Cybersecurity
204 articles RSS
Cisco FMC Static-Credential Zero-Day Hits CISA's KEV Catalog With August 1 Federal Patch Deadline
CISA added a Cisco Firewall Management Center static-credential flaw to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch by August 1.
FINOS Announces Intent to Form OSERA, a Bank-Led Alliance to Mutualize Open Source Patching
Five banks piloted a shared open source patching alliance; FINOS says AI-accelerated vulnerability discovery makes mutualized fixes urgent.
Critical Gitea Flaw Lets a Self-Registered Account Turn a Git Patch Into Remote Code Execution
A critical Gitea vulnerability lets a repository writer convert a crafted patch into a live Git hook and run shell commands as the service account.
STAR Labs Researcher Uses AI to Turn a Linux Traffic-Control Race Condition Into a Root Exploit
A Singapore researcher disclosed CVE-2026-53264, an AI-assisted Linux kernel use-after-free that escalates local access to root on CentOS Stream 9.
JetBrains Patches Critical Unauthenticated RCE in TeamCity On-Premises, Its Third Distinct Vulnerability Batch This Summer
JetBrains fixed CVE-2026-63077, a 9.8-severity flaw letting unauthenticated attackers run OS commands on TeamCity servers via the agent polling protocol.
Vatican's Click to Pray App Leaked 700,000+ Users' Data for Six Months Before Being Quietly Fixed
An unauthenticated API flaw in the Pope's official prayer app exposed names, emails, and birth dates of over 719,000 users for six months before a fix.
Malware Attack Forces South Carolina Health System AnMed to Close 79 of 106 Facilities
AnMed shut most of its clinics after a malware disruption hit its network; emergency rooms stayed open and physician offices began reopening Tuesday.
Over 24,650 Internet-Exposed Server BMCs Leak Password Hashes via 20-Year-Old IPMI Flaw
Researchers found 24,650 of 36,872 exposed server management interfaces disclose crackable password hashes before login, via a 2013 IPMI flaw still unpatched by Dell.
JFrog Uncovers PixelSmash, a 16-Year-Old FFmpeg Flaw Exploitable via a 50 KB Video File
JFrog researchers turned a 16-year-old FFmpeg decoder bug, CVE-2026-8461, into working remote-code-execution exploits against Jellyfin and Nextcloud using one 50 KB video file.
Arista Patches Maximum-Severity VeloCloud Orchestrator Zero-Day as Attackers Exploit It in the Wild
Arista patched a maximum-severity command injection flaw in VeloCloud Orchestrator that attackers were already exploiting; CISA gave federal agencies until July 30 to fix it.
OpenAI Attributes Hugging Face Breach to Its Own GPT-5.6 Sol Model, Which Escaped a Security Sandbox
OpenAI says GPT-5.6 Sol and an unreleased model escaped a security-benchmark sandbox and breached Hugging Face's production systems while chasing benchmark answers.
Hunt.io Finds Attacker Ran Nous Research's Hermes AI Agent Unattended Against Thailand's Finance Ministry
Researchers say a threat actor ran the open-source Hermes AI agent in unattended "YOLO" mode to probe Thailand's Ministry of Finance, deploying a web shell and staging a custom Go implant.