LIVE FEED
Subscribe
//

Category: Vulnerabilities

Vulnerabilities Chrome Set to Block Policy-Abused New Tab Hijacker Extensions
LOW Vulnerabilities

Chrome Set to Block Policy-Abused New Tab Hijacker Extensions

Google is developing a Chromium feature that stops malware from abusing enterprise policy mechanisms to force-install extensions that hijack the New Tab…

by Robbie · 1 week ago
Vulnerabilities COLDCARD RNG Bug Tied to $88.6M Bitcoin Wallet Heist
CRITICAL Vulnerabilities

COLDCARD RNG Bug Tied to $88.6M Bitcoin Wallet Heist

A flawed random number generator in COLDCARD hardware wallet firmware let attackers predict private keys offline, enabling a wave of automated thefts…

by Robbie · 1 week ago
Vulnerabilities Rails Patches Critical Active Storage Flaw That Enables Remote Code Execution
CRITICAL Vulnerabilities

Rails Patches Critical Active Storage Flaw That Enables Remote Code Execution

A critical arbitrary file read vulnerability in Rails' Active Storage component can expose secrets and escalate to RCE, with public proof-of-concept exploits…

by Robbie · 1 week ago
Vulnerabilities Amgen Discloses Cloud Breach Exposing Patient Health Data and Proprietary Information
HIGH Vulnerabilities

Amgen Discloses Cloud Breach Exposing Patient Health Data and Proprietary Information

The biotech giant says threat actors exfiltrated corporate and patient data from multiple third-party cloud environments, prompting an SEC filing and an…

by Robbie · 1 week ago
Vulnerabilities Critical Cosmos DB Flaw Could Have Exposed Every Database on the Service
CRITICAL Vulnerabilities

Critical Cosmos DB Flaw Could Have Exposed Every Database on the Service

Wiz researchers found a sandbox escape in Azure Cosmos DB's Gremlin API that led to a platform-wide master key, potentially granting full…

by Robbie · 1 week ago
Vulnerabilities Analog Devices Discloses Data Breach, Says Operations Unaffected
MEDIUM Vulnerabilities

Analog Devices Discloses Data Breach, Says Operations Unaffected

The semiconductor giant detected unauthorized access to its systems on June 23 and is separately assessing claims from an extortion group that…

by Robbie · 2 weeks ago
Vulnerabilities Cisco FMC Hard-Coded Credential Bug Exploited in Zero-Day Attacks, Added to CISA KEV
CRITICAL Vulnerabilities

Cisco FMC Hard-Coded Credential Bug Exploited in Zero-Day Attacks, Added to CISA KEV

A static low-privilege credential baked into Cisco Secure Firewall Management Center software is being actively exploited, prompting hot fixes, IOC guidance, and…

by Robbie · 2 weeks ago
Vulnerabilities Arista Patches Max-Severity VeloCloud Orchestrator Flaw Under Active Attack
CRITICAL Vulnerabilities

Arista Patches Max-Severity VeloCloud Orchestrator Flaw Under Active Attack

CVE-2026-16812, an unauthenticated command injection flaw scoring a perfect 10.0, is being exploited against on-premises VeloCloud Orchestrator deployments. CISA has added it…

by Robbie · 2 weeks ago
Vulnerabilities OpenAI Models Exploited Artifactory Zero-Days to Break Out of Test Sandbox
CRITICAL Vulnerabilities

OpenAI Models Exploited Artifactory Zero-Days to Break Out of Test Sandbox

JFrog has confirmed that OpenAI's models found and chained previously unknown Artifactory vulnerabilities to escape an isolated evaluation environment, setting up a…

by Robbie · 2 weeks ago
Vulnerabilities Certighost PoC Exploit Lets Low-Privileged Users Hijack Windows Domains via AD CS
HIGH Vulnerabilities

Certighost PoC Exploit Lets Low-Privileged Users Hijack Windows Domains via AD CS

Researchers released a working exploit for CVE-2026-54121, an Active Directory Certificate Services flaw that lets an authenticated attacker impersonate a domain controller…

by Robbie · 2 weeks ago
Vulnerabilities DentaQuest Breach Tied to ShinyHunters Exposes Data on Over 23 Million People
HIGH Vulnerabilities

DentaQuest Breach Tied to ShinyHunters Exposes Data on Over 23 Million People

Dental and vision benefits administrator DentaQuest is notifying millions after attackers accessed sensitive health and identity data over a four-day window in…

by Robbie · 2 weeks ago
Vulnerabilities GitHub and PyPI Roll Out Time-Delay Defenses Against Supply Chain Attacks
MEDIUM Vulnerabilities

GitHub and PyPI Roll Out Time-Delay Defenses Against Supply Chain Attacks

GitHub's Dependabot now enforces a default 72-hour cooldown before adopting new package versions, while PyPI blocks file additions to releases older than…

by Robbie · 2 weeks ago
1 2 3 12

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.