Tag

#vulnerability disclosure

50 stories taggedvulnerability disclosure.

Full-frame edge-to-edge photoreal news-editorial shot of a darkened modern data center aisle, glowing amber server LEDs reflecting on polished floor, faint blue
AI Security

Researchers Tricked Microsoft Copilot Into Revealing Its Own Weaknesses, Then Used That Knowledge to Steal Data

A research team at Varonis discovered that simply chatting with Microsoft's AI assistant could expose enough internal detail to build a working attack. Microsoft has patched the flaws, but the technique raises questions that go well beyond one product.

4 min read
Photoreal editorial shot of a vintage red vending machine in a dim server room, glowing softly, dispensing translucent glass capsules that contain glowing circu
AI Security

Black Hat 2026: Five Security Findings Every Organisation Should Know About

From fake AI tools downloaded 1.7 million times to a flaw that lets attackers hijack internet connections through network devices, this year's hacker conference in Las Vegas carried some practical warnings for businesses of every size.

4 min read
Photoreal news-editorial image, full-frame edge-to-edge 16:9 composition
Vulnerabilities

Millions of Belgians' IDs and bank accounts were wide open through a government browser extension

A browser extension used by more than 2 million Belgians to log into government and banking websites contained flaws so serious that criminals could have stolen identities, hijacked payment cards, and taken full control of victims' computers. The vendor fixed the problems on 22 July.

4 min read
A vast, dimly lit server hall photographed head-on, rows of identical racks receding into the distance with only a fraction illuminated by cool blue status ligh
Policy & Regulation

A 1990 Law Could Send Ethical Hackers to Prison. Dozens of Countries Are Fixing That.

Researcher Katharina Sommer mapped which nations protect good-faith security work and built a five-point blueprint to push the UK's creaking Computer Misuse Act into the present day.

4 min read
Close-up overhead shot of a dense rack of enterprise networking and telephony hardware, blinking amber and red indicator lights visible across multiple units, s
Vulnerabilities

Cisco Patches a Dozen Flaws in SD-WAN and IOS XE, Three Rated Critical

An internal Cisco security review turned up 12 vulnerabilities, including three with a severity score of 9.8 out of 10, in software that runs corporate networks worldwide.

3 min read
Full-frame photoreal editorial image of a darkened developer workstation with two glowing monitors, one showing abstract code and the other showing a plain web
AI Security

Researchers Find AI Agents at AWS, Google and Vercel Can Be Tricked Into Running Tools Without the AI

Flaws in agent plumbing let forged instructions reach powerful tools before any safety check runs, and in some cases the AI model never runs at all.

4 min read
Full-frame 16:9 photoreal editorial image of a dark server room with a single illuminated monitor displaying abstract blue shield iconography under a red alert
Vulnerabilities

Microsoft Paid Out $20 Million in Bug Bounty Rewards This Year

More than 560 security researchers from 64 countries were paid to find and report software flaws. Not everyone is happy about how the company handled the work.

3 min read
Photoreal news-editorial shot of a stack of rack-mounted network appliances in a dim server room, faint amber status LEDs reflecting off polished floor tiles, s
Vulnerabilities

AI Scanner Finds Eight Serious Bugs in NodeBB Forum Software

Aikido Security's automated code review turned up admin takeover and private-message flaws in six hours. All eight are patched in version 4.14.2.

3 min read
Photoreal news-editorial image, full-frame edge-to-edge 16:9 composition
Vulnerabilities

Oracle Patches 1,434 Flaws in One Go. AI Probably Found Most of Them.

Oracle's July 2026 quarterly security update is the largest in the company's history, covering hundreds of products used by hospitals, banks, retailers, and governments worldwide.

3 min read
Photoreal editorial shot of a modern smartphone screen showing a generic mail app inbox with a blurred alias-style email address at the top, sitting on a matte
Vulnerabilities

Apple Patches Year-Old Hide My Email Bug That Leaked Real Addresses

A flaw in Apple's email-cloaking feature let real addresses appear in mail logs. The fix took over a year to ship.

3 min read
A close-up photorealistic view of a fractured dark blue computer chip on a black reflective surface, with hairline cracks glowing faint red from underneath, sha
Vulnerabilities

Meta Paid a Researcher $78,000 to Find a Flaw That Exposed Support Chats and Personal Data

An independent security researcher discovered a hole in Meta's internal support system that could have let anyone read private conversations between users and Meta support staff. Meta patched it quietly. Then came the cheque.

3 min read
AI scanning for software vulnerabilities
AI Security

Ivanti Used AI to Find a Perfect-Score Security Flaw in Its Own Software. Here Is What That Means.

The company quietly ran an AI project starting in March and says the results are already surprising even its own security chief.

3 min read
Aerial view of a large industrial fuel storage facility at dusk, rows of cylindrical metal tanks reflecting low amber light, pressure gauges and pipe networks v
Vulnerabilities

The Machines That Run the World Are Running Decades-Old Software

Industrial control systems keep factories, water plants, and power grids alive. They also run code written before Wi-Fi existed. Fixing that is harder than it sounds.

3 min read
A dimly lit server room with rows of rack-mounted hardware, status indicator lights blinking amber and red in rhythmic patterns, cool blue ambient light casting
Vulnerabilities

Splunk and Zoom Fix Security Flaws That Could Let Hackers Take Over Accounts

Both companies pushed out patches this week. One Zoom flaw scores a near-perfect danger rating and could let a criminal break into accounts without knowing a password.

3 min read
A digital lock with a double-factor authentication symbol, representing security in software supply chains
Policy & Regulation

Five Government Agencies Tell Software Makers: Open a Front Door for Bug Reporters

CISA and four allied agencies have published a joint guide urging tech companies to set up formal programmes so security researchers can safely report flaws before criminals find them first.

3 min read
© 2026 Threat Vectr