Tag

#vulnerability disclosure

45 stories taggedvulnerability disclosure · page 2 of 3.

A network operations center displaying SD-WAN infrastructure diagrams with twelve vulnerability indicators highlighted across the topology, three of them marked
Vulnerabilities

Cisco Patches a Dozen Flaws in SD-WAN and IOS XE, Three Rated Critical

An internal Cisco security review turned up 12 vulnerabilities, including three with a severity score of 9.8 out of 10, in software that runs corporate networks worldwide.

3 min read
Cloud service provider architecture displayed on a monitor with AI agent systems connected to external tools, showing forged instruction packets bypassing safet
AI Security

Researchers Find AI Agents at AWS, Google and Vercel Can Be Tricked Into Running Tools Without the AI

Flaws in agent plumbing let forged instructions reach powerful tools before any safety check runs, and in some cases the AI model never runs at all.

4 min read
Illustration: A security researcher at a laptop surrounded by screens displaying code and vulnerability reports
Vulnerabilities

Microsoft Paid Out $20 Million in Bug Bounty Rewards This Year

More than 560 security researchers from 64 countries were paid to find and report software flaws. Not everyone is happy about how the company handled the work.

3 min read
An automated code review dashboard showing NodeBB forum software source code with eight security vulnerabilities flagged in red, timestamps showing discovery wi
Vulnerabilities

AI Scanner Finds Eight Serious Bugs in NodeBB Forum Software

Aikido Security's automated code review turned up admin takeover and private-message flaws in six hours. All eight are patched in version 4.14.2.

3 min read
A server room with multiple racks of enterprise computing systems and patch management dashboards illuminated on screens, showing the scale of a massive securit
Vulnerabilities

Oracle Patches 1,434 Flaws in One Go. AI Probably Found Most of Them.

Oracle's July 2026 quarterly security update is the largest in the company's history, covering hundreds of products used by hospitals, banks, retailers, and governments worldwide.

3 min read
Illustration: a modern smartphone screen showing a generic mail app inbox with a blurred alias-
Vulnerabilities

Apple Patches Year-Old Hide My Email Bug That Leaked Real Addresses

A flaw in Apple's email-cloaking feature let real addresses appear in mail logs. The fix took over a year to ship.

3 min read
A security researcher's workspace showing the moment of discovery: a laptop screen displaying Meta's internal support system with exposed user chat records and
Vulnerabilities

Meta Paid a Researcher $78,000 to Find a Flaw That Exposed Support Chats and Personal Data

An independent security researcher discovered a hole in Meta's internal support system that could have let anyone read private conversations between users and Meta support staff. Meta patched it. Then came the cheque.

3 min read
An Ivanti security research facility with engineers reviewing AI-discovered vulnerability findings on multiple displays, showing the moment a perfect-score crit
AI Security

Ivanti Used AI to Find a Perfect-Score Security Flaw in Its Own Software. Here Is What That Means.

The company quietly ran an AI project starting in March and says the results are already surprising even its own security chief.

3 min read
A factory floor with industrial control panels displaying dated interfaces and green monochrome screens, connected via tangled cables to modern equipment, showi
Vulnerabilities

The Machines That Run the World Are Running Decades-Old Software

Industrial control systems keep factories, water plants, and power grids alive. They also run code written before Wi-Fi existed. Fixing that is harder than it sounds.

3 min read
A computer monitor split into two sections, one showing Splunk's interface with vulnerability indicators, the other showing Zoom's login screen, both with patch
Vulnerabilities

Splunk and Zoom Fix Security Flaws That Could Let Hackers Take Over Accounts

Both companies pushed out patches this week. One Zoom flaw scores a near-perfect danger rating and could let a criminal break into accounts without knowing a password.

3 min read
An official government building with cybersecurity researchers and technology professionals entering through the front doors for a formal briefing, representing
Policy & Regulation

Five Government Agencies Tell Software Makers: Open a Front Door for Bug Reporters

CISA and four allied agencies have published a joint guide urging tech companies to set up formal programmes so security researchers can safely report flaws before criminals find them first.

3 min read
Illustration: a clean modern government-
Policy & Regulation

CISA and NSA Publish Playbook for Working With Outside Bug Hunters

New joint guidance urges software makers and online services to set up formal channels for security researchers, with clear rules, CVE assignments, and the option to lean on national response teams.

3 min read
Illustration: a modern developer workstation at dusk, two large monitors glowing with abstract code editor windows
AI Security

Two Clicks to Own a Developer's Machine: The Cursor AI Flaw You Should Know About

Researchers found they could smuggle a malicious installation command into the most popular AI code editor by hiding it inside what looked like a routine code-review link.

4 min read
Illustration: a darkened server room with a single Windows laptop open on a rack shelf
Vulnerabilities

Researcher Publishes Windows Privilege-Escalation Exploit Hours After Microsoft's Monthly Patch

A proof-of-concept called LegacyHive targets the Windows User Profile Service, raising fresh questions about coordinated disclosure timing.

3 min read
Illustration: a dimly lit server rack in a data center, focused on a single rack unit with a glowing amber status LED
Vulnerabilities

Fortinet, Ivanti, and ServiceNow patch 15 flaws, including a critical no-login attack on ServiceNow's AI platform

A flaw rated 9.5 out of 10 in severity lets criminals run malicious code on ServiceNow systems without needing a password. Twelve Fortinet products and two Ivanti tools also received fixes on the same day.

2 min read
© 2026 Threat Vectr