#vulnerability disclosure
45 stories taggedvulnerability disclosure.

The EU's New Cyber Security Law Gives Manufacturers 24 Hours to Report Flaws. Almost No One Is Ready.
The Cyber Resilience Act, which took effect in September, requires companies to report actively exploited vulnerabilities within one day. Security experts say the clock will break every manual process most vendors currently rely on.

A researcher keeps dropping Windows Defender zero-days, and Microsoft is losing patience
Abdelhamid Naceri's latest proof-of-concept, BigDiskBuster, stops Microsoft's built-in antivirus from updating. It is the eleventh unpatched flaw he has posted this year in a public feud with Redmond.

The EU's New 24-Hour Bug Reporting Rule Starts September 11. Most Vendors Aren't Ready.
A new European law forces software makers to disclose actively exploited flaws within a day. The hard part isn't the paperwork, it's knowing what you shipped.

CISA Warns of Active Attacks on Critical NetScaler Flaw
Federal agencies have three days to patch CVE-2026-19490 after CISA confirmed criminals are actively exploiting the high-severity flaw in Citrix's widely used network gateway software.

Vercel's $1 Million Sandbox Challenge Turned Up Linux Kernel Bugs Nobody Knew About
A two-week public hacking contest aimed at Vercel's AI code sandbox drew 1,285 submissions and uncovered two serious Linux kernel bugs that affect far more than one company.

One Researcher Just Published Working Hacks Against CrowdStrike, Avast, and Nvidia
A prolific security researcher dropped three zero-day exploits in a single week, targeting software that millions of people and businesses rely on to stay safe.

A Zero-Day With a Perfect Danger Score Is Being Exploited in N-able's Remote Management Software
Three vulnerabilities in four days have left IT service providers scrambling to patch N-central, the tool they use to remotely manage their customers' computers. One flaw is already being used by attackers.

Hackers Are Already Breaking Into Software Stores Using a Flaw Disclosed Three Days Ago
A critical security hole in JFrog Artifactory, a platform used by thousands of companies to store and ship software, is being actively exploited just 72 hours after its public disclosure.

NVIDIA workstation GPUs fall to GPUThor attack that beats built-in error correction
University of Toronto researchers show a Rowhammer variant can crash Ampere-class NVIDIA cards or hand an attacker root access, and NVIDIA has now issued guidance.

Researchers Warn a Booby-Trapped Webpage Could Hijack NVIDIA NemoClaw AI Agents
Oasis Security says a flaw in NVIDIA's NemoClaw lets a malicious site quietly take over a local AI model and slip in hidden instructions.

Silent Software Patches Protect Hackers, Not Users
When companies fix security flaws without telling anyone, the people paid to defend your data are flying blind. A new Broadcom programme for its Spring software framework shows exactly how that plays out.

Researchers Tricked Microsoft Copilot Into Revealing Its Own Weaknesses, Then Used That Knowledge to Steal Data
A research team at Varonis discovered that simply chatting with Microsoft's AI assistant could expose enough internal detail to build a working attack. Microsoft has patched the flaws, but the technique raises questions that go well beyond one product.

Black Hat 2026: Five Security Findings Every Organisation Should Know About
From fake AI tools downloaded 1.7 million times to a flaw that lets attackers hijack internet connections through network devices, this year's hacker conference in Las Vegas carried some practical warnings for businesses of every size.

Millions of Belgians' IDs and bank accounts were wide open through a government browser extension
A browser extension used by more than 2 million Belgians to log into government and banking websites contained flaws so serious that criminals could have stolen identities, hijacked payment cards, and taken full control of victims' computers. The vendor fixed the problems on 22 July.

A 1990 Law Could Send Ethical Hackers to Prison. Dozens of Countries Are Fixing That.
Researcher Katharina Sommer mapped which nations protect good-faith security work and built a five-point blueprint to push the UK's creaking Computer Misuse Act into the present day.