#vulnerabilities
66 stories taggedvulnerabilities · page 2 of 5.

GitLab Flaw Lets Any Logged-In User Run Commands on Self-Hosted Servers
A researcher published working exploit code against GitLab 18.11.3 that hijacks the server through two booby-trapped notebooks and a diff request.

Three Security Stories You May Have Missed: Industrial Switches, Russian Email Spying, and a Rail Ransomware Shakedown
A digest of under-reported threats: flaws in Siemens industrial network hardware, a Russian hacking campaign targeting Zimbra webmail servers, and a ransomware attack against Swiss train maker Stadler Rail.

Redis Patches Four Code-Execution Bugs After AI Agent Finds Zero-Days
Seven security releases went out on July 23 after researchers used Moonshot AI's Kimi K3 agents to uncover authenticated remote code execution chains in stock Redis builds.

What is a CVE and how does vulnerability scoring work?
CVEs are the universal ID system for software flaws, and CVSS scores tell you how bad each one actually is.

What is a zero-day vulnerability? A plain-English guide
Zero-days are unpatched security flaws the software vendor doesn't know about yet, making them among the most dangerous bugs in existence.

GitHub Slashes Public Bug Bounty Payouts, Reserves Top Rewards for VIPs
Starting July 27, 2026, GitHub will reduce public bug bounty payments, with top prizes reserved for an exclusive group.

Oracle's Largest Patch Update Fixes Hundreds of Vulnerabilities
Oracle releases its biggest Critical Patch Update yet, addressing severe vulnerabilities in multiple products.

AI-Written Apps Are Shipping With Hundreds of Security Holes, Study Finds
A new analysis counted 434 exploitable flaws across apps built with AI coding tools. The findings raise hard questions about who is responsible when software writes itself.

AI Coding Tools Carry Real Security Risks, and the Danger Depends on What You're Building With
A new study tested 16 major AI coding assistants and found an average of 15 security flaws per project. The safest choice for one type of software can be one of the worst for another.

Hackers Start Breaking Into ServiceNow AI Platform Through Critical Flaw CVE-2026-6875
Attackers are exploiting a pre-authentication bug in ServiceNow's flagship platform just days after patches shipped, researchers confirm.

Google Patches Seven Memory Safety Bugs in Chrome 150, Three Rated Critical
All seven flaws were found internally or by researchers, not by criminals. But history says patch fast anyway.

Claude Mythos: A New Frontier in AI Cybersecurity
Anthropic's Claude Mythos emerges as a powerful AI tool for cybersecurity, promising faster vulnerability discovery but raising concerns over potential misuse.

CISA sounds alarm on SharePoint Server flaws being used to break in right now
The US cyber agency says attackers are chaining three unpatched holes in self-hosted SharePoint to bypass logins, run code and stay hidden. Nearly 10,000 servers sit exposed online.

SonicWall Rushes to Patch Two Live Attacks on Remote Access Boxes
One of the flaws scores a perfect 10 out of 10 for severity, and attackers are already using both in real intrusions.

SAP Fixes Critical NetWeaver Bug That Lets Logged-In Users Corrupt Memory
The July 2026 patch batch closes CVE-2026-44747, a 9.9-rated flaw in the ABAP application server that could expose or alter company data.