Tag

#vulnerability

95 stories taggedvulnerability · page 3 of 7.

An AI assistant interface on a computer screen being corrupted by malicious webpage code injected through a browser window overlay, showing instruction prompt m
AI Security

A Single Website Visit Can Poison Your Local AI Agent, Researchers Find

A flaw in Nvidia's NemoClaw lets a malicious webpage secretly rewrite the instructions an AI assistant follows, and the damage survives every conversation that comes after.

4 min read
A developer's workspace with a Jupyter-style notebook application open on the monitor, showing code cells and a warning notification banner indicating a securit
Vulnerabilities

Marimo Patches Notebook Flaw That Let Hidden Commands Run on Open

A high-severity bug in the Marimo notebook app could quietly run attacker-supplied commands the moment a user opened a booby-trapped file in edit mode.

3 min read
A corporate server room with Oracle WebLogic servers and associated hardware, with critical alert notifications flashing on monitoring dashboards, showing activ
Vulnerabilities

CISA Flags Critical Oracle WebLogic Flaw as Attackers Hit Unpatched Servers

The bug, rated a perfect 10 on the severity scale, lets attackers reach sensitive data without needing a password.

3 min read
A web browser window with a password manager extension visible in the toolbar, its icon displaying a warning indicator while credential fields are shown being a
Vulnerabilities

A Flaw in N-able's Passportal Handed Any Malicious Website the Keys to Every Password a Business Stored

A researcher found that Passportal's browser extension trusted every message it received without question, letting any webpage silently drain a company's entire vault of login credentials.

4 min read
A NASA control center environment with spacecraft telemetry displays on large screens and communication interfaces, with security vulnerability indicators visib
Vulnerabilities

NASA Spacecraft Control Software Has a Critical Flaw Attackers Could Use Remotely

Researchers at Cycode found a chain of bugs in AIT-GUI, a NASA/JPL tool used to talk to spacecraft, that lets outsiders send commands with no login required.

3 min read
A corporate email server room with warning tape cordoning off affected equipment, technicians reviewing security patches on terminal screens, calendar dates sho
Vulnerabilities

Poland's CERT warns of active attacks on critical Zimbra email flaw

CERT Polska says attackers are exploiting CVE-2026-73570 in Zimbra Collaboration Suite. Zimbra patched the bug in version 10.1.20 on 20 July 2025.

3 min read
A server room filled with blinking network equipment and cooling systems, with red warning lights illuminating the hardware, suggesting active threat detection
Vulnerabilities

CISA Adds Actively Exploited Ray AI Framework Flaw to Must-Patch List

The bug in Ray, a popular open-source tool for running AI workloads, is being abused in the wild. CISA gave federal agencies a deadline to fix it.

3 min read
A GitLab repository interface on a computer screen with project files being deleted in real-time, showing the cascading removal of code and data without authent
Vulnerabilities

Critical GitLab Flaw Lets Attackers Wipe Public Projects Without Logging In

GitLab has patched a flaw rated 9.4 out of 10 that let unauthenticated attackers alter or delete public projects and user data through the platform's GraphQL interface.

3 min read
Mac computer setup in an office with screen sharing remotely active, malware process running in the background detected by system logs, cryptocurrency mining st
Vulnerabilities

Dutch cyber agency warns of live attacks on macOS Screen Sharing flaw

Hackers are breaking into Mac computers exposed to the internet, seizing top-level control, and quietly mining Monero cryptocurrency.

4 min read
An industrial design workstation with 3D modelling software displaying a malformed CAD file causing a crash, error messages and system logs visible, security pa
Vulnerabilities

Siemens Patches High-Severity Flaw in Parasolid 3D Modelling Engine

A memory-handling bug in Siemens Parasolid, tracked as CVE-2026-64629, lets a booby-trapped design file crash the host application or run attacker code. Siemens has shipped fixed builds.

3 min read
A corporate IT dashboard on multiple monitors showing enterprise device management software interface with highlighted security warning indicators and system co
Vulnerabilities

$58 Certificate, Four Flaws: Researchers Show How SCCM Can Hand Attackers the Keys to an Entire Company

A security research team chained four weaknesses in Microsoft's enterprise device-management software to reach full system control, starting with nothing more than a standard company login.

5 min read
A server room with equipment racks, multiple screens displaying vulnerability scans and patch status dashboards, calendar or timeline showing urgent deadlines a
Vulnerabilities

Hackers Exploit Patched VMware vCenter Flaw as Regulators Watch Disclosure Clocks

A directory-traversal bug rated 9.8 out of 10 is under active attack, and SEC and EU disclosure duties now sit squarely on affected firms.

4 min read
A computer mouse pointer hovering over a link in an email interface, with office collaboration tool icons visible on the background desktop
AI Security

A Single Click Could Have Handed Hackers Your Company's Confluence and Jira Files

Researchers found a flaw in Atlassian's Rovo AI assistant that let an attacker steal data from widely used workplace tools with almost no effort from the victim.

2 min read
A WordPress login page on a server with malicious code injecting itself into the authentication flow, represented by digital tendrils wrapping around the interf
Vulnerabilities

WordPress Login Flaw Lets Attackers Slip Code Into Every Site Running It

A newly disclosed bug on the WordPress sign-in page affects every version of the software and, in the wrong conditions, can hand attackers full control of the server.

3 min read
A browser window showing the Chrome update notification center with multiple critical security patches listed, and system processes running in the background to
Vulnerabilities

Google Patches 41 Security Flaws in Chrome 151, Six Rated Critical

The latest Chrome update fixes a cluster of memory-safety bugs that could let attackers crash your browser or run malicious code on your device. Here is what happened and what you should do.

3 min read
© 2026 Threat Vectr