#vulnerability
95 stories taggedvulnerability · page 3 of 7.

A Single Website Visit Can Poison Your Local AI Agent, Researchers Find
A flaw in Nvidia's NemoClaw lets a malicious webpage secretly rewrite the instructions an AI assistant follows, and the damage survives every conversation that comes after.

Marimo Patches Notebook Flaw That Let Hidden Commands Run on Open
A high-severity bug in the Marimo notebook app could quietly run attacker-supplied commands the moment a user opened a booby-trapped file in edit mode.

CISA Flags Critical Oracle WebLogic Flaw as Attackers Hit Unpatched Servers
The bug, rated a perfect 10 on the severity scale, lets attackers reach sensitive data without needing a password.

A Flaw in N-able's Passportal Handed Any Malicious Website the Keys to Every Password a Business Stored
A researcher found that Passportal's browser extension trusted every message it received without question, letting any webpage silently drain a company's entire vault of login credentials.

NASA Spacecraft Control Software Has a Critical Flaw Attackers Could Use Remotely
Researchers at Cycode found a chain of bugs in AIT-GUI, a NASA/JPL tool used to talk to spacecraft, that lets outsiders send commands with no login required.

Poland's CERT warns of active attacks on critical Zimbra email flaw
CERT Polska says attackers are exploiting CVE-2026-73570 in Zimbra Collaboration Suite. Zimbra patched the bug in version 10.1.20 on 20 July 2025.

CISA Adds Actively Exploited Ray AI Framework Flaw to Must-Patch List
The bug in Ray, a popular open-source tool for running AI workloads, is being abused in the wild. CISA gave federal agencies a deadline to fix it.

Critical GitLab Flaw Lets Attackers Wipe Public Projects Without Logging In
GitLab has patched a flaw rated 9.4 out of 10 that let unauthenticated attackers alter or delete public projects and user data through the platform's GraphQL interface.

Dutch cyber agency warns of live attacks on macOS Screen Sharing flaw
Hackers are breaking into Mac computers exposed to the internet, seizing top-level control, and quietly mining Monero cryptocurrency.

Siemens Patches High-Severity Flaw in Parasolid 3D Modelling Engine
A memory-handling bug in Siemens Parasolid, tracked as CVE-2026-64629, lets a booby-trapped design file crash the host application or run attacker code. Siemens has shipped fixed builds.

$58 Certificate, Four Flaws: Researchers Show How SCCM Can Hand Attackers the Keys to an Entire Company
A security research team chained four weaknesses in Microsoft's enterprise device-management software to reach full system control, starting with nothing more than a standard company login.

Hackers Exploit Patched VMware vCenter Flaw as Regulators Watch Disclosure Clocks
A directory-traversal bug rated 9.8 out of 10 is under active attack, and SEC and EU disclosure duties now sit squarely on affected firms.

A Single Click Could Have Handed Hackers Your Company's Confluence and Jira Files
Researchers found a flaw in Atlassian's Rovo AI assistant that let an attacker steal data from widely used workplace tools with almost no effort from the victim.

WordPress Login Flaw Lets Attackers Slip Code Into Every Site Running It
A newly disclosed bug on the WordPress sign-in page affects every version of the software and, in the wrong conditions, can hand attackers full control of the server.

Google Patches 41 Security Flaws in Chrome 151, Six Rated Critical
The latest Chrome update fixes a cluster of memory-safety bugs that could let attackers crash your browser or run malicious code on your device. Here is what happened and what you should do.