Tag

#vulnerability disclosure

45 stories taggedvulnerability disclosure.

Illustration: a large industrial server room at night
Policy & Regulation

The EU's New Cyber Security Law Gives Manufacturers 24 Hours to Report Flaws. Almost No One Is Ready.

The Cyber Resilience Act, which took effect in September, requires companies to report actively exploited vulnerabilities within one day. Security experts say the clock will break every manual process most vendors currently rely on.

4 min read
Illustration: a darkened office workstation
Vulnerabilities

A researcher keeps dropping Windows Defender zero-days, and Microsoft is losing patience

Abdelhamid Naceri's latest proof-of-concept, BigDiskBuster, stops Microsoft's built-in antivirus from updating. It is the eleventh unpatched flaw he has posted this year in a public feud with Redmond.

4 min read
A calendar showing September 11 highlighted in red with notification badges, surrounded by software vendor communication interfaces and vulnerability disclosure
Policy & Regulation

The EU's New 24-Hour Bug Reporting Rule Starts September 11. Most Vendors Aren't Ready.

A new European law forces software makers to disclose actively exploited flaws within a day. The hard part isn't the paperwork, it's knowing what you shipped.

4 min read
Federal cybersecurity operations center with urgent alert banners across multiple screens displaying NetScaler vulnerability information, patch deployment timel
Vulnerabilities

CISA Warns of Active Attacks on Critical NetScaler Flaw

Federal agencies have three days to patch CVE-2026-19490 after CISA confirmed criminals are actively exploiting the high-severity flaw in Citrix's widely used network gateway software.

3 min read
A competitive hacking event setup with multiple workstations, live leaderboards displaying submission counts, and technical diagrams of Linux kernel architectur
Vulnerabilities

Vercel's $1 Million Sandbox Challenge Turned Up Linux Kernel Bugs Nobody Knew About

A two-week public hacking contest aimed at Vercel's AI code sandbox drew 1,285 submissions and uncovered two serious Linux kernel bugs that affect far more than one company.

4 min read
A security researcher's desk with multiple monitors displaying code exploits, vulnerability details, and security software logos (CrowdStrike, Avast, Nvidia), d
Vulnerabilities

One Researcher Just Published Working Hacks Against CrowdStrike, Avast, and Nvidia

A prolific security researcher dropped three zero-day exploits in a single week, targeting software that millions of people and businesses rely on to stay safe.

4 min read
An IT service provider's office with technicians at workstations displaying N-able N-central remote management software, critical alert banners visible across m
Vulnerabilities

A Zero-Day With a Perfect Danger Score Is Being Exploited in N-able's Remote Management Software

Three vulnerabilities in four days have left IT service providers scrambling to patch N-central, the tool they use to remotely manage their customers' computers. One flaw is already being used by attackers.

3 min read
A software repository server facility with glowing rack-mounted hardware and network cables, while a security alert banner scrolls across a monitoring station's
Vulnerabilities

Hackers Are Already Breaking Into Software Stores Using a Flaw Disclosed Three Days Ago

A critical security hole in JFrog Artifactory, a platform used by thousands of companies to store and ship software, is being actively exploited just 72 hours after its public disclosure.

4 min read
Close-up of a circuit board with memory modules and error-correction circuitry illuminated under cool blue light, showing intricate pathways and semiconductor c
Vulnerabilities

NVIDIA workstation GPUs fall to GPUThor attack that beats built-in error correction

University of Toronto researchers show a Rowhammer variant can crash Ampere-class NVIDIA cards or hand an attacker root access, and NVIDIA has now issued guidance.

4 min read
A web browser loading a webpage with a malicious hidden instruction being silently injected into a local NVIDIA AI model interface running in the background tas
AI Security

Researchers Warn a Booby-Trapped Webpage Could Hijack NVIDIA NemoClaw AI Agents

Oasis Security says a flaw in NVIDIA's NemoClaw lets a malicious site quietly take over a local AI model and slip in hidden instructions.

3 min read
A corporate development environment showing Spring framework code with security patches being silently applied in the background, while a security team at separ
Policy & Regulation

Silent Software Patches Protect Hackers, Not Users

When companies fix security flaws without telling anyone, the people paid to defend your data are flying blind. A new Broadcom programme for its Spring software framework shows exactly how that plays out.

4 min read
A researcher's computer showing a chat interface with an AI assistant, with internal system information and security weaknesses being revealed in the conversati
AI Security

Researchers Tricked Microsoft Copilot Into Revealing Its Own Weaknesses, Then Used That Knowledge to Steal Data

A research team at Varonis discovered that simply chatting with Microsoft's AI assistant could expose enough internal detail to build a working attack. Microsoft has patched the flaws, but the technique raises questions that go well beyond one product.

4 min read
The Las Vegas convention center during Black Hat conference with security professionals examining booth displays of attack tools and vulnerability demonstration
AI Security

Black Hat 2026: Five Security Findings Every Organisation Should Know About

From fake AI tools downloaded 1.7 million times to a flaw that lets attackers hijack internet connections through network devices, this year's hacker conference in Las Vegas carried some practical warnings for businesses of every size.

4 min read
A browser window open on a laptop showing a government login portal with security warning icons, surrounded by digital vulnerability indicators on the screen
Vulnerabilities

Millions of Belgians' IDs and bank accounts were wide open through a government browser extension

A browser extension used by more than 2 million Belgians to log into government and banking websites contained flaws so serious that criminals could have stolen identities, hijacked payment cards, and taken full control of victims' computers. The vendor fixed the problems on 22 July.

4 min read
A policy research office with international cybersecurity law documents spread across a desk, a world map with legal status indicators for different countries,
Policy & Regulation

A 1990 Law Could Send Ethical Hackers to Prison. Dozens of Countries Are Fixing That.

Researcher Katharina Sommer mapped which nations protect good-faith security work and built a five-point blueprint to push the UK's creaking Computer Misuse Act into the present day.

4 min read
© 2026 Threat Vectr