Category: Vulnerabilities
Chrome Set to Block Policy-Abused New Tab Hijacker Extensions
Google is developing a Chromium feature that stops malware from abusing enterprise policy mechanisms to force-install extensions that hijack the New Tab…
COLDCARD RNG Bug Tied to $88.6M Bitcoin Wallet Heist
A flawed random number generator in COLDCARD hardware wallet firmware let attackers predict private keys offline, enabling a wave of automated thefts…
Rails Patches Critical Active Storage Flaw That Enables Remote Code Execution
A critical arbitrary file read vulnerability in Rails' Active Storage component can expose secrets and escalate to RCE, with public proof-of-concept exploits…
Amgen Discloses Cloud Breach Exposing Patient Health Data and Proprietary Information
The biotech giant says threat actors exfiltrated corporate and patient data from multiple third-party cloud environments, prompting an SEC filing and an…
Critical Cosmos DB Flaw Could Have Exposed Every Database on the Service
Wiz researchers found a sandbox escape in Azure Cosmos DB's Gremlin API that led to a platform-wide master key, potentially granting full…
Analog Devices Discloses Data Breach, Says Operations Unaffected
The semiconductor giant detected unauthorized access to its systems on June 23 and is separately assessing claims from an extortion group that…
Cisco FMC Hard-Coded Credential Bug Exploited in Zero-Day Attacks, Added to CISA KEV
A static low-privilege credential baked into Cisco Secure Firewall Management Center software is being actively exploited, prompting hot fixes, IOC guidance, and…
Arista Patches Max-Severity VeloCloud Orchestrator Flaw Under Active Attack
CVE-2026-16812, an unauthenticated command injection flaw scoring a perfect 10.0, is being exploited against on-premises VeloCloud Orchestrator deployments. CISA has added it…
OpenAI Models Exploited Artifactory Zero-Days to Break Out of Test Sandbox
JFrog has confirmed that OpenAI's models found and chained previously unknown Artifactory vulnerabilities to escape an isolated evaluation environment, setting up a…
Certighost PoC Exploit Lets Low-Privileged Users Hijack Windows Domains via AD CS
Researchers released a working exploit for CVE-2026-54121, an Active Directory Certificate Services flaw that lets an authenticated attacker impersonate a domain controller…
DentaQuest Breach Tied to ShinyHunters Exposes Data on Over 23 Million People
Dental and vision benefits administrator DentaQuest is notifying millions after attackers accessed sensitive health and identity data over a four-day window in…
GitHub and PyPI Roll Out Time-Delay Defenses Against Supply Chain Attacks
GitHub's Dependabot now enforces a default 72-hour cooldown before adopting new package versions, while PyPI blocks file additions to releases older than…