Browsing Category
Vulnerability
35 posts
Zoom and Gloom as Researchers Uncover RCE Flaw in Conferencing App
Zoom fixed three critical vulnerabilities in its meeting-annotation feature that could allow remote code execution on participant devices, discovered by researchers utilizing AI.
EU Cyber Agency Adds NATO, AI Firm to CVE Program
ENISA expands CVE program footprint, adds NATO and AI security firm as new CNAs.
SonicWall VPN Flaw Chain Gives INC Ransomware Root Access
INC Ransomware threat actors exploited a critical pre-auth bypass flaw and pairing it with a privilege-escalation bug to gain root on SonicWall SMA 1000 appliances.
Firefox Patches Two Critical Bugs as Exploit Code Goes Public
Mozilla says it has not detected attacks exploiting the WebAssembly and site-isolation vulnerabilities fixed in Firefox 152.0.6
Dirty Deeds Done Dirt Cheap: Australia Warns of Mass CMS Attacks
Australia warns website operators of a mass exploitation campaign targeting known vulnerabilities in content management systems, urging timely updates to prevent webshell deployments.
Dell Patches Critical Flaw in Exascale Storage Hardware: PowerFlex
Dell disclosed three PowerFlex Manager vulnerabilities this week, led by a 9.1-severity flaw that lets a privileged remote attacker run commands as root with no user interaction required.
Januscape KVM Bug Is Actually Two Flaws: One Patch Won’t Cover You
A newly discovered flaw in the Linux kernel's virtualization code, named "Januscape," threatens virtual machine isolation. It combines two vulnerabilities requiring simultaneous patches to prevent potential exploitation that could grant attackers full host control.
NVIDIA Patches Critical Auth Bypass in AIStore Framework
NVIDIA has addressed a critical authentication-bypass vulnerability in its AIStore framework, which could enable data tampering and system disruptions, urging immediate updates.
WinRAR Patches Critical Flaw Enabling Remote Code Execution
CVE-2026-14191 hits RAR5 recovery-volume handling; no auto-update means the fix is on users to install.
Adobe Patches 11 ColdFusion, Campaign Classic Flaws: Four Hit Max Severity
Adobe has patched 11 vulnerabilities in ColdFusion and Campaign Classic, including six critical flaws in ColdFusion that allow remote code execution. No active exploitation is reported. Users should update affected versions promptly.