#cve

[ follow ]
fromComputerworld
4 days ago

February's Patch Tuesday release fixes 59 flaws, including 6 being exploited

Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February addresses 59 CVEs across the company's product family - roughly half the volume of January's 159 patches. Six vulnerabilities, affecting Windows Shell, MSHTML, Desktop Window Manager, Remote Desktop, Remote Access, and Microsoft Word, are already being actively exploited.
Information security
#vulnerabilities
fromTechzine Global
1 week ago

Over 40,000 OpenClaw agents vulnerable

Security experts have discovered tens of thousands of unsecured OpenClaw instances. The AI agents run vulnerable software versions and offer attackers access to systems. More than 12,000 instances are vulnerable to remote code execution. Researchers at SecurityScorecard have exposed a major security problem for the rapidly growing OpenClaw. Through internet scans, the team identified 28,663 unique IP addresses with exposed OpenClaw control panels spread across 76 countries.
Information security
#cvss
fromTheregister
2 months ago

New React vulns leak secrets, invite DoS attacks

In addition to already-reported flaws, newly discovered bugs allow attackers to hang vulnerable servers and potentially leak Server Function source code, so anyone using RSC or frameworks that support it should patch quickly. The latest vulnerabilities - two high-severity denial-of-service bugs tracked as CVE-2025-55184 and CVE-2025-67779 (CVSS 7.5), and a source-code exposure flaw tracked as CVE-2025-55183 (CVSS 5.3) - were found by security researchers attempting to poke holes in the patch for the earlier maximum-severity React flaw that is under active exploitation.
React
Information security
fromZero Day Initiative
2 months ago

Zero Day Initiative - The December 2025 Security Update Review

Adobe released five bulletins addressing 139 CVEs—mostly XSS in Experience Manager—with Critical DOM-based XSS and a priority-1 ColdFusion fix; Microsoft released 56 Windows CVEs.
Information security
fromIT Pro
2 months ago

Security experts claim the CVE Program isn't up to scratch anymore - inaccurate scores and lengthy delays mean the system needs updated

The CVE/NVD system is failing: many open-source vulnerabilities lack timely or accurate CVSS scores, creating operational risk for enterprises.
fromTheregister
4 months ago

CVE, CVSS scores need overhauling, argues Codific CEO

His analysis cites academic research published in August as part of the USENIX Security Symposium. The paper, "Confusing Value with Enumeration: Studying the Use of CVEs in Academia," (Moritz Schloegel et al.), reports that 34 percent of 1,803 CVEs cited in research papers over the past five years either have not been publicly confirmed or have been disputed by maintainers of the supposedly vulnerable software projects. The authors argue that CVEs should not be taken as a proxy for the real-world impact of claimed vulnerabilities.
Information security
fromTheregister
4 months ago

Microsoft frightful Patch Tuesday: 175+ CVEs, 3 under attack

Spooky season is in full swing, and this extends to Microsoft's October Patch Tuesday with security updates for a frightful 175 Microsoft vulnerabilities, plus an additional 21 non-Microsoft CVEs. And even scarier than the sheer number of bugs: three are listed as under attack, with three others publicly known, and 17 deemed critical security holes. Let's start with the flaws that attackers already found and exploited before Redmond pushed patches.
Information security
Information security
fromThe Verge
4 months ago

Unity discloses a years-old security exploit and urges developers to update their games

Major Unity security vulnerability dating to 2017 requires developers who released Windows, Android, or macOS builds to update to patched Unity versions immediately.
fromSecurityWeek
5 months ago

Apple Rolls Out iOS 26, macOS Tahoe 26 With Patches for Over 50 Vulnerabilities

iOS 26 and iPadOS 26 were released for the latest generation iPhone and iPad devices with fixes for 27 unique CVEs that could lead to memory corruption, information disclosure, crashes, and sandbox escapes. WebKit received the largest number of fixes, at five, for security defects that could lead to process crashes, Safari crashes, or could allow websites to access sensor information without consent.
Apple
Information security
fromTheregister
5 months ago

CISA attempts to assert control over CVE in vision outline

CISA aims to assert governmental control over the CVE program, transitioning it from a growth era to a government-led "quality era" beginning in 2025.
fromThe Hacker News
6 months ago

Google's August Patch Fixes Two Qualcomm Vulnerabilities Exploited in the Wild

The vulnerabilities include CVE-2025-21479 (CVSS score: 8.6) and CVE-2025-27038 (CVSS score: 7.5), both of which were disclosed alongside CVE-2025-21480 (CVSS score: 8.6) by the chipmaker back in June 2025.
Privacy technologies
#cybersecurity
fromHackernoon
2 years ago
EU data protection

Attaxion Becomes The First EASM Platform To Integrate ENISA's EU Vulnerability Database (EUVD) | HackerNoon

Information security
fromDevOps.com
9 months ago

INE Security Alert: Continuous CVE Practice Closes Critical Gap Between Vulnerability Alerts and Effective Defense - DevOps.com

Ongoing practical training with CVEs is essential for cybersecurity teams to transition from reactive to proactive readiness.
Information security
fromHackernoon
2 years ago

Continuous CVE Practice Closes Critical Gap Between Vulnerability Alerts and Effective Defense | HackerNoon

Transforming security teams from reactive to proactive defenders is vital, requiring hands-on practice with real-world vulnerabilities.
fromHackernoon
2 years ago
EU data protection

Attaxion Becomes The First EASM Platform To Integrate ENISA's EU Vulnerability Database (EUVD) | HackerNoon

fromDevOps.com
9 months ago
Information security

INE Security Alert: Continuous CVE Practice Closes Critical Gap Between Vulnerability Alerts and Effective Defense - DevOps.com

fromHackernoon
2 years ago
Information security

Continuous CVE Practice Closes Critical Gap Between Vulnerability Alerts and Effective Defense | HackerNoon

Information security
fromTheregister
8 months ago

Salesforce fixes 5 bugs following spate of reported issues

Salesforce identified five significant vulnerabilities related to configuration weaknesses, urging customers to secure their setups.
fromZero Day Initiative
8 months ago

Zero Day Initiative - The June 2025 Security Update Review

Adobe's June 2025 updates address 254 CVEs across multiple products, prioritizing those in Commerce and introducing a substantial fix for Experience Manager, despite no known exploits.
Web frameworks
Node JS
fromThe Cyber Express
8 months ago

Multer Vulnerabilities Expose Node.js Apps To DoS Attacks

Two critical vulnerabilities in Multer could crash Node.js applications through malformed uploads, emphasizing the need for immediate updates.
Information security
fromThe Hacker News
9 months ago

SonicWall Confirms Active Exploitation of Flaws Affecting Multiple Appliance Models

Two significant security vulnerabilities in SonicWall's SMA100 appliances have been exploited, urging users to review their devices for unauthorized logins.
fromTheregister
10 months ago

The splintering of a standard bug tracking system has begun

"Dependence on the largesse of a single, and now volatile, government48;that's a serious flaw. The CVE funding fiasco is a wake-up call for the industry."
Privacy professionals
[ Load more ]