Latest stories — Page 2

Microsoft's AI bug-hunters logged 140 Windows CVEs in four months. The queue is now the problem.
FORGE Lab's agentic scanner is finding flaws faster than humans can validate and patch them, and the open-source world is feeling it too.

A single bad character can crash a vLLM server, and the fix is still pending
A moderate-severity flaw in the popular AI serving engine lets any logged-in user kill the whole process with one malformed request.

A teenage hacker, a Boeing spin-off, and the Oracle flaw tying them together
Jordanian authorities have detained the alleged leader of ShinyHunters as the group tried to extort a former Boeing aviation unit, using a critical Oracle PeopleSoft bug now on CISA's must-patch list.

CISA's Updated Software Ingredient List Rules Change What Knowing Your Code Actually Means
The US government just raised the bar on software transparency. The harder problem is that no single inventory was ever enough to answer the question that matters most: what can your software actually do?

One flaw, eight Atlassian products, no login required
A critical file-access vulnerability published this month lets anyone on the internet read files inside Atlassian's most trusted enterprise tools without ever signing in.

INC Ransom Claims Attack on US Firm Magnals.com
The ransomware group has listed the American company on its dark-web pressure site. The claim is unverified, and Magnals.com has not publicly confirmed any incident.

A Fresh Citrix Zero-Day Is Already Being Exploited, and Federal Agencies Have Three Days to Fix It
CVE-2026-88779 hit live networks almost immediately after Citrix shipped patches for two earlier flaws, leaving IT teams scrambling again.

A 9.8-severity hole in industrial email code puts water and energy gear at risk
A buffer overflow in the lwIP SMTP client could let an unauthenticated attacker crash or hijack equipment running in energy and water systems. A patch is available.

Two Open-Source Bugs Force Patch for Hitachi Energy's REB500 Grid Relay
A pair of flaws in a widely used XML parser could let an insider knock Hitachi Energy's protection relay offline. The fix is version 8.3.4.0.

ClingSTUN: The Linux Backdoor Hiding in Your Router's Traffic
A newly tracked malware strain is quietly turning home routers, security cameras, and smart-office hardware into a criminal relay network, and it uses the internet's own plumbing to avoid detection.

Langflow's Built-In Testing Tool Has No Password and Attackers Are Using It Right Now
Three critical flaws in the popular AI workflow builder let attackers run any code they like on your server, as root, without logging in. CISA ordered federal agencies to patch by May 26. Attackers are not waiting.

AI Is Cutting the Time Criminals Need to Turn a Known Bug Into a Working Attack
Exploitation of already-patched flaws is outpacing zero-days, CVE volumes are on track to hit 96,000 this year, and the window between public disclosure and first attack has shrunk to 80 days.

ShinyHunters Claims a Second PeopleSoft Zero-Day, and Oracle Has Said Nothing
A known criminal group says it used an unpatched Oracle flaw to break into FBI systems. The first PeopleSoft vulnerability is already being actively exploited. A possible second one has no patch, no CVE, and no vendor comment.

Ransomware Group Insomnia Claims Attack on Medical Records Firm Praxis EMR
A criminal gang that has claimed 53 victims since February has listed an American electronic health records company on its dark-web shaming site. The company has not confirmed anything.

UK Account Hijacking Fraud Up 400% as Scammers Sell Fake Tickets Through Victims' Own Profiles
Criminals are breaking into people's email and social media accounts to impersonate them, then selling counterfeit concert tickets to the victim's own friends. The UK's cybersecurity authority says one fix is already in most people's pockets.

Teenager accused of running KillSec ransomware gang arrested as police seize servers
Europol says three suspects were detained and eight searches carried out across four countries, taking down the leak site of a group tied to around 1,000 attacks.

Apple will tighten Full Disk Access after AI agents started reading everything
Apple says it will redesign the macOS permission that hands an approved app the keys to a user's files, mail and browsing history, after finding that AI assistants are quietly using it to hoover up personal data.

A Broken Cryptographic Check in SWIFT's Login Tool Handed Attackers Full PC Control
A homemade RSA verification routine in Thales Group's SConnect software left SWIFT banking access, Qatar's national identity system, and the Swedish Tax Agency open to silent drive-by attacks. The patch is out. Most users haven't moved.

Attackers Are Hunting a Rejetto HFS Flaw That an AI Model Found First
A session-cookie bug uncovered with Anthropic's Project Glasswing is now drawing live exploitation attempts against Rejetto's file server.

Citrix NetScaler Zero-Day Is Knocking Login Systems Offline
A memory flaw in NetScaler ADC and Gateway, now exploited in the wild, can crash the gateways many companies rely on for single sign-on. US federal agencies have three days to patch.

Australia Orders Federal Agencies to Audit Old Tech After AI Agent Exploited Medicare Systems
A government-wide stocktake of ageing technology is now mandatory for all 194 Australian federal entities, after an AI-assisted attack exposed how outdated systems make government networks easier to breach.