LIVE FEED
Subscribe
//

Category: Vulnerabilities

Vulnerabilities Unpatched XRING Bug in Alibaba’s XQUIC Lets Remote Clients Crash HTTP/3 Servers
HIGH Vulnerabilities

Unpatched XRING Bug in Alibaba’s XQUIC Lets Remote Clients Crash HTTP/3 Servers

A single-line variable error in Alibaba's XQUIC library allows unauthenticated attackers to crash HTTP/3 servers with a short burst of valid QPACK…

by Robbie · 3 months ago
Vulnerabilities Three Chained Flaws in OpenClaw AI Assistant Enabled WhatsApp-to-Host Takeover
HIGH Vulnerabilities

Three Chained Flaws in OpenClaw AI Assistant Enabled WhatsApp-to-Host Takeover

A researcher has disclosed details of three now-patched, high-severity vulnerabilities in the OpenClaw personal AI assistant that could be chained from a…

by Robbie · 3 months ago
Vulnerabilities Weekly Roundup: DHS Database Breach, Adobe Speeds Up Patches, Canada Disrupts Ransomware Infrastructure
MEDIUM Vulnerabilities

Weekly Roundup: DHS Database Breach, Adobe Speeds Up Patches, Canada Disrupts Ransomware Infrastructure

This week's roundup covers a breach of a DHS interagency network, Adobe's move to twice-monthly patch releases, Canadian intelligence operations against ransomware…

by Robbie · 3 months ago
Vulnerabilities Progress Tells ShareFile Storage Zone Controller Customers to Shut Down Servers Now
HIGH Vulnerabilities

Progress Tells ShareFile Storage Zone Controller Customers to Shut Down Servers Now

Progress Software has disabled cloud access to on-premises ShareFile Storage Zone Controllers and is urging customers to manually power down affected Windows…

by Robbie · 3 months ago
Vulnerabilities Dutch Police Suspect Local Hackers Behind Odido Vishing Breach
HIGH Vulnerabilities

Dutch Police Suspect Local Hackers Behind Odido Vishing Breach

Dutch National Police say they have found strong indications that Dutch-speaking hackers used a vishing call to Odido's customer service to trigger…

by Robbie · 3 months ago
Vulnerabilities npm 12 Disables Install Scripts by Default to Cut Supply Chain Risk
MEDIUM Vulnerabilities

npm 12 Disables Install Scripts by Default to Cut Supply Chain Risk

GitHub has shipped npm 12 with install scripts turned off by default and has deprecated granular access tokens that could bypass two-factor…

by Robbie · 3 months ago
Vulnerabilities Injective Labs npm SDK Backdoored to Steal Crypto Wallet Keys
CRITICAL Vulnerabilities

Injective Labs npm SDK Backdoored to Steal Crypto Wallet Keys

Attackers compromised a contributor's GitHub account to publish a malicious version of the @injectivelabs/sdk-ts package, silently harvesting private keys and seed phrases…

by Robbie · 3 months ago
Vulnerabilities Chrome 150 Patches 27 Vulnerabilities, Including Two Critical Flaws
CRITICAL Vulnerabilities

Chrome 150 Patches 27 Vulnerabilities, Including Two Critical Flaws

Google's Chrome 150 update addresses 27 security vulnerabilities, with two critical use-after-free bugs in the Ozone and Views components leading the list.…

by Robbie · 3 months ago
Vulnerabilities CISA Orders Federal Agencies to Patch Actively Exploited Langflow Auth Bypass
HIGH Vulnerabilities

CISA Orders Federal Agencies to Patch Actively Exploited Langflow Auth Bypass

CISA has added a Langflow authorization bypass flaw to its KEV catalog and given federal civilian agencies until Friday to apply patches,…

by Robbie · 3 months ago
Vulnerabilities Critical Gitea Auth Bypass Flaw Under Active Exploitation
CRITICAL Vulnerabilities

Critical Gitea Auth Bypass Flaw Under Active Exploitation

A critical vulnerability in Gitea's Docker images allows attackers to impersonate any user with a single HTTP header. Exploitation began just 13…

by Robbie · 3 months ago
Vulnerabilities Januscape: 16-Year-Old Linux KVM Flaw Enables VM Escape on Intel and AMD
CRITICAL Vulnerabilities

Januscape: 16-Year-Old Linux KVM Flaw Enables VM Escape on Intel and AMD

A use-after-free bug in the Linux kernel's KVM shadow MMU lets an attacker with guest root access execute code on the host,…

by Robbie · 3 months ago
Vulnerabilities Hidden Backdoor in Tenda Router Firmware Grants Admin Access
CRITICAL Vulnerabilities

Hidden Backdoor in Tenda Router Firmware Grants Admin Access

A hardcoded secondary authentication mechanism in multiple Tenda router firmware versions allows any attacker who knows the backdoor password to gain full…

by Robbie · 3 months ago
1 … 12 13 14 … 19

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.