolen Snowflake's internal Jira keys
Researchers at Wiz found a flaw in a Snowflake code repository that let anyone on the internet run commands inside its automated build system, exposing credentials to the company's private issue tracker.

Forminator WordPress Plugin Carries Critical Flaw Rated 9.8; 600,000 Sites Affected
A newly disclosed vulnerability in the Forminator plugin lets attackers upload malicious files without logging in, putting hundreds of thousands of WordPress sites at risk of full takeover.

Certighost: The Windows Certificate Flaw That Hands Attackers the Keys to the Kingdom
A newly disclosed bug, CVE-2026-54121, lets any ordinary staff account quietly promote itself to top-level control of a Windows network by abusing the company's certificate server.

A Video Call Can Now Hand Attackers the Keys to Your Android Phone
Researchers say a two-stage exploit against Unisoc modem chips turns a VoLTE video call into full kernel access, and there is no patch.

Dutch cyber agency warns of live attacks on macOS Screen Sharing flaw
Hackers are breaking into Mac computers exposed to the internet, seizing top-level control, and quietly mining Monero cryptocurrency.

Oracle Releases Free Database Security Tool Amid Growing Pressure From AI-Powered Bug Hunters
Oracle Database Security Central gives organisations a single place to spot risky database settings and unusual access patterns. It is free until February 2027, though the window that prompted its creation is already closing.

Hackers Are Already Probing a Dangerous, Unpatched Flaw in GeoServer
A newly public security hole in popular mapping software is drawing hundreds of attack attempts within hours. No fix exists yet.