What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,943 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 10h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 14h ago
-
The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software
Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain. The post The Frontier AI Vulnerability Burst: Industrializing Autonomo…
-
AI widely used to exploit critical flaws, disrupt supply chains
A report confirms the growing use of AI across a broad spectrum of threat groups.
-
CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild
Overview On August 2, 2026, N-able published a security advisory for CVE-2026-18577 , an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix for an earlie…
-
CVE-2026-18556: N-able N-central — N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
-
CVE-2026-34486: Apache Tomcat — Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
-
CVE-2026-9198: IBM Langflow — IBM Langflow Code Injection Vulnerability
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
-
Attackers Exploit N-able Patch Bypass Flaw on RMM Servers
Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access.
-
Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
Overview On July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066 , an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected A…
-
Critical N-able N-central Vulnerability and Active Exploitation
Critical vulnerability in N-able N-central gives attackers unauthenticated, "god-mode" access to the RMM console.
-
CVE-2026-18577: N-able N-central — N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.
-
Digging Into Anthropic’s Cyber Verification Program
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 31, 2026 – Listen to the podcast The exploit lands before the fix even ships, says John Vecchi, CMO at Mitiga, a leader in zero-impact bre…
-
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Exploits can give persistent server access that survives credential rotation and disk re-imaging.
-
AI Harnesses Burst With Potential Exploit Opps
A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors.
-
Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting
The two Chrome updates in June patched more bugs than the 23 updates before them. Now, Google is ramping up its patching schedule thanks to AI-assisted vulnerability discovery.
-
KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
Overview On July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066 , a critical vulnerability affecting Active Storage image processing when used in conjunction with the libvips image processing …
-
Rapid7 named a Leader in the IDC MarketScape: Worldwide MDR Service for Midmarket 2026 Vendor Assessment
IDC has named Rapid7 a Leader in the 2026 Worldwide Managed Detection and Response Service for Midmarket 2026 Vendor Assessment ( Doc #US52992326, July 2026 ). We believe this recognition and research highlights where MDR is headi…
-
Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affectin…
-
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberatta…
-
CyberSecurity Expert Joseph Steinberg Discusses The Dangerous Failure to Address Hardware Vulnerabilities
In a video shot for Sepio Cyber, on whose advisory board he serves, Cybersecurity Expert Joseph Steinberg warns the public about a critical vulnerability facing modern organizations: unmanaged hardware. Steinberg explains that whi…
-
CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
Overview On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077 , a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrust…
-
Patch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent Swarms
The vulnerability in the AI hosting platform Ruflo allows an unauthenticated attacker to take over the system and corrupt memory, so bad behavior can persist after patching.
-
How AI is Rewriting the Zero-Day Playbook for Preemptive Security
The scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operati…
-
CVE-2026-20316: Cisco Secure Firewall Management Center (FMC) — Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device u…
-
This week on Enterprise Security Weekly: O'Shea Bowens explores MCP from a network security lens Jeremiah Gros…
This week on Enterprise Security Weekly: O'Shea Bowens explores MCP from a network security lens Jeremiah Grossman drops a serious truth bomb - the evidence doesn't support all the fervor around AI vulnerability discovery In the n…
-
Rapid7 Analysis: Check Point SmartConsole Authentication Bypass (CVE-2026-16232)
Overview On July 22, 2026, Check Point published a security advisory for CVE-2026-16232 , an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server …
-
'Certighost' Flaw Haunts Microsoft Active Directory Certificates
Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment.
-
Today's episode of Breach Please is live. Jake and Jess talk about how the story (again) about AI chats being …
Today's episode of Breach Please is live. Jake and Jess talk about how the story (again) about AI chats being indexed by search engines isn't really an AI story. We also talk briefly about a repo zero day. https:// youtu.be/pgLoqM…
-
'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure
This category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers' access controls.
-
Adversaries Don't Need a Zero-Day — They Read Your Rulebook
Confidence in autonomous security tools is declining, and here's why.
-
CVE-2025-68686: Fortinet FortiOS — Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism obse…
-
CVE-2026-16812: Arista VeloCloud Orchestrator — Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the …
-
Beyond the Vulnerability Apocalypse: Scaling Your Basics and Vulnerability Management
Developed together with Usman Chaudhary @ Google for Public Sector ( his post ) Let’s call it what some in the industry are calling it: the vulnerability apocalypse . For years, finding vulnerabilities was slow, expensive, special…
-
Mount Here, Read There: Twin Path Traversal CVEs in Kubernetes Storage
Discover how a filepath.Join misconception caused cross-tenant path traversal vulnerabilities in Kubernetes CSI drivers.
-
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
Overview On July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232 , an authe…
-
CVE-2026-16232: Check Point SmartConsole — Check Point SmartConsole Improper Authentication Vulnerability
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
-
CVE-2026-50522: Microsoft SharePoint — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
-
CVE-2026-60137: WordPress Core — WordPress Core SQL Injection Vulnerability
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code e…
-
CVE-2026-63030: WordPress Core — WordPress Core Interpretation Conflict Vulnerability
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
-
CVE-2026-0770: Langflow Langflow — Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
-
CVE-2021-27137: DD-WRT DD-WRT — DD-WRT Stack-Based Buffer Overflow Vulnerability
DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
-
Weekly Cyber Update: 10 July 2026
A new campaign threatens vulnerable content management systems; Progress Software patches a zero-day; Microsoft issues a record patch haul; and Russia’s FSB is targeting routers again. The Cyber Threat Intelligence Briefing is a w…
-
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appea…
-
FreeBSD Released the Most Security Advisories in Project History in June 2026
On average, the FreeBSD security team releases about 2 security advisories per month. AI has changed this. In April, the project released 8 advisories, with 6 powered by AI . In May, the count decreased slightly to 7. Today I took…
-
CVE-2026-58644: Microsoft SharePoint — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
-
CVE-2026-25089: Fortinet FortiSandbox — Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
-
CVE-2026-39808: Fortinet FortiSandbox — Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
-
CVE-2026-46817: Oracle E-Business Suite — Oracle E-Business Suite Improper Privilege Management Vulnerability
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can resul…
-
CVE-2023-4346: KNX Association KNX Protocol Connection Authorization Option 1 — KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled an…
-
Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical."
-
Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing P…
Last fetch 17m ago · 1 new · 2 source error(s)