< ciso
brief />
Tag Banner

All news with #vulnerability disclosure tag

648 articles · page 2 of 33

CoSnitch flaws let Copilot execute prompts and exfiltrate

🛡️ Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal that could allow a single click on a crafted link to run prompts and pull data from connected apps within a victim's authenticated session. The issues — collectively named CoSnitch and tracked as CVE-2026-24301 — rely on an undocumented URL parameter pairing (autorun=1 and q) to trigger automatic prompt execution and data exfiltration. Microsoft received the report in December 2025 and shipped patches on August 18, 2026.
read more →

Critical AIT‑GUI Flaw Allows Remote Command Execution

🔒 A critical vulnerability in NASA's open-source AIT-GUI ground control software could let unauthenticated actors issue spacecraft and instrument commands, execute server-side scripts, and run command sequences. Disclosed by Cycode researcher Yuval Elbar on August 18 and tracked as GHSA-p9r8-2q67-fp86 (CVSS 9.4), the flaw affects versions through 2.5.1 and was fixed in 2.5.2. The issue stems from an API that listens on all interfaces, lacks authentication/CSRF protection, and allows unsafe filesystem path construction on execution endpoints.
read more →

Critical GitLab GraphQL Flaw Allows Remote Project Changes

🔒 GitLab released out-of-cycle security updates on August 17, 2026, to fix a critical GraphQL vulnerability (CVE-2026-19478) that could let unauthenticated attackers remotely modify or delete public projects and user data. The patches apply to self-managed instances in versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4; hosted GitLab.com and Dedicated are already patched. A second, High-severity issue (CVE-2026-19650) addresses a CSRF-related GraphQL multiplex handling flaw requiring user interaction.
read more →

Critical Forminator flaw lets attackers execute code

🛡️ A critical vulnerability (CVE-2026-15748) in the Forminator Forms WordPress plugin — used on 600,000+ sites — allows unauthenticated attackers to upload arbitrary files, including executable PHP, and achieve remote code execution. The flaw, present in versions up to 1.56.1, stems from improper file type validation in the handle_file_upload() function and misuse of MIME key matching combined with a public submission handler. Patch 1.56.2, released on July 31, 2026, fixes the issue; site owners should update immediately.
read more →

UNISOC modem isolation flaw risks kernel RCE

🔒 SSD Secure Disclosure researchers revealed a UNISOC modem firmware vulnerability that lets modem-level code execution reach Android kernel space by exploiting improper isolation between modem and kernel memory. The team demonstrated a full exploit chain, including a VoLTE-triggered final stage, and tested it on devices such as the Realme C33. No vendor firmware fix from UNISOC has been reported, leaving OEM updates as the primary mitigation.
read more →

Critical WordPress plugin flaw exposes admin accounts

🔒 More than 40,000 WordPress sites were exposed by an authentication bypass in the User Profile Builder plugin. Tracked as CVE-2026-15826 with a 9.8 CVSS score, versions up to 3.16.4 are affected. Wordfence identified a type confusion in the registration/auto-login flow that can convert a failed registration into user ID 1, enabling generation of an admin authentication token. The vendor released version 3.16.5 on July 16; site owners should update immediately.
read more →

Critical SAP Commerce Cloud RCE Vulnerability Alert

🔔 SAP Commerce Cloud is affected by a maximum-severity vulnerability, CVE-2026-58231, rated 10.0 for insufficient authorization and input validation. An unauthenticated attacker can abuse a default authentication client to send crafted input and trigger arbitrary code execution, risking confidentiality, integrity, and availability. Vendors urge immediate patching and recommend IP filter sets as a temporary mitigation.
read more →

AI-driven vulnerability discovery and its implications

🔍 A Black Hat USA 2026 keynote highlighted rapid growth in AI-assisted vulnerability discovery and the strain it places on defenders. Research from Arizona State University found that advanced models and workflows dramatically increased the number of bugs found, creating reporting and patching backlogs. This surge raises concerns about responsible disclosure, patching practices, and the potential for AI to eventually reduce new vulnerabilities as models and development processes improve.
read more →

SCCM attack chain exploited with $58 certificate

🛡️ Researchers at XM Cyber demonstrated how a standard domain user can chain multiple flaws in Microsoft System Center Configuration Manager (SCCM) to achieve remote code execution on the primary site server. The attack combines a broken AdminService authorization, a path-traversal bug called CabSlip, weak signature validation exploitable with a low-cost commercial certificate, and an unsigned DLL load in the SMS Executive service. Microsoft patched the initial authorization flaw (CVE-2026-47301) in July, but additional fixes are expected in ConfigMgr 2609.
read more →

Researcher posts Defender patch bypass PoC

🛡️ A researcher known as Nightmare Eclipse published a proof-of-concept called ShieldBreak that appears to bypass Microsoft’s recent patch for CVE-2026-50656, enabling attackers with any initial access to escalate to system-level privileges. Security experts warn the PoC could erode trust in patches and stress defense-in-depth measures such as application allowlisting, tightened admin rights, and hunting for MsMpEng.exe spawning system shells. Independent confirmations and community detections are emerging, though Microsoft has not yet provided a formal response.
read more →

New ShieldBreak zero-day elevates Defender privileges

🔒 A new zero-day named ShieldBreak was published by researcher Nightmare Eclipse after Microsoft's August 2026 Patch Tuesday. The exploit is a bypass for the earlier RoguePlanet privilege escalation flaw and can grant SYSTEM privileges on patched Windows 10, Windows 11, and Windows Server installations. The researcher claims a 100% success rate in tested builds and ties the release to an ongoing dispute over Microsoft's disclosure and bug bounty practices.
read more →

SAP Commerce Cloud flaw lets attackers run code

🔒 SAP released patches for a maximum-severity vulnerability in SAP Commerce Cloud (Data Hub Adapter) tracked as CVE-2026-58231, rated 10.0, that could allow arbitrary code execution due to insufficient authorization checks and input validation. Onapsis urged customers to update to the fixed release and re-deploy; as a temporary mitigation, apply an IP Filter Set to restrict access to the vulnerable endpoint. SAP's August 2026 update also addressed three other critical flaws across Manufacturing Integration and Intelligence and ABAP platforms.
read more →

Microsoft issues massive August security patch bundle

🔒 Microsoft released updates addressing 398 security vulnerabilities across Windows and related software in its August Patch Tuesday, including one actively exploited zero-day and two publicly disclosed flaws. The company rated 42 of the fixes as critical, and attributed the flood of discoveries to AI-assisted vulnerability research. Experts caution that AI may accelerate bug finding but human oversight remains essential for safe, effective patching.
read more →

Cisco warns of ASA and FTD VPN flaw causing DoS

🔒 Cisco warns of a high-severity DoS vulnerability, CVE-2026-20349, affecting Secure Firewall ASA and Threat Defense (FTD) devices when certain remote access services are enabled. The flaw stems from insufficient error checking in HTTP request processing and can be exploited remotely without authentication to crash affected devices. Cisco has released hotfixes for multiple ASA and FTD releases and urges customers to upgrade, noting no available workarounds. The company reports active exploitation since August 2026 but has not shared exploit details or indicators of compromise.
read more →

OpenAI launches GPT‑5.6‑Cyber and Daybreak tiers

🔒 OpenAI has announced GPT‑5.6‑Cyber, a purpose-trained LLM for cybersecurity, and introduced two Daybreak tiers: Daybreak Blue for defensive tasks and Daybreak Red for advanced defensive and offensive testing. Daybreak Blue members get access to frontier models like GPT‑5.6 Sol with certain system-level safeguards removed for authorized defensive work, while Daybreak Red members can use purpose-trained cyber models such as GPT‑5.5‑Cyber and GPT‑5.6‑Cyber for advanced tasks. OpenAI says GPT‑5.6‑Cyber outperforms prior models on benchmarks and was used to find a high-severity V8 vulnerability that was responsibly disclosed and fixed.
read more →

OpenAI debuts GPT-5.6-Cyber; narrows response window

🔒 OpenAI expanded its Daybreak cybersecurity program and introduced GPT-5.6-Cyber, a specialized model for approved security researchers, warning that AI will shorten the time to detect and remediate vulnerabilities. Daybreak now has two tiers: Blue for defensive use of frontier models and Red for advanced vulnerability research and exploit validation. GPT-5.6-Cyber completed 95% of high-risk security requests in internal tests and has already discovered two V8 engine flaws reported to Google. Access is tightly controlled and will require hardware security keys for individuals by September 1, 2026.
read more →

Cisco warns of high-severity ClamAV flaws with PoC exploits

🔒 Cisco alerted customers to two high-severity vulnerabilities in the ClamAV ZIP archive parser used by its Secure Endpoint Connector, tracked as CVE-2026-20337 and CVE-2026-20338. The flaws, caused by improper boundary checks and memory handling, allow unauthenticated remote attackers to crash the ClamAV scanning process, resulting in denial-of-service (DoS). Proof-of-concept exploit code is publicly available, and Cisco plans updates later this month to address the issues across Windows, Linux, and macOS.
read more →

One-click prompt injection exposed Atlassian Rovo data

🛡️ Researchers at DEF CON 34 demonstrated a one-click prompt-injection attack called “RovoBlast” that abused Atlassian’s enterprise AI assistant Rovo by injecting malicious instructions via the rovoChatPrompt parameter. The exploit allowed a single click to make Rovo accept attacker-supplied parameters in a user session, potentially exposing data across connected services like Slack, Microsoft 365, Google Workspace, Jira, and Confluence. Varonis reported the issue through Bugcrowd and Atlassian has issued a fix, while researchers urged limiting Rovo’s access and disabling unneeded automation.
read more →

WordPress pre-auth XSS patched in 7.0.3 release

🔒 WordPress patched a pre-auth reflected XSS in the login screen (CVE-2026-64638) that requires no attacker privileges and can execute JavaScript when a crafted username reaches the failed-login page. Researchers at pwn.ai demonstrated chaining the XSS to PHP code execution if an Administrator interacts with an attacker-controlled page, and WordPress issued fixes on August 6 across supported branches.
read more →

AI-driven HTTP desync research uncovers new techniques

🛡️ PortSwigger's AI-assisted system HTTP Terminator, developed by James Kettle, autonomously generated and validated novel HTTP desynchronization techniques after exploring 30,000 candidate attack vectors. The team also ran a human-guided cascade that discovered a now-patched zero-day in Apache Traffic Server (CVE-2026-63078) and reported findings across banks, government infrastructure, and security products. PortSwigger released the tool as open source and recommends avoiding HTTP/1.1 upstream or tightly allow-listing methods where removal isn't possible.
read more →