#vulnerabilities
74 stories taggedvulnerabilities · page 3 of 5.

cPanel patches critical database flaw that let hosting customers run SQL as root
A newly disclosed bug, CVE-2026-58048, crossed the line between a single hosting account and the server's master database identity. cPanel has shipped a targeted fix.

Researchers Find 84 Flaws in the Guts of 4G and 5G Networks
A Singapore university team says weaknesses in mobile core software could let attackers knock users offline or hijack their sessions.

Google Patches 1,442 Chrome Flaws Across Three Releases, More Than the Prior 23 Combined
Chrome 149, 150 and 151 together resolved more security bugs than nearly two years of previous updates, with Google's own researchers flagging the bulk of the issues.

One in Five Data Centre Systems Is One Step Away From Hackers, Research Finds
A study of 174,000 data centre infrastructure devices found that roughly 32,000 sit just one network hop from the open internet, putting cooling, power and fire systems within easier reach of attackers than most operators realise.

Google Patches 370 Security Flaws in Chrome 151, Including Seven Critical Bugs
The browser update is one of Google's largest single releases of the year, fixing flaws that could let attackers take control of your browser or crash it entirely.

What Is Really Inside Your Work Apps? Lookout's New Tool Aims to Tell You
A new scanning service from mobile security firm Lookout builds detailed ingredient lists for enterprise apps, exposing hidden vulnerable components before criminals can exploit them.

GitLab Flaw Lets Any Logged-In User Run Commands on Self-Hosted Servers
Researcher Yuhang Wu published working exploit code against GitLab 18.11.3 that hijacks the server through two booby-trapped notebooks and a diff request.

Three Security Stories You May Have Missed: Industrial Switches, Russian Email Spying, and a Rail Ransomware Shakedown
Flaws in Siemens industrial network hardware, a Russian espionage campaign targeting Zimbra webmail servers, and a ransomware extortion attempt against Swiss train maker Stadler Rail.

Redis Patches Four Code-Execution Bugs After AI Agent Finds Zero-Days
Seven security releases went out on July 23 after researchers used Moonshot AI's Kimi K3 agents to uncover authenticated remote code execution chains in stock Redis builds.

What is a CVE and how does vulnerability scoring work?
CVEs are the universal ID system for software flaws, and CVSS scores tell you how bad each one actually is.

What is a zero-day vulnerability? A plain-English guide
Zero-days are unpatched security flaws the software vendor doesn't know about yet, making them among the most dangerous bugs in existence.

GitHub Slashes Public Bug Bounty Payouts, Reserves Top Rewards for VIPs
From July 27, 2026, GitHub is cutting what it pays public researchers for security finds, while keeping the largest rewards for an invite-only group.

Oracle's Largest Patch Update Fixes Hundreds of Vulnerabilities
Oracle's July 2026 Critical Patch Update is its biggest ever, with ten perfect-10 flaws in Fusion Middleware and a 9.9-scored hole in the flagship database product.

AI-Written Apps Are Shipping With Hundreds of Security Holes, Study Finds
A new analysis counted 434 exploitable flaws across apps built with AI coding tools, raising hard questions about who checks the work when the developer is a machine.

AI Coding Tools Carry Real Security Risks, and the Danger Depends on What You're Building With
A new study tested 16 major AI coding assistants and found an average of 15 security flaws per project. The safest choice for one type of software can be one of the worst for another.