#vulnerability disclosure
50 stories taggedvulnerability disclosure.

Researchers Tricked Microsoft Copilot Into Revealing Its Own Weaknesses, Then Used That Knowledge to Steal Data
A research team at Varonis discovered that simply chatting with Microsoft's AI assistant could expose enough internal detail to build a working attack. Microsoft has patched the flaws, but the technique raises questions that go well beyond one product.

Black Hat 2026: Five Security Findings Every Organisation Should Know About
From fake AI tools downloaded 1.7 million times to a flaw that lets attackers hijack internet connections through network devices, this year's hacker conference in Las Vegas carried some practical warnings for businesses of every size.

Millions of Belgians' IDs and bank accounts were wide open through a government browser extension
A browser extension used by more than 2 million Belgians to log into government and banking websites contained flaws so serious that criminals could have stolen identities, hijacked payment cards, and taken full control of victims' computers. The vendor fixed the problems on 22 July.

A 1990 Law Could Send Ethical Hackers to Prison. Dozens of Countries Are Fixing That.
Researcher Katharina Sommer mapped which nations protect good-faith security work and built a five-point blueprint to push the UK's creaking Computer Misuse Act into the present day.

Cisco Patches a Dozen Flaws in SD-WAN and IOS XE, Three Rated Critical
An internal Cisco security review turned up 12 vulnerabilities, including three with a severity score of 9.8 out of 10, in software that runs corporate networks worldwide.

Researchers Find AI Agents at AWS, Google and Vercel Can Be Tricked Into Running Tools Without the AI
Flaws in agent plumbing let forged instructions reach powerful tools before any safety check runs, and in some cases the AI model never runs at all.

Microsoft Paid Out $20 Million in Bug Bounty Rewards This Year
More than 560 security researchers from 64 countries were paid to find and report software flaws. Not everyone is happy about how the company handled the work.

AI Scanner Finds Eight Serious Bugs in NodeBB Forum Software
Aikido Security's automated code review turned up admin takeover and private-message flaws in six hours. All eight are patched in version 4.14.2.

Oracle Patches 1,434 Flaws in One Go. AI Probably Found Most of Them.
Oracle's July 2026 quarterly security update is the largest in the company's history, covering hundreds of products used by hospitals, banks, retailers, and governments worldwide.

Apple Patches Year-Old Hide My Email Bug That Leaked Real Addresses
A flaw in Apple's email-cloaking feature let real addresses appear in mail logs. The fix took over a year to ship.

Meta Paid a Researcher $78,000 to Find a Flaw That Exposed Support Chats and Personal Data
An independent security researcher discovered a hole in Meta's internal support system that could have let anyone read private conversations between users and Meta support staff. Meta patched it quietly. Then came the cheque.

Ivanti Used AI to Find a Perfect-Score Security Flaw in Its Own Software. Here Is What That Means.
The company quietly ran an AI project starting in March and says the results are already surprising even its own security chief.

The Machines That Run the World Are Running Decades-Old Software
Industrial control systems keep factories, water plants, and power grids alive. They also run code written before Wi-Fi existed. Fixing that is harder than it sounds.

Splunk and Zoom Fix Security Flaws That Could Let Hackers Take Over Accounts
Both companies pushed out patches this week. One Zoom flaw scores a near-perfect danger rating and could let a criminal break into accounts without knowing a password.

Five Government Agencies Tell Software Makers: Open a Front Door for Bug Reporters
CISA and four allied agencies have published a joint guide urging tech companies to set up formal programmes so security researchers can safely report flaws before criminals find them first.