#vulnerability disclosure
45 stories taggedvulnerability disclosure · page 3 of 3.

Nine Security Flaws Found in ATM Encryption Software, and Nobody Agrees How Bad It Is
A researcher found serious bugs in software that locks ATM hard drives. The world's biggest ATM maker says they don't matter. The researcher disagrees. The truth is somewhere uncomfortable.

The Summer Everyone Launched a Clearinghouse
Vendor announcements have piled up fast. But not every 'clearinghouse' is a fresh idea, and the differences matter more than the marketing suggests.

AI Coding Assistants Fooled by Decades-Old File Trick to Attack Developer Machines
A technique as old as Unix itself let researchers plant hidden traps inside innocent-looking code projects, then watch AI tools quietly rewrite the wrong files while developers clicked 'approve'.

Microsoft patches 'RoguePlanet' Defender flaw after researcher publishes exploit in disclosure spat
The zero-day let attackers hand themselves the keys to a fully patched Windows machine. It was revealed by a researcher publicly feuding with Microsoft.

A New Citrix NetScaler Flaw Is Already Being Exploited, And It Looks Familiar
A security hole in widely used Citrix network equipment is leaking corporate secrets from memory. Attackers moved within 24 hours of the patch dropping.

Adobe Is Doubling Its Patch Releases — Here's Why That Matters
Starting in July, Adobe will push security fixes twice a month instead of once. Faster vulnerability discovery, AI-assisted research, and a threat pace that monthly updates can no longer keep up with are all driving the change.

Dify AI Platform Carried Multi-Tenant Flaws Exposing Private Chats and Internal APIs
Cross-tenant data leakage vulnerabilities in Dify's cloud service let attackers read other users' conversations, preview documents, and probe internal API endpoints.

Samsung KNOX Use-After-Free Bug Sat in Galaxy Devices for Eight Years Before Patch
A high-severity kernel-level flaw in Samsung's KNOX security framework affected Galaxy handsets from the S9 through the S25, a product window spanning nearly a decade.

DifyTap: Four Unauthenticated Bugs in Dify Expose Cross-Tenant AI Conversations
Researchers at Zafran say a chain of flaws in the popular agentic workflow platform let attackers read other tenants' chats without logging in.

Microsoft Acknowledges 'RoguePlanet' Defender Zero-Day, Patch Still in the Works
CVE-2026-50656 is a privilege escalation bug in the Malware Protection Engine, the component sitting at the heart of every Defender install.

One-Click VS Code Flaw Exposed GitHub OAuth Tokens to Theft
A researcher-disclosed bug in Microsoft's browser-based VS Code variant let a single crafted link siphon tokens with read/write access to private repos.

FFmpeg Gets 21 New Bugs from an AI Fuzzer; Chrome 149 Ships a Record 429 Fixes
An autonomous agent dug up zero-days in the codec library that ships in everything. Google's browser shipped its largest single security release on record. Same week.

HTTP/2 Bomb: A Decade-Old Compression Trick Finally Gets a CVE
A chained HPACK attack lets small packets force runaway memory allocation on nginx, Apache, IIS, Envoy and Cloudflare's Pingora. Patches are partial. Exposure is wide.

Ten Thousand Bugs, One Model: Inside Anthropic's Project Glasswing
Claude Mythos Preview has scanned more than 1,000 open-source projects and surfaced thousands of critical flaws. The bottleneck has moved, and the patch queue is not moving fast enough.

Anthropic Says Project Glasswing AI Has Flagged 10,000 High-Severity Bugs in a Month
The Claude-based scanner has been pointed at widely deployed open-source code since October. Anthropic has not named the affected projects.