Tag : Vulnerabilities

image_pdfimage_print

Cisco on Wednesday rolled out patches for two dozen vulnerabilities across its products, including critical-severity bugs in Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC). For Catalyst SD-WAN, the company released five fixes, noting that the CVEs were assigned to multiple weaknesses grouped by the underlying vulnerability class. Three of the CVEs, namely ..

Leggi tutto

Threat actors have started exploiting a recently patched vulnerability in JetBrains TeamCity, the US cybersecurity agency CISA warns. A continuous integration and continuous delivery (CI/CD) platform, TeamCity provides automated software building and deployment and is a central component of enterprise workflows, collaboration, and development practices. Tracked as CVE-2026-63077 (CVSS score of 9.8), the critical security ..

Leggi tutto

BLACK HAT – Two security researchers found a way to exploit vulnerabilities in Samsung software, including the virtual assistant Bixby, to hack mobile devices. The research was conducted by Dimitrios Valsamaras, senior security researcher at Microsoft, and Ken Gannon, head of mobile research at Mobile Hacking Lab.  Gannon and Valsamaras demonstrated the vulnerabilities at the ..

Leggi tutto

Palo Alto Networks researchers have disclosed the details of new attack methods targeting passwordless authentication, showing how malware can hijack a passkey-protected account. Passkeys are increasingly adopted by tech giants and are widely recommended because they are more secure against phishing. The new attack methods, named ‘Pass-ta-key’ by Palo Alto Networks, focus on Google-synced passkeys. ..

Leggi tutto

Ruby on Rails this week rolled out patches for a critical vulnerability that could allow unauthenticated attackers to achieve remote code execution (RCE). A server-side web application framework written in Ruby, Ruby on Rails is used for the fast building of full-stack web applications and APIs. Tracked as CVE-2026-66066 (CVSS score of 9.5), the critical ..

Leggi tutto

JetBrains this week rolled out patches for a critical-severity vulnerability in TeamCity On-Premises that can be exploited without authentication. Tracked as CVE-2026-63077 (CVSS score of 9.8), the security defect can be exploited via HTTP/S to bypass authentication and achieve remote code execution (RCE). “An unauthenticated attacker could exploit the vulnerability via the TeamCity agent polling ..

Leggi tutto

Unauthenticated attackers could exploit a critical-severity vulnerability in the open source AI agent orchestration platform Ruflo to execute commands inside the container, Noma Labs security researchers warn. A popular automation assistant with over 67,000 GitHub stars, Ruflo (formerly Claude Flow) comes with a multi-model AI chat interface, agent swarms, persistent memory, and built-in Model Context ..

Leggi tutto