The Cybersecurity and Infrastructure Security Agency has expanded its Known Exploited Vulnerabilities (KEV) catalog with three Linux kernel flaws, urging federal agencies to immediately patch them. Tracked as CVE-2025-39682 (CVSS score of 9.8), the first of the bugs is a… Read More "Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities"
Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Cybersecurity firms Check Point, Kaspersky, and Tanium have each patched severe vulnerabilities in their products, including ones that can be exploited for remote code execution. Check Point has informed customers about a critical vulnerability affecting Security Management and Log Server… Read More "Check Point, Kaspersky, Tanium Patch Product Vulnerabilities"
AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Researchers at security firm Hacktron used Claude to build a working exploit for a vulnerability in an image-processing library, then chained it with a flaw in OpenAI’s sign-in system to take over employee ChatGPT and Codex accounts, and ultimately gained… Read More "AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code"
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Microsoft released patches for 18 vulnerabilities on Thursday, spanning its Azure cloud portfolio and Copilot-branded AI products. Elevation of privilege flaws made up the bulk of the disclosures, affecting Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Billing, Azure… Read More "Microsoft Patches 18 Vulnerabilities in AI, Cloud Products"
Critical Orkes Conductor Vulnerability Exploited in Attacks
A critical-severity vulnerability in Orkes Conductor that can be exploited without authentication has been in attackers’ crosshairs for at least a month. Conductor is an open source unified enterprise framework that allows organizations to orchestrate microservices, workflows, and AI agents.… Read More "Critical Orkes Conductor Vulnerability Exploited in Attacks"
ISC Patches 14 Vulnerabilities in BIND 9 Security Update
Internet Systems Consortium (ISC) has released fresh security updates for BIND, the widely used open source DNS server software, resolving 14 vulnerabilities that could lead to denial-of-service (DoS) attacks. Seven are high-severity flaws that could be exploited to cause an… Read More "ISC Patches 14 Vulnerabilities in BIND 9 Security Update"
CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot
The US Cybersecurity and Infrastructure Security Agency (CISA) announced on Wednesday that it’s retiring its weekly vulnerability bulletin. The vulnerability bulletin will be discontinued on September 28 as part of a shift to a risk-based approach in vulnerability management. The… Read More "CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot"
Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard
Cisco on Wednesday announced patches for dozens of critical-severity CVEs in Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard. The ISE security updates stand out with patches for 20 CVEs, including 12 critical-severity flaws. Three of… Read More "Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard"
Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day
Cisco on Wednesday released urgent patches for a critical-severity authentication bypass vulnerability in Identity Services Engine (ISE) that has been exploited in the wild as a zero-day. Tracked as CVE-2026-76460 (CVSS score of 10/10), the security defect impacts an API… Read More "Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day"
Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover
More than 200,000 WordPress websites are potentially exposed to takeover attacks via two critical-severity vulnerabilities in The Events Calendar plugin. A highly popular plugin with over 600,000 active installations, The Events Calendar allows administrators to easily create and manage an… Read More "Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover"