< ciso
brief />
Tag Banner

All news with #vulnerability disclosure tag

648 articles · page 5 of 33

Progress restores ShareFile after security suspension

🔒 Progress has restored access to its ShareFile Storage Zones Controller after a four-day suspension following the detection of a credible external security threat on July 10. The incident involved exploitation of a high-severity path traversal vulnerability in Storage Zones Controller versions 5.x and 6.x, and patched releases 5.12.5 and 6.0.2 have been issued. Progress reported no evidence of unauthorized access and is withholding the CVE to allow customers time to patch.
read more →

Microsoft July 2026 Patch Tuesday: 622 Flaws Released

🛡️ Microsoft released its July 2026 security updates addressing 622 vulnerabilities across many products, including 57 marked critical. Two flaws have confirmed in-the-wild exploitation: an AD FS elevation of privilege (CVE-2026-56155) and a SharePoint spoofing/authentication issue (CVE-2026-56164). Talos highlights multiple critical remote-code-execution and elevation-of-privilege flaws affecting Windows components, Office, SharePoint, SQL Server, Defender, Copilot and cloud services. Cisco Talos also published Snort rules and urged customers to update intrusion-detection rule sets to detect exploitation attempts.
read more →

Microsoft issues record July security update batch

🔒 Microsoft released updates addressing a record 570 security vulnerabilities in July’s Patch Tuesday, attributing the surge to AI-assisted discovery. Nearly 60 of the flaws are rated critical, and three are confirmed zero-days already exploited in the wild. The fixes include numerous elevation-of-privilege bugs and a BitLocker security bypass; vendors warn that AI speeds both discovery and exploit development.
read more →

Microsoft issues Windows 10 KB5099539 security update

🔒 Microsoft released the Windows 10 KB5099539 extended security update, delivering the July 2026 Patch Tuesday fixes and additional security and reliability improvements for enrolled devices and LTSC editions. The update moves Windows 10 to build 19045.7548 (19044.7548 for Enterprise LTSC 2021) and addresses a record 570 vulnerabilities, including two exploited and one publicly disclosed zero-day. Administrators and eligible consumers can install it via Settings > Windows Update; several known issues and hardening changes are documented.
read more →

SAP July 2026 fixes critical NetWeaver ABAP flaw

🔒 SAP released its July 2026 security updates to remediate multiple serious vulnerabilities, including a critical NetWeaver Application Server ABAP out-of-bounds write (CVE-2026-44747). Vendors and customers are urged to apply the ABAP Kernel patch because the suggested workaround—disabling specific ICF nodes via SICF—may break SAP GUI for HTML. Other addressed issues include an HTTP request/response smuggling bug in Approuter (CVE-2026-27690) and a default-credential OAuth client issue in Commerce Cloud (CVE-2026-44761). SAP notes no evidence of active exploitation but recommends immediate patching and auditing of production instances for sample OAuth clients.
read more →

RabbitMQ flaws risk OAuth secret exposure

🔒 Cybersecurity researchers disclosed two access-control flaws in RabbitMQ that could leak OAuth client secrets and allow cross-tenant data access. Miggo's team reported one issue exposes the broker's OAuth secret to unauthenticated requests, enabling full broker takeover, while the other permits authenticated users to read other tenants' queue metadata. Affected releases begin at 3.13.0; fixes are available in recent patch releases and administrators are urged to rotate secrets and restrict management access.
read more →

Old Microsoft-signed UEFI shims expose Secure Boot

🔒 Researchers found 11 Microsoft-signed UEFI shim bootloaders that can be abused to bypass Secure Boot on many systems, enabling execution of untrusted code during early boot. ESET and CERT/CC detail how outdated shims (mostly v0.9 and earlier) remained trusted because they were not revoked, allowing attackers to deploy UEFI bootkits and persist below the OS. Microsoft revoked affected certificates in June 2026 following disclosures.
read more →

RabbitMQ OAuth secret leak and authorization bypass patched

🔒 RabbitMQ has patched two critical access control flaws that could expose OAuth client secrets and leak queue/exchange metadata. Discovered by Miggo Security, CVE-2026-57219 allowed unauthenticated retrieval of OAuth configuration from an obsolete endpoint, risking full broker takeover; CVE-2026-57221 permitted authorization bypass for passive declarations, enabling reconnaissance. Users should upgrade immediately and rotate secrets.
read more →

Six U-Boot Vulnerabilities Enable Stealthy Firmware Attacks

🔒 Binarly disclosed six vulnerabilities in the widely used U-Boot bootloader's FIT signature verification that can lead to crashes or arbitrary code execution during device boot. These flaws, present in code dating back to U-Boot 2013.07, potentially affect many releases and vendor forks across BMCs, networking gear, industrial systems, and IoT devices. While patches have been accepted upstream, vendor firmware updates are required to protect devices, and unsupported hardware may remain vulnerable.
read more →

Friday Squid Blogging: Squidbleed Vulnerability

🦑 A decades-old bug in the Squid proxy can leak HTTP request data, a flaw dubbed "Squidbleed." This post mixes a lighthearted squid image with serious security discussion, noting the vulnerability's age and potential impact on privacy. The author also invites readers to discuss other current security news not yet covered.
read more →

Six new U-Boot flaws risk pre-OS code execution

🔒 Researchers at Binarly disclosed six vulnerabilities in U-Boot, the bootloader used across routers, cameras, and server management controllers. Two flaws allow code execution during image parsing before signature verification, while four cause crashes. The bugs trace to unchecked returns from fdt_get_name and other parsing errors; patches were merged but not yet broadly distributed.
read more →

OpenClaw flaws enable host escape and credential theft

🔒 Three critical vulnerabilities in the OpenClaw personal AI assistant could allow credential theft, privilege escalation, and arbitrary host code execution if exploited. The flaws include two command injection bugs (GHSA-hjr6-g723-hmfm and GHSA-9969-8g9h-rxwm) and a path traversal/link-following issue (GHSA-575v-8hfq-m3mc). OpenClaw 2026.6.6 patches these issues; operators are advised to harden configurations and limit tool/channel allowlists.
read more →

Talos: Multiple Vulnerabilities in WolfSSL, GeoVision, VTK

🔒 Cisco Talos disclosed multiple vulnerabilities across WolfSSL, GeoVision, and VTK-DICOM, all of which have been patched by vendors in line with Cisco’s disclosure policy. The findings include three WolfSSL issues (two improper input validation and one integer underflow), 14 GeoVision advisories spanning 37 CVEs, and one heap-based buffer overflow in VTK-DICOM. Snort rules to detect exploit attempts are available from Snort.org. Discoveries were made by Ankur Tyagi, Philippe Laulheret, and Emmanuel Tacheau of Cisco Talos.
read more →

GhostApproval: AI coding assistants allow hidden writes

🔒 Wiz Research disclosed GhostApproval, a flaw in six AI coding assistants that allows symlink tricks to make approval prompts misrepresent targets. The vulnerability can let a repository write attacker-supplied keys or files to sensitive locations, potentially enabling passwordless remote access or remote code execution. Amazon, Google and Cursor have patched the issue; Augment and Windsurf have yet to fix it, while Anthropic disputes that its behavior is a vulnerability. Wiz recommends resolving symlinks before approval and flagging writes outside the project.
read more →

Critical Writer AI flaw let attackers hijack sessions

🔒 Cybersecurity researchers disclosed a critical session isolation vulnerability in Writer, an enterprise generative AI platform, that allowed cross-tenant account takeover via a one-click exploit named WriteOut. An attacker could create an agent, share its live preview link, and when a logged-in user opened the link their session cookie would be forwarded into the attacker’s sandbox and exfiltrated. Writer has patched the issue by isolating session cookies and preventing them from being forwarded into sandbox previews.
read more →

CERT/CC warns of hidden admin backdoor in Tenda

🔒 The CERT Coordination Center (CERT/CC) has disclosed that multiple Tenda router firmware versions contain an undocumented authentication backdoor (CVE-2026-11405) that allows attackers to bypass password checks and gain administrative access. The backdoor resides in the login() function of the /bin/httpd binary and compares a submitted password to a configuration-stored value obtained via GetValue("sys.rzadmin.password"). Any username is accepted when the backdoor password matches, enabling full device takeover. Users should disable remote management and change default LAN IPs while a patch is pending.
read more →

Critical Opera GX mod flaw allowed cross‑site data theft

🔒 An independent researcher discovered a critical vulnerability in Opera GX where GX Mods auto-install on download with no permission prompt, allowing an attacker to inject CSS across all pages. This behavior enabled a zero-click XS-Leak to recover a victim's Gmail address and facilitated a DoS crash when mods were forced into private mode. The issue was reported in February, patched on May 8, and the PoC was published on July 3.
read more →

Max-severity Adobe ColdFusion flaw being actively exploited

🔧 Adobe has issued emergency updates to fix a maximum-severity ColdFusion vulnerability (CVE-2026-48282) that is now being actively exploited, the Canadian Center for Cyber Security (CCCS) warned. The flaw affects ColdFusion 2025.9, 2023.20, and earlier, enabling unauthenticated remote code execution on unpatched systems. Adobe urges administrators to install the patch immediately, and Shadowserver reports nearly 800 exposed ColdFusion instances online.
read more →

Opera GX auto-install flaw allowed silent data leaks

🛡️ Researchers discovered a flaw in the gaming-focused Opera GX browser that allowed malicious websites to silently auto-install a GX Mod (a .crx look-and-feel package) and use its CSS to extract specific data from pages a victim visited. In a proof of concept, the team reconstructed a signed-in user's full Gmail address from a single visit, with no clicks required. Opera patched the issue in Opera GX version 130.0.5847.89, labeled the bug P1, paid the $5,000 maximum bounty, and reported no evidence of in-the-wild exploitation. There was no practical workaround prior to the patch.
read more →

Seven vulnerabilities disclosed in ubiquitous FatFs library

🔒 Security firm runZero disclosed seven vulnerabilities in the FatFs filesystem library used to read FAT/exFAT on many embedded devices. The bugs—rated Medium to High—can lead to memory corruption, crashes, data leaks, or code execution when a device mounts malformed media or firmware images. Only the GPT hang issue is fixed upstream; most fixes must come from downstream vendors who bundle FatFs. runZero published PoCs and urges vendors and integrators to audit wrappers and treat physical ports and update channels as attack surfaces.
read more →