#vulnerability
95 stories taggedvulnerability · page 4 of 7.

Researchers Cracked Samsung Phones Wide Open by Turning Bixby Against Its Own Device
A five-step exploit chain using Bixby, Samsung Members, and Samsung Account could hand a stranger complete control of your Galaxy phone. Patches are out, but older devices may still be exposed.

Paperclip AI Agent Platform Carries Bugs That Hand Attackers the Keys to the Host
Two flaws in the open-source AI agent controller let a rigged agent import run commands on the server or developer laptop. A third leaks control-plane data through unprotected API routes.

Thermo Fisher patches DNA analysis flaw that could let evidence files be quietly altered
A vulnerability in Applied Biosystems human identification software could allow near-invisible edits to forensic DNA files before analysts ever see them.

Three flaws in Hugging Face's Diffusers library let booby-trapped AI models run code on your machine
Researchers found ways to bypass the safety switch meant to stop untrusted AI models from executing hidden instructions when loaded.

N-able confirms hackers seized N-central servers through a login-bypass flaw
The remote-management platform's first patch didn't hold. A second fix, in build 2026.3.1.7, closes CVE-2026-18577.

Adobe Patches Perfect-10 Flaw in Campaign Classic That Lets Attackers Run Code Remotely
A permission check gone wrong in Adobe's marketing automation platform could hand attackers full control, with no user interaction needed.

Schneider Electric patches a nasty file-parsing bug in its industrial control software
A booby-trapped design file could let attackers run code inside IGSS, the SCADA tool used to monitor factories, energy sites and manufacturing plants worldwide.

A Rails Bug Lets Strangers Read Your Server's Secrets Through a Photo Upload
CVE-2026-66066 in Active Storage scores 9.5 out of 10 for severity, and no login is required to exploit it.

JetBrains Patches Critical TeamCity Flaw That Let Attackers Run Commands Without Logging In
CVE-2026-63077 carries a 9.8 severity score and affects every on-premises version of the build server. Cloud customers were patched automatically.

n8n Patches Sandbox Escape That Let Editors Run Commands on the Server
A flaw in the popular automation platform let anyone with workflow-editing access break out of the safe zone and run system commands. n8n has issued a fix.

OpenAI Patches ChatGPT Flaw That Let Attackers Plant an Invisible AI Agent Inside a Company
A vulnerability called AgentForger meant a criminal could quietly forge a rogue AI assistant inside a victim organisation, give it instructions, and control it from outside.

Check Point Rushes Fix for SmartConsole Flaw Already Being Exploited
A critical authentication bypass in Check Point's management console let attackers walk past the login screen. The vendor confirms real-world attacks are already happening.

Critical Ubuntu Flaw Allows Local Users Full Control
Security researchers reveal a serious vulnerability in Ubuntu's snap-confine that could let local users gain root access on default desktop installs.

A Browser Extension Installed 300 Million Times Had a Flaw That Let Attackers Steal Your WhatsApp Messages
A security hole in Adobe's widely used browser extension meant that simply visiting the wrong website could hand criminals your private messages and contacts.

Windmill Path Traversal Flaw Under Active Attack, VulnCheck Warns
CVE-2026-29059 lets unauthenticated attackers read files from servers running the open-source developer platform. Patch guidance and exploitation details below.