#vulnerabilities
74 stories taggedvulnerabilities · page 5 of 5.

Researchers Show How a Fake GitHub Comment Can Trick AI Tools Into Leaking Secret Code
A crafted public comment on GitHub can manipulate AI-powered automation into handing over data from private repositories, no password required.

New Chinese AI Models Challenge Cyber Defenses
Two new Chinese AI models can find software vulnerabilities faster and cheaper than most defenders can patch them.

Citrix NetScaler Vulnerability Sparks Exploitation Attempts
Citrix patches a high-severity flaw in NetScaler appliances as exploitation attempts are reported within 24 hours.

NIST's Cutback on Vulnerability Enrichment Sparks Concerns
New research finds thousands of CVEs left unanalyzed or inaccurately scored after NIST scaled back its National Vulnerability Database work.

One Researcher, 14 Flaws, Millions of Indians at Risk
A young independent security researcher found gaping holes in Indian government portals, including an admin panel left wide open to the entire internet. The government fixed everything within three weeks.

IBM and Red Hat Launch $5 Billion Initiative to Secure Open-Source Software
IBM and Red Hat invest heavily in Project Lightwell to address open-source software vulnerabilities revealed by Anthropic's AI.

Apple Shifts Security Update Strategy Amid AI-Driven Cyber Threats
Apple now releases security patches more frequently to tackle the growing threats posed by AI-enhanced cyberattacks.

CISA Flags SharePoint Deserialization Bug CVE-2026-45659 as Actively Exploited
The RCE flaw joins KEV with a three-week federal patch deadline. Attribution details remain thin.

Apple Ships Multi-Component Patch Round Covering iOS, macOS, and Safari
Fixes land for WebKit, the kernel, WebRTC, and Web Extensions, touching every major Apple platform in a single release cycle.

Citrix Ships Fixes for Six NetScaler Bugs, Including a File-Read Flaw Scoring 8.8
The patch batch covers NetScaler ADC and Gateway, with input-validation and DoS issues that admins should not sit on.

CISA Flags Three Daktronics Controller Flaws That Could Let Attackers Hijack Highway Signs
A researcher found the vulnerabilities in controllers widely used to drive digital billboards and roadway message signs. Exploitation could mean someone else controls what drivers read.

CISA Flags Active Exploitation of Lantronix EDS5000 Code Injection Bug
CVE-2025-67038 carries a 9.8 CVSS. Federal agencies have until June 26, 2026 to patch, but if it's already being hit in the wild, that runway looks generous.

GitHub Tightens Security to Counter Pwn Request Attacks
actions/checkout v7 automatically blocks workflows that pull unreviewed fork code inside pull_request_target events, with backports arriving July 16.

AI in Cyber Operations: From Scripts to Autonomous Systems
AI's role in cyber operations is not just about speed anymore. It's about scale and autonomy, reshaping offensive capabilities.