Tag

#vulnerability disclosure

50 stories taggedvulnerability disclosure · page 2 of 4.

Full-frame edge-to-edge photoreal editorial shot of a clean modern government-style office desk at night, an open laptop showing an abstract dashboard of colour
Policy & Regulation

CISA and NSA Publish Playbook for Working With Outside Bug Hunters

New joint guidance urges software makers and online services to set up formal channels for security researchers, with clear rules, CVE assignments, and the option to lean on national response teams.

3 min read
Full-frame photoreal editorial shot of a modern developer workstation at dusk, two large monitors glowing with abstract code editor windows, a small permission
AI Security

Two Clicks to Own a Developer's Machine: The Cursor AI Flaw You Should Know About

Researchers found they could smuggle a malicious installation command into the most popular AI code editor by hiding it inside what looked like a routine code-review link.

3 min read
Photoreal news-editorial shot of a darkened server room with a single Windows laptop open on a rack shelf, screen glowing pale blue with abstract registry-tree
Vulnerabilities

Researcher Publishes Windows Privilege-Escalation Exploit Hours After Microsoft's Monthly Patch

A proof-of-concept called LegacyHive targets the Windows User Profile Service, raising fresh questions about coordinated disclosure timing.

3 min read
Full-frame 16:9 photoreal editorial image of a dimly lit server rack in a data center, focused on a single rack unit with a glowing amber status LED, shallow de
Vulnerabilities

Fortinet, Ivanti, and ServiceNow patch 15 flaws, including a critical no-login attack on ServiceNow's AI platform

A flaw rated 9.5 out of 10 in severity lets criminals run malicious code on ServiceNow systems without needing a password. Twelve Fortinet products and two Ivanti tools also received fixes on the same day.

3 min read
Photoreal news-editorial 16:9 photograph of a modern bank ATM machine viewed from a low angle in a quiet urban street at dusk, the top panel of the machine slig
Vulnerabilities

Nine Security Flaws Found in ATM Encryption Software, and Nobody Agrees How Bad It Is

A researcher found serious bugs in software that locks ATM hard drives. The world's biggest ATM maker says they don't matter. The researcher disagrees. The truth is somewhere uncomfortable.

4 min read
Full-frame edge-to-edge photoreal editorial shot of an empty modern office reception desk with a single unmarked intake tray and a locked glass door behind it,
Opinion

The Summer Everyone Launched a Clearinghouse

Vendor announcements have piled up fast. But not every 'clearinghouse' is a fresh idea, and the differences matter more than the marketing suggests.

4 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
AI Security

AI Coding Assistants Fooled by Decades-Old File Trick to Attack Developer Machines

A technique as old as Unix itself let researchers plant hidden traps inside innocent-looking code projects, then watch AI tools quietly rewrite the wrong files while developers clicked 'approve'.

3 min read
Full-frame close-up of a modern laptop screen glowing blue in a dim office, showing an abstract Windows security shield icon partly fractured, dust motes catchi
Vulnerabilities

Microsoft patches 'RoguePlanet' Defender flaw after researcher publishes exploit in disclosure spat

The zero-day let attackers hand themselves the keys to a fully patched Windows machine. It was revealed by a researcher publicly feuding with Microsoft.

4 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Vulnerabilities

A New Citrix NetScaler Flaw Is Already Being Exploited, And It Looks Familiar

A security hole in widely used Citrix network equipment is leaking corporate secrets from memory. Attackers moved within 24 hours of the patch dropping.

3 min read
Photoreal, news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Vulnerabilities

Adobe Is Doubling Its Patch Releases — Here's Why That Matters

Starting in July, Adobe will push security fixes twice a month instead of once. Blame faster vulnerability discovery, AI-assisted research, and a threat pace that monthly updates can no longer keep up with.

3 min read
Vulnerabilities

Active Exploitation Reported Against Progress Kemp LoadMaster Pre-Auth RCE (CVE-2026-8037)

Threat responders flag in-the-wild attempts against a 9.6-rated OS command injection flaw in the load balancer, days after Progress issued a fixed build.

2 min read
AI Security

Dify AI Platform Carried Multi-Tenant Flaws Exposing Private Chats and Internal APIs

Cross-tenant data leakage vulnerabilities in Dify's cloud service let attackers read other users' conversations, preview documents, and probe internal API endpoints.

2 min read
Vulnerabilities

Samsung KNOX Use-After-Free Bug Sat in Galaxy Devices for Eight Years Before Patch

A high-severity kernel-level flaw in Samsung's KNOX security framework affected Galaxy handsets from the S9 through the S25 — a product window spanning nearly a decade.

2 min read
AI Security

DifyTap: Four Unauthenticated Bugs in Dify Expose Cross-Tenant AI Conversations

Researchers at Zafran say a chain of flaws in the popular agentic workflow platform let attackers read other tenants' chats without logging in.

3 min read
Vulnerabilities

Microsoft Acknowledges 'RoguePlanet' Defender Zero-Day, Patch Still in the Works

CVE-2026-50656 is a privilege escalation bug in the Malware Protection Engine — the component sitting at the heart of every Defender install.

2 min read
© 2026 Threat Vectr