#vulnerabilities
74 stories taggedvulnerabilities · page 2 of 5.

Oracle Pushes 943 Security Fixes in August 2026 Patch Update
Oracle's August 2026 security release closes more than 1,000 flaws across two dozen products, with nearly 90 critical bugs scoring 9.8 or higher on the industry's 0-to-10 severity scale.

Six flaws in CISA's own Malcolm network tool let low-level users run code and slip past access checks
The US cyber agency's open-source traffic analyzer, used by defenders worldwide, shipped with a file-upload bug that hands attackers a shell as the web user, plus two authorization gates that fall open on a simple URL trick.

Patching Once a Month Is No Longer Enough, Rapid7 Warns
Security firm Rapid7 says the old model of fixing software flaws on a fixed schedule is breaking down, as the number of new vulnerabilities grows faster than most organisations can respond.

AI is getting better at breaking software than fixing it
Multiple studies show AI tools write insecure code nearly as often as they did a year ago, even as those same tools grow sharper at finding and exploiting the very flaws they leave behind.

Apple Patches Dozens of WebKit Flaws That Could Let Attackers Crash or Spy on Your iPhone and Mac
A wave of security fixes landed for iPhones and Macs, closing holes in the browser engine that powers Safari. Some bugs were serious enough to let criminals steal data or break out of the software's built-in safety walls.

Zhipu's GLM-5.3 AI Model: A Double-Edged Sword in Cybersecurity
Zhipu's new coding AI finds vulnerabilities faster than expected, and the open-weight release means anyone can download that capability.

Mindgard Raises $30 Million to Test AI Systems for Security Flaws
The London-and-Boston startup has already found more than 150 vulnerabilities in popular AI products, including a previously unknown flaw in a widely used code editor. Fresh capital will expand its engineering and sales teams.

Some of the Bugs That Hid Inside Everyday Software for Decades
From a print-spooler flaw that Stuxnet quietly exploited to a 30-year-old graphics library hole, a handful of the most stubborn software vulnerabilities ever found show how long danger can lurk unnoticed.

Cisco firewalls are being crashed through a VPN flaw, and the fix is a full software upgrade
A high-severity bug in Cisco's Secure Firewall ASA and FTD software lets attackers reboot devices remotely with a single crafted web request. Cisco says the attacks started in August.

Two Million Belgians Exposed by Flaws in the Software They Use to Sign Legal Documents Online
Security researcher James Arnott found that Belgium's most-used digital identity tool could let any malicious website steal a user's PIN, forge their electronic signature, or quietly run attack code on their computer, all without the victim clicking anything suspicious.

A Safety Recall on a Truck Brake Controller Was Also Quietly Fixing Security Flaws
NMFTA researchers found that a Bendix EC-80 recall patched serious software vulnerabilities, including one that could let an attacker run their own code on a commercial truck's braking system, with no cybersecurity advisory ever issued.

The Window Between a New Vulnerability and an Active Attack Is Getting Shorter
Security teams are buried in alerts while attackers move faster than ever. The real problem isn't a shortage of warnings. It's knowing which ones actually matter before criminals act on them.

Cisco Patches 24 Flaws, Including a Perfect-Score Bug That Hands Attackers Full Control
A flaw in Cisco's firewall management software scores a rare 10 out of 10 on the severity scale, meaning a remote attacker needs no password to take complete control of an affected system.

15 Flaws in TP-Link Kit Put Automatic Network Setup at Risk
Security researchers found 15 vulnerabilities in TP-Link's Omada networking system and warn that the convenient zero-touch setup process millions of organisations rely on could hand criminals the keys to an entire network.

CISA Adds Three Actively Exploited Bugs to Its Must-Patch List
A critical Langflow flaw joins Apache Tomcat and N-central issues on the U.S. government's Known Exploited Vulnerabilities catalog after evidence of live attacks.