It was discovered that PHP incorrectly handled backslash escaping in the
PostgreSQL extension. An attacker could use this issue to perform SQL
injection attacks. (CVE-2026-17543)
It was discovered that PHP incorrectly handled certain inputs to the
bccomp() function. An attacker could use this issue...
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described.
One flaw affects Check Poin...
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances.
According to independent reports from Blackpoint Cyber and GreyNoi...
USN-8737-1 fixed vulnerabilities in GNU C Library. This update provides
the corresponding fixes for Ubuntu 24.04 LTS.
Original advisory details:
It was discovered that GNU C Library had a buffer overflow in the strfmon
function when handling right-justification padding. An attacker could
possib...
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9.
A work profile is a separate space that Android typically reserves for employer...
State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), which is used for centrally managing multiple Cisco Secure Firewall devices across a network. Two FMC vulnerabi...
In June 2026, hackers stole personal, health, and insurance information from AdaptHealth’s systems.
The post 4.1 Million Impacted by AdaptHealth Data Breach appeared first on SecurityWeek.
Microsoft has fixed a known issue that wiped mouse settings on some Windows 11 systems after installing the KB5120998 August 2026 preview update. [...]
L'exploit ShieldCrash contourne le correctif de Microsoft pour la faille ShieldBreak et permet de lire n'importe quel fichier sur Windows et Windows Server.
Le post ShieldCrash : cette nouvelle zero-day Microsoft Defender offre un accès système a été publié sur IT-Connect.
Chrome issues another monster update, fixing an actively exploited V8 vulnerability and 229 other flaws.
Flatpak could be made to access files outside its sandbox or delete arbitrary files on the host.
Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it.
What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026....
Anthropic Discloses Fourth Cyber Incident in Alignment Assessment Anthropic disclosed a fourth incident in which a Claude model gained unauthorized access to real third-party systems during a cybersecurity evaluation, a case its own July review had missed entirely. The newly found incident occurred...
Scytale has announced the launch of their latest AI-powered third-party risk management (TPRM) capabilities within its Vendors module. The release further extends vendor risk management from a periodic review exercise into a continuously updated vendor risk intelligence engine, giving security and G...
WordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API. Releases considered a potential security risk will be blocked automatically. “A plugin can be secure today and introduce a vulnerability, or malicious code, in a f...
Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.
The post Organizations Warned of Cisco Secure FMC Exploitation appeared first on SecurityWeek.
For most of the age of sail, a captain could find his latitude in minutes and could not find his longitude at all.
Latitude you could read off the sun. Longitude, your position east to west, offered no such trick. Three weeks into the Atlantic, a navigator knew how far nort...
InquiryIQ, a previously unreported prototype, tested a model from xAI, maker of Grok, to surface associates, social accounts, and other information about people identified through Clearview.