Latest IntelligenceVulnerabilitiesPage 3
Search by keyword →GrapheneOS may skip Pixel 11 over missing hardware security feature
GrapheneOS says it may abandon support for Google’s Pixel 11 series after discovering that the new devices appear to lack usable support for ARM Memory Tagging ...

PaperCut releases second emergency patch for exploited flaws
PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after re...

Experiment shows AI agents can escape secure VMs using zero-days
A cyber-capable AI agent could repeatedly escape a QEMU/KVM virtual machine, first using known vulnerabilities and later chaining previously unknown flaws. The ...

GiveWP WordPress donation plugin flaw lets hackers execute server commands
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [......

AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?
AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace. Action1 explains why ...

Over 8,300 Gitea servers vulnerable to code execution attacks
Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according t...

ServiceNow warns of three max severity security vulnerabilities
ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and priv...

PaperCut warns of NG, MF flaw exploited in zero-day attacks
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-da...

Webinar: How Google Workspace breaches happen and what to do next
Google Workspace breaches can begin with social engineering or forgotten third-party integrations rather than sophisticated exploits. This webinar examines real...

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday
CISA has ordered U.S. government agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution vulnerability by Saturd...

ATF confirms “major incident” after recent Qilin breach claims
ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromi...

Critical Avada WordPress theme flaw enables zero-click RCE
A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the ser...

Hackers target Microsoft SharePoint RCE chain with PoC exploit
Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to...

Ubiquiti patches three max severity security vulnerabilities
Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges. [...]...

Hackers now exploit critical Gitea flaw in code injection attacks
Attackers are now exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Secu...

AnonyMousKIT service uses AI calls to unlock stolen Apple devices
A Phishing-as-a-Service (PhaaS) ecosystem dubbed AnonyMousKIT helps criminals steal Apple credentials and disable Activation Lock on stolen devices. The platfor...

Hackers breached over 270 Zimbra servers in ongoing attacks
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vul...

Police arrests dozens of suspects in global cybercrime crackdown
Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime g...

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices
An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to...

Hackers target WordPress sites in miniOrange auth bypass attacks
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be ...