#vulnerability disclosure
45 stories taggedvulnerability disclosure · page 2 of 3.

Cisco Patches a Dozen Flaws in SD-WAN and IOS XE, Three Rated Critical
An internal Cisco security review turned up 12 vulnerabilities, including three with a severity score of 9.8 out of 10, in software that runs corporate networks worldwide.

Researchers Find AI Agents at AWS, Google and Vercel Can Be Tricked Into Running Tools Without the AI
Flaws in agent plumbing let forged instructions reach powerful tools before any safety check runs, and in some cases the AI model never runs at all.

Microsoft Paid Out $20 Million in Bug Bounty Rewards This Year
More than 560 security researchers from 64 countries were paid to find and report software flaws. Not everyone is happy about how the company handled the work.

AI Scanner Finds Eight Serious Bugs in NodeBB Forum Software
Aikido Security's automated code review turned up admin takeover and private-message flaws in six hours. All eight are patched in version 4.14.2.

Oracle Patches 1,434 Flaws in One Go. AI Probably Found Most of Them.
Oracle's July 2026 quarterly security update is the largest in the company's history, covering hundreds of products used by hospitals, banks, retailers, and governments worldwide.

Apple Patches Year-Old Hide My Email Bug That Leaked Real Addresses
A flaw in Apple's email-cloaking feature let real addresses appear in mail logs. The fix took over a year to ship.

Meta Paid a Researcher $78,000 to Find a Flaw That Exposed Support Chats and Personal Data
An independent security researcher discovered a hole in Meta's internal support system that could have let anyone read private conversations between users and Meta support staff. Meta patched it. Then came the cheque.

Ivanti Used AI to Find a Perfect-Score Security Flaw in Its Own Software. Here Is What That Means.
The company quietly ran an AI project starting in March and says the results are already surprising even its own security chief.

The Machines That Run the World Are Running Decades-Old Software
Industrial control systems keep factories, water plants, and power grids alive. They also run code written before Wi-Fi existed. Fixing that is harder than it sounds.

Splunk and Zoom Fix Security Flaws That Could Let Hackers Take Over Accounts
Both companies pushed out patches this week. One Zoom flaw scores a near-perfect danger rating and could let a criminal break into accounts without knowing a password.

Five Government Agencies Tell Software Makers: Open a Front Door for Bug Reporters
CISA and four allied agencies have published a joint guide urging tech companies to set up formal programmes so security researchers can safely report flaws before criminals find them first.

CISA and NSA Publish Playbook for Working With Outside Bug Hunters
New joint guidance urges software makers and online services to set up formal channels for security researchers, with clear rules, CVE assignments, and the option to lean on national response teams.

Two Clicks to Own a Developer's Machine: The Cursor AI Flaw You Should Know About
Researchers found they could smuggle a malicious installation command into the most popular AI code editor by hiding it inside what looked like a routine code-review link.

Researcher Publishes Windows Privilege-Escalation Exploit Hours After Microsoft's Monthly Patch
A proof-of-concept called LegacyHive targets the Windows User Profile Service, raising fresh questions about coordinated disclosure timing.

Fortinet, Ivanti, and ServiceNow patch 15 flaws, including a critical no-login attack on ServiceNow's AI platform
A flaw rated 9.5 out of 10 in severity lets criminals run malicious code on ServiceNow systems without needing a password. Twelve Fortinet products and two Ivanti tools also received fixes on the same day.