VulnerabilityCybersecurity Dive·5 days ago

GitLab issues emergency patch for critical code-injection flaw

GitLab has released an emergency patch addressing a critical code-injection vulnerability that allows unauthenticated attackers to delete or modify publicly accessible projects. The flaw poses a significant risk to organizations using GitLab, as it can be exploited without requiring valid credentials to compromise project integrity and availability.

VulnerabilityRapid7 Blog·5 days ago

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

Rapid7's Q2 2026 Quarterly Threat Landscape Report reveals that vulnerability disclosure volume has doubled year-over-year to 8,539 high- and critical-severity CVEs, while attackers increasingly leverage AI-assisted automation to exploit vulnerabilities faster than traditional patch cycles can address them. The report identifies that 62% of exploited vulnerabilities require no user interaction, with missing-authentication flaws surging 247% year-over-year, and highlights persistent nation-state activity from Iranian, North Korean, and Russian clusters alongside continued ransomware campaigns led by Qilin. Organizations can no longer rely on patching volume alone; success requires understanding which exposures are actually reachable and prioritizing risk reduction based on exploitability rather than severity scores.

VulnerabilityCISA Advisories·5 days ago

CISA Malcolm

CISA Malcolm, a network traffic analysis tool suite, contains multiple vulnerabilities across versions prior to 26.08.0 that could allow authenticated attackers to execute arbitrary code, bypass access controls, or cause denial-of-service conditions. The flaws span archive extraction without resource limits, path traversal in file handling, unsafe file uploads with inadequate type validation, RBAC bypasses via path normalization issues, and insufficient protections against compressed data bombs. Users should upgrade to the patched versions (26.06.1, 26.07.0, or 26.08.0 depending on the vulnerability) to mitigate exploitation risks.

VulnerabilityCISA Advisories·5 days ago

Siemens Simcenter Nastran

A stack overflow vulnerability in Siemens Simcenter Nastran and Simcenter Femap versions prior to V2606 could allow remote code execution when a user is tricked into running an affected application binary with a malicious string argument. The vulnerability carries a CVSS score of 7.8 and affects critical infrastructure sectors including manufacturing, defense, energy, healthcare, and transportation systems worldwide. Siemens has released patched versions and recommends users update immediately.

VulnerabilityCISA Advisories·5 days ago

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation: a Microsoft IKE service double free vulnerability, a Microsoft SharePoint weak authentication flaw, a Broadcom VMware vCenter path traversal issue, and an Apple macOS improper authentication vulnerability. Under Binding Operational Directive 26-04, federal agencies must prioritize rapid remediation of these KEV-listed vulnerabilities on publicly exposed assets, while CISA encourages all organizations to adopt risk-based vulnerability management practices and address high-risk exploited vulnerabilities as a priority.

VulnerabilityCybersecurity Dive·5 days ago

AI-powered vulnerability clearinghouse faces deep skepticism, major challenges

The U.S. government's Gold Eagle coordination program aims to help organizations prioritize patching and mitigation efforts, though cybersecurity experts express significant skepticism about the initiative's ambitions and promised capabilities. Despite concerns that the government's claims may be overstated, the program could still provide practical value in vulnerability management if executed effectively.

VulnerabilityThe Hacker News·5 days ago

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

CISA has added a critical Ray vulnerability to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The flaw in this open-source Python-based distributed computing framework can enable remote code execution through browsers, posing a significant risk to organizations using Ray for AI and machine learning workloads.

VulnerabilityCISA KEV·5 days ago

CVE-2026-59310: Broadcom VMware vCenter Path Traversal Vulnerability

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.8 (Critical). Affects Broadcom VMware vCenter.

VulnerabilityCISA KEV·5 days ago

CVE-2026-55040: Microsoft SharePoint Weak Authentication Vulnerability

Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.1 (Critical). Affects Microsoft SharePoint.

VulnerabilityCISA KEV·5 days ago

CVE-2026-65400: Apple macOS Improper Authentication Vulnerability

Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.8 (Critical). Affects Apple macOS.

VulnerabilityDark Reading·5 days ago

Video Call Exploit Chains Two Flaws in Unisoc Modems

Researchers have discovered an exploit chain combining two separate vulnerabilities in Unisoc modems that allows attackers to compromise Android devices through a simple phone call. The attack requires only that a victim answer the incoming call, after which an attacker can deliver a malicious payload to gain device control.

VulnerabilityThe Hacker News·6 days ago

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

A critical GraphQL vulnerability in GitLab Community and Enterprise editions (CVE-2026-19478, CVSS 9.4) could allow unauthenticated attackers to remotely delete or modify public projects and user data under certain conditions. GitLab has released security updates to address the flaw, which represents a significant risk to instances exposed to untrusted networks.

VulnerabilitySANS Internet Storm Center·6 days ago

Apple Patches iOS and macOS, (Mon, Aug 17th)

Apple released updates for iOS/iPadOS and macOS addressing 108 vulnerabilities across the platforms, arriving roughly two weeks after a targeted macOS patch for a screen-sharing flaw. The screen-sharing vulnerability patched in the previous update did not impact iOS/iPadOS devices.

VulnerabilityThe Hacker News·6 days ago

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Wiz researchers discovered a GitHub Actions workflow injection vulnerability in Snowflake's snowflake-connector-net repository that could allow attackers to execute arbitrary commands through a crafted GitHub issue, potentially exposing internal Jira credentials stored in the affected workflow. The flaw existed in the jira_issue.yml workflow file, which was triggered by GitHub issues, creating an attack vector for credential theft and unauthorized command execution.

VulnerabilityThe Hacker News·6 days ago

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

A critical vulnerability in the widely-deployed Forminator Forms WordPress plugin allows unauthenticated attackers to upload malicious PHP files and achieve remote code execution on affected sites. Tracked as CVE-2026-15748 with a CVSS score of 9.8, the flaw poses a severe risk to the plugin's 600,000+ active installations. The vulnerability was discovered by a security researcher and demands immediate patching to prevent exploitation.

VulnerabilityInfosecurity Magazine·6 days ago

UNISOC Modem Flaw Enables Remote Code Execution via Video Calls

A vulnerability in UNISOC modems allows attackers to achieve kernel-level code execution by exploiting video call functionality. This remote code execution capability represents a significant risk to devices using UNISOC chipsets, as the attack vector operates at a fundamental system level.

Load more