Cisco on Wednesday rolled out patches for two dozen vulnerabilities across its products, including critical-severity bugs in Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC). For Catalyst SD-WAN, the company released five fixes, noting that the CVEs were assigned to multiple weaknesses grouped by the underlying vulnerability class. Three of the CVEs, namely ..
Tag : Vulnerabilities
Threat actors have started exploiting a recently patched vulnerability in JetBrains TeamCity, the US cybersecurity agency CISA warns. A continuous integration and continuous delivery (CI/CD) platform, TeamCity provides automated software building and deployment and is a central component of enterprise workflows, collaboration, and development practices. Tracked as CVE-2026-63077 (CVSS score of 9.8), the critical security ..
BLACK HAT – Two security researchers found a way to exploit vulnerabilities in Samsung software, including the virtual assistant Bixby, to hack mobile devices. The research was conducted by Dimitrios Valsamaras, senior security researcher at Microsoft, and Ken Gannon, head of mobile research at Mobile Hacking Lab. Gannon and Valsamaras demonstrated the vulnerabilities at the ..
Palo Alto Networks researchers have disclosed the details of new attack methods targeting passwordless authentication, showing how malware can hijack a passkey-protected account. Passkeys are increasingly adopted by tech giants and are widely recommended because they are more secure against phishing. The new attack methods, named ‘Pass-ta-key’ by Palo Alto Networks, focus on Google-synced passkeys. ..
Ruby on Rails this week rolled out patches for a critical vulnerability that could allow unauthenticated attackers to achieve remote code execution (RCE). A server-side web application framework written in Ruby, Ruby on Rails is used for the fast building of full-stack web applications and APIs. Tracked as CVE-2026-66066 (CVSS score of 9.5), the critical ..
Google this week confirmed that this year’s surge in Chrome vulnerabilities has been driven by the use of AI. The increase in Chrome bugs started in April and has continued throughout July, with the latest browser release containing 370 security fixes and bringing the total number of bugs patched this year to over 1,800. Google ..
A critical vulnerability in the Azure Cosmos DB database service could have allowed attackers to compromise all databases on the service, cybersecurity outfit Wiz reports. Referred to as CosmosEscape, the security defect could have allowed an attacker to obtain a platform-wide key and retrieve the primary key of any Cosmos DB account, gaining full read ..
JetBrains this week rolled out patches for a critical-severity vulnerability in TeamCity On-Premises that can be exploited without authentication. Tracked as CVE-2026-63077 (CVSS score of 9.8), the security defect can be exploited via HTTP/S to bypass authentication and achieve remote code execution (RCE). “An unauthenticated attacker could exploit the vulnerability via the TeamCity agent polling ..
Unauthenticated attackers could exploit a critical-severity vulnerability in the open source AI agent orchestration platform Ruflo to execute commands inside the container, Noma Labs security researchers warn. A popular automation assistant with over 67,000 GitHub stars, Ruflo (formerly Claude Flow) comes with a multi-model AI chat interface, agent swarms, persistent memory, and built-in Model Context ..
Apple announced on Monday that it has released patches for dozens of vulnerabilities discovered recently in its operating systems. The company patched 87 vulnerabilities with the release of iOS 26.6 and iPadOS 26.6. The flaws can be exploited to access sensitive user data, fingerprint users, cause a DoS condition, execute arbitrary code, delete files, modify ..


