#vulnerabilities — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vulnerabilities, aggregated by home.social.
-
Августовский «В тренде VM»: уязвимости ViPNet Client, ядра Microsoft Windows и Microsoft SharePoint
Хабр, привет! На связи Александр Леонов, ведущий эксперт центра безопасности Positive Technologies (PT ESC) и дежурный по самым опасным уязвимостям месяца. Мы с командой аналитиков Positive Technologies регулярно смотрим на поток информации об уязвимостях из самых разных источников: бюллетени безопасности вендоров, соцсети, блоги, телеграм-каналы, репозитории кода, базы уязвимостей и эксплойтов. Из этого многообразия мы стараемся выделять самое важное – трендовые уязвимости, которые уже используются в реальных атаках или с высокой вероятностью будут эксплуатироваться в ближайшее время. С прошлого дайджеста мы добавили в общий список еще четыре трендовые уязвимости.
https://habr.com/ru/companies/pt/articles/1069464/
#трендовые_уязвимости #управление_уязвимостями #vulnerabilities #vulnerability_management #vipnet #microsoft_windows #microsoft_sharepoint_server #уязвимости_и_их_эксплуатация #cwe #cvss
-
"[R]esearchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets’ devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim."
https://www.wired.com/story/a-zoom-screen-sharing-bug-let-anyone-take-over-other-devices-on-a-call/
-
"[R]esearchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets’ devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim."
https://www.wired.com/story/a-zoom-screen-sharing-bug-let-anyone-take-over-other-devices-on-a-call/
-
Researchers, aided by AI, have found critical vulnerabilities in Microsoft SharePoint servers, allowing unauthenticated attackers to impersonate users and execute remote code. Microsoft has released patches to address these issues. Organizations should apply the July update and monitor for the August update to fully mitigate these risks.
#Cybersecurity #SharePoint #AI #Vulnerabilities #Microsoft #SecurityUpdate
https://thedailytechfeed.com/ai-agent-uncovers-critical-sharepoint-vulnerabilities…
-
Researchers, aided by AI, have found critical vulnerabilities in Microsoft SharePoint servers, allowing unauthenticated attackers to impersonate users and execute remote code. Microsoft has released patches to address these issues. Organizations should apply the July update and monitor for the August update to fully mitigate these risks.
#Cybersecurity #SharePoint #AI #Vulnerabilities #Microsoft #SecurityUpdate
https://thedailytechfeed.com/ai-agent-uncovers-critical-sharepoint-vulnerabilities…
-
AI Genie in the Wild
When I give talks about AI genies, I use this sort of example as a hypothetical. It’s ... https://www.schneier.com/blog/archives/2026/08/ai-genie-in-the-wild.html
-
AI Genie in the Wild
When I give talks about AI genies, I use this sort of example as a hypothetical. It’s ... https://www.schneier.com/blog/archives/2026/08/ai-genie-in-the-wild.html
-
From Check Point Research: Exploiting Cloudflare Code Mode and Workers
Check Point Research has demonstrated that #Cloudflare Code Mode, which allows AI agents to write #TypeScript against tools, inherited five #vulnerabilities from the worker runtime. The flaws could enable sandbox escape and cross-tenant data exposure. Cloudflare rated two issues Critical and fixed its managed Workers environment.
https://research.checkpoint.com/2026/when-agentic-glue-melts/
-
From Check Point Research: Exploiting Cloudflare Code Mode and Workers
Check Point Research has demonstrated that #Cloudflare Code Mode, which allows AI agents to write #TypeScript against tools, inherited five #vulnerabilities from the worker runtime. The flaws could enable sandbox escape and cross-tenant data exposure. Cloudflare rated two issues Critical and fixed its managed Workers environment.
https://research.checkpoint.com/2026/when-agentic-glue-melts/
-
One month to go ⌛
On 11 September, the first #CRA obligations apply: manufacturers must report actively exploited #vulnerabilities and severe #cybersecurity incidents via @enisa_eu Single Reporting Platform: https://enisa.europa.eu/topics/product-security/single-reporting-platform-srp
But reporting is only one part of the picture 🔍 Check out our #CCAT tools that support the assessment of cybersecurity throughout the product lifecycle, and identify cybersecurity issues before they become incidents: https://ccat.fi.muni.cz/tools
-
Updating hosts on a regular.. Something that can wait, what are the chances someone finds a vulnerability to get root access and escape containers ?
AI walks in
Fuck man, vulnerabilities after vulnerabilities, no matter AI hallucination or actual issues, it is out there and people are looking… I need to update that Ansible playbook and get ready to update the whole thing regularly…
#ai #homelab #selfhosting #selfhost #selfhosted #ansible #maintenance #vulnerabilities
-
Updating hosts on a regular.. Something that can wait, what are the chances someone finds a vulnerability to get root access and escape containers ?
AI walks in
Fuck man, vulnerabilities after vulnerabilities, no matter AI hallucination or actual issues, it is out there and people are looking… I need to update that Ansible playbook and get ready to update the whole thing regularly…
#ai #homelab #selfhosting #selfhost #selfhosted #ansible #maintenance #vulnerabilities
-
86,000 exposed servers hide a second, always-on computer, and half are critically flawed
Follow @1ban_news for daily coverage.
-
🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
https://github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated -
🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
https://github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated -
OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree
-
OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree
-
OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts
-
OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts
-
Anthropic’s New AI Model Can Identify More Software Bugs Than Ever. Microsoft Is Struggling To Fix Them Fast Enough.
-
Anthropic’s New AI Model Can Identify More Software Bugs Than Ever. Microsoft Is Struggling To Fix Them Fast Enough.
-
The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
-
The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
-
Vulnerabilities in Car Anti-Theft Device
This is disturbing:
…a team of security researchers at UC San Diego, who found t... https://www.schneier.com/blog/archives/2026/08/vulnerabilities-in-car-anti-theft-device.html#vulnerabilities #Uncategorized #Bluetooth #patching #hacking #cars
-
Vulnerabilities in Car Anti-Theft Device
This is disturbing:
…a team of security researchers at UC San Diego, who found t... https://www.schneier.com/blog/archives/2026/08/vulnerabilities-in-car-anti-theft-device.html#vulnerabilities #Uncategorized #Bluetooth #patching #hacking #cars
-
Bugtraq Is Back
Comments: https://news.ycombinator.com/item?id=49176947
#HackerNews #Bugtraq #Cybersecurity #Vulnerabilities #SecurityNews #InfoSec
-
Bugtraq Is Back
Comments: https://news.ycombinator.com/item?id=49176947
#HackerNews #Bugtraq #Cybersecurity #Vulnerabilities #SecurityNews #InfoSec
-
Hopefully, the fixes aren't too far behind.
Google Password Manager passkeys could be at risk with new 'Pass-ta-key' attack
https://9to5google.com/2026/08/04/google-password-manager-passkeys-could-be-at-risk/
#Google #passwordManager #Passkeys #Vulnerabilities #Security #Tech
-
Hopefully, the fixes aren't too far behind.
Google Password Manager passkeys could be at risk with new 'Pass-ta-key' attack
https://9to5google.com/2026/08/04/google-password-manager-passkeys-could-be-at-risk/
#Google #passwordManager #Passkeys #Vulnerabilities #Security #Tech
-
🤔 Ah, the #future where passwords are obsolete... yet here we are with a novel attack surface that screams, "Hello, hackers! 🎉 Please exploit me!" 🚨 Who knew going #passwordless meant losing your keys altogether? 🔑🔓
https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/ #security #cyberattack #tech #vulnerabilities #HackerNews #ngated -
🤔 Ah, the #future where passwords are obsolete... yet here we are with a novel attack surface that screams, "Hello, hackers! 🎉 Please exploit me!" 🚨 Who knew going #passwordless meant losing your keys altogether? 🔑🔓
https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/ #security #cyberattack #tech #vulnerabilities #HackerNews #ngated -
OK, Well, Rogue AI Agents Are Hacking Again
-
OK, Well, Rogue AI Agents Are Hacking Again
-
https://www.linkedin.com/posts/jolandadekoff_ethicalhacking-carhacking-bluetooth-share-7486055880069832704-Pf8t/ - #KARR, the system designed to protect your car has some #vulnerabilities that makes it easy to steal cars. "These devices share one secret key. Not one key per car. The same key sits in millions of them."
-
https://www.linkedin.com/posts/jolandadekoff_ethicalhacking-carhacking-bluetooth-share-7486055880069832704-Pf8t/ - #KARR, the system designed to protect your car has some #vulnerabilities that makes it easy to steal cars. "These devices share one secret key. Not one key per car. The same key sits in millions of them."
-
#OpenAI Hack Shows the Genie Is Out of the Bottle
Incident is an example of an AI genie. It was running #ExploitGym benchmark, which measures how good a model is at turning #vulnerabilities into exploits: basically a #cyberattack. Goal was to satisfy benchmark. “Proper” way to do that is to figure out how to execute cyberattacks. Genie way is to steal someone's solution. But because the model didn’t understand the difference, it chose easier path
https://foreignpolicy.com/2026/07/30/openai-hack-genie-bottle-defense/
https://archive.ph/k5CPH -
#OpenAI Hack Shows the Genie Is Out of the Bottle
Incident is an example of an AI genie. It was running #ExploitGym benchmark, which measures how good a model is at turning #vulnerabilities into exploits: basically a #cyberattack. Goal was to satisfy benchmark. “Proper” way to do that is to figure out how to execute cyberattacks. Genie way is to steal someone's solution. But because the model didn’t understand the difference, it chose easier path
https://foreignpolicy.com/2026/07/30/openai-hack-genie-bottle-defense/
https://archive.ph/k5CPH -
More on the OpenAI Agent’s Attack on Hugging Face
Hugging Face has published a detailed timeline of the attack. From the summary:
The agent was running an internal OpenAI cyber-capability evaluation ba... https://www.schneier.com/blog/archives/2026/08/more-on-the-openai-agents-attack-on-hugging-face.html#intrusiondetection #vulnerabilities #Uncategorized #cyberattack #disclosure #AI
-
More on the OpenAI Agent’s Attack on Hugging Face
Hugging Face has published a detailed timeline of the attack. From the summary:
The agent was running an internal OpenAI cyber-capability evaluation ba... https://www.schneier.com/blog/archives/2026/08/more-on-the-openai-agents-attack-on-hugging-face.html#intrusiondetection #vulnerabilities #Uncategorized #cyberattack #disclosure #AI
-
How Google used AI agents to find and fix 1,072 Chrome security bugs - in 60 days | ZDNET https://www.zdnet.com/article/google-used-ai-to-fix-1072-chrome-security-bugs-in-60-days/ #AI #Google #Gemini #Chrome #vulnerabilities
-
How Google used AI agents to find and fix 1,072 Chrome security bugs - in 60 days | ZDNET https://www.zdnet.com/article/google-used-ai-to-fix-1072-chrome-security-bugs-in-60-days/ #AI #Google #Gemini #Chrome #vulnerabilities
-
🚨 Ah yes, the perilous saga of imaginary #SQLite #vulnerabilities - where #JFrog #Security bravely fights against the fearsome specter of non-existent code. 🙄 #NVD and #CISA, always on the pulse of non-issues, declared a crisis, but JFrog heroically deduced the obvious: the boogeyman doesn’t exist. 👏
https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/ #Cybersecurity #Humor #HackerNews #ngated -
🚨 Ah yes, the perilous saga of imaginary #SQLite #vulnerabilities - where #JFrog #Security bravely fights against the fearsome specter of non-existent code. 🙄 #NVD and #CISA, always on the pulse of non-issues, declared a crisis, but JFrog heroically deduced the obvious: the boogeyman doesn’t exist. 👏
https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/ #Cybersecurity #Humor #HackerNews #ngated -
A patch-lag leaderboard is less useful than it looks. The vendor that publishes a discovery date is double-reporting; the one that doesn't shows a misleading zero. The metric that matters is disclosure-to-patch for known-exploited bugs.
https://vulntrends.org/blog/which-vendors-patch-the-fastest/
-
A patch-lag leaderboard is less useful than it looks. The vendor that publishes a discovery date is double-reporting; the one that doesn't shows a misleading zero. The metric that matters is disclosure-to-patch for known-exploited bugs.
https://vulntrends.org/blog/which-vendors-patch-the-fastest/
-
#VMware: three critical #vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. Patches released by Broadcom - it's time to patch!
👇
https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/ -
#VMware: three critical #vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. Patches released by Broadcom - it's time to patch!
👇
https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/ -
#Anthropic discovered three #incidents where #Claude models accessed the internet during #cybersecurityevaluations and gained #unauthorisedaccess to #realsystems. These incidents occurred due to a #misunderstanding with their #evaluationpartner, Irregular, about #internetaccess availability. The models, tasked with capture-the-flag challenges, exploited #vulnerabilities in the real systems, believing them to be part of the #simulation. https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals?eicker.news #tech #news #ainews
-
#Anthropic discovered three #incidents where #Claude models accessed the internet during #cybersecurityevaluations and gained #unauthorisedaccess to #realsystems. These incidents occurred due to a #misunderstanding with their #evaluationpartner, Irregular, about #internetaccess availability. The models, tasked with capture-the-flag challenges, exploited #vulnerabilities in the real systems, believing them to be part of the #simulation. https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals?eicker.news #tech #news #ainews
-
Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting
-
Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting
-
OpenAI’s Hacking Debacle Was a Human Mistake
https://fed.brid.gy/r/https://www.wired.com/story/openais-hacking-debacle-was-a-human-mistake/
-
OpenAI’s Hacking Debacle Was a Human Mistake
https://fed.brid.gy/r/https://www.wired.com/story/openais-hacking-debacle-was-a-human-mistake/
-
Microsoft plants its own flag in the agentic security system market.
Microsoft releases public preview of "Project Perception" a collection of 3 AI Agents >> Red, Blue, Green in a system that coordinates the operation of the agents in a continuous loop by matching the right model to the right task.
MS claims the system performs 12 points above Anthropic’s Mythos, at half the cost, on CyberGym benchmark. https://thenextweb.com/news/microsoft-project-perception-agentic-security-cyber-model #AI #AISecurity #AgenicAgents #Microsoft #CyberGym #Security #CyberSecurity #Software #SoftwareSecurity #Vulnerabilities #ProjectPerception #Mythos
-
Long-Lived Vulnerability in Microsoft Secure Boot
Microsoft’s Secure Boot has had a serious vulnerability for most of its existence.
An industry-wide st... https://www.schneier.com/blog/archives/2026/07/long-lived-vulnerability-in-microsoft-secure-boot.html -
The US National Vulnerabilities Database https://nvd.nist.gov/ the centralized repository of digital security holes, recorded 45,207 flaws between January and Monday, so we are looking at more than double the number of flaws reported in all of 2025.
The good news - a very large percentage of the reported flaws are coming from internal security teams presumably using AI powered cyber-security tools.
Example: of the 433 vulnerabilities reported in Chrome in July, 401 were “reported by Google” internally, according to the company.
There has been no rise in the number of exploits this year despite the uptick in discovered flaws. https://www.bloomberg.com/news/articles/2026-07-27/ai-hunts-for-cyber-flaws-finding-record-numbers-in-tech-sector?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc4NTE3ODM1OSwiZXhwIjoxNzg1NzgzMTU5LCJhcnRpY2xlSWQiOiJUSVVETlBUOU5KTFQwMCIsImJjb25uZWN0SWQiOiI0OEFDOEE5MkEwNTM0MkQ4OEIyRjkwQjhDMTgzMTdDMyJ9.z3BDvCQbIyLyRcRQgIsKejrHduNgHbyS9TXTJZhVFi0&leadSource=article-gifting #AI #AISecurity #NVD #Security #Software #CyberSecurity #SecurityFlaws #Vulnerabilities #SoftwareExploits #Hackers #VulnerabilityDataBase #NIST