#remote-code-execution

[ follow ]
#cybersecurity
Privacy technologies
fromThe Hacker News
1 week ago

Cursor AI Code Editor Vulnerability Enables RCE via Malicious MCP File Swaps Post Approval

Cursor AI has a critical vulnerability allowing remote code execution through altered software configurations.
fromTheregister
1 week ago

Vibe coding tool Cursor allows persistent code execution

Cursor's remote code execution bug poses significant risks by allowing attackers to modify configurations silently.
fromThe Hacker News
1 week ago

Google's August Patch Fixes Two Qualcomm Vulnerabilities Exploited in the Wild

The vulnerabilities include CVE-2025-21479 (CVSS score: 8.6) and CVE-2025-27038 (CVSS score: 7.5), both of which were disclosed alongside CVE-2025-21480 (CVSS score: 8.6) by the chipmaker back in June 2025.
Privacy technologies
#nvidia
Information security
fromTheregister
3 weeks ago

Cisco ISE flaw gave root access before fix landed

Cisco's Identity Services Engine vulnerability has been actively exploited since early July, rated critical on the CVSS scale for remote code execution.
#sharepoint
fromZDNET
4 weeks ago
Privacy professionals

Microsoft fixes two SharePoint zero-days under attack, but it's not over - how to patch

fromZDNET
4 weeks ago
Privacy professionals

Microsoft fixes two SharePoint zero-days under attack, but it's not over - how to patch

#microsoft
fromTechCrunch
1 month ago

Activision took down Call of Duty game after PC players hacked, says source | TechCrunch

The game is not safe to play on PC right now, there's an RCE exploit, which allows hackers the ability to plant malware capable of essentially taking control of a victim's device.
Video games
Video games
fromGadgets 360
1 month ago

Call of Duty: WWII Players on Xbox PC App Are Getting Hacked

Activision has removed Call of Duty: WWII from the Xbox PC app due to a serious security exploit.
fromIT Pro
1 month ago

Using WinRAR? Update now to avoid falling victim to this file path flaw

A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user.
Information security
Information security
fromTheregister
2 months ago

Veeam fixes another critical RCE bug in Backup & Replication

Users of Veeam Backup & Replication should urgently apply the latest patches to fix a critical remote code execution vulnerability.
fromThe Hacker News
2 months ago

HPE Issues Security Patch for StoreOnce Bug Allowing Remote Authentication Bypass

These vulnerabilities could be remotely exploited to allow remote code execution, disclosure of information, server-side request forgery, authentication bypass, arbitrary file deletion, and directory traversal information disclosure vulnerabilities.
Information security
Information security
fromTechzine Global
2 months ago

Active exploitation of vulnerabilities in Ivanti EPMM

Ivanti's Endpoint Manager Mobile has critical vulnerabilities exploited in both on-premises and cloud environments, allowing remote code execution without authentication.
fromSecuritymagazine
3 months ago

Hackers Can Take Control via SAP NetWeaver Flaw: SAP Security Analyst Discusses the Risks

A zero-day vulnerability in SAP NetWeaver allows remote code execution, posing significant risks to organizations globally.
#commvault
fromTechzine Global
3 months ago

SAP patches zero-day vulnerability in NetWeaver, denies exploitation

ReliaQuest reported that multiple customers have been compromised via unauthorized file uploads to SAP NetWeaver, allowing remote code execution.
Information security
Information security
fromSecuritymagazine
3 months ago

Devices exposed to remote hacking via Erlang/OTP SSH vulnerability

Erlang/OTP's SSH implementation has a critical vulnerability allowing remote code execution without authentication, requiring urgent attention and action from security teams.
[ Load more ]