#Vulnerability

Every story tagged Vulnerability, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

38 stories · open in the command center

  • Security & PrivacyVulners1m

    CVE-2026-18806: External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-im... (CVSS 7.1)

    CVE-2026-18806 is a high-severity (CVSS 7.1) path traversal vulnerability in pardus-image-writer that allows local users with low privileges to remove critical client functionality, requiring immediate patching to versions 1.0.4 or later across all affected systems. This vulnerability poses a significant operational risk as it enables privilege escalation and service disruption through file system manipulation, necessitating urgent inventory review and rapid deployment of security updates. IT organizations must assess the blast radius of this vulnerability in their infrastructure and prioritize remediation to prevent potential data integrity issues and system availability impacts.

  • Security & PrivacyVulners1m

    CVE-2026-68494: The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint byp... (CVSS 8.7)

    CVE-2026-68494 is a critical denial-of-service vulnerability in Jackson Core (CVSS 8.7) that allows attackers to exhaust JVM heap memory through incomplete number length validation in non-blocking parsers used by reactive frameworks like Spring WebFlux, Quarkus, and Vert.x. Organizations using affected versions (2.15.0-2.18.7, 2.19.0-2.21.3, 2.22.0, and 3.0.0-3.2.0) face heap exhaustion risks when parsing untrusted JSON streams, as attackers can amplify memory consumption by ~20,000x over documented limits through chunked input without terminator bytes. IT organizations must immediately audit reactive Java applications for vulnerable Jackson versions and prioritize upgrades to patched releases to prevent production outages.

  • Security & PrivacyVulners1m

    CVE-2026-25292: Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration... (CVSS 7.6)

    CVE-2026-25292 is a HIGH severity memory corruption vulnerability (CVSS 7.6) affecting multiple Qualcomm Snapdragon platforms across automotive, mobile, IoT, and wearable devices through the fastboot audio framework command handler. This vulnerability could allow attackers with physical access to execute arbitrary code with complete system compromise (confidentiality, integrity, and availability impact). IT organizations must immediately inventory affected Snapdragon devices across their infrastructure and apply vendor patches to mitigate the risk of device compromise and potential lateral movement into enterprise networks.

  • Security & PrivacyVulners1m

    CVE-2026-67311: Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fail... (CVSS 8.2)

    CVE-2026-67311 is a high-severity SSRF vulnerability (CVSS 8.2) in Budibase versions before 3.38.1 that allows authenticated Builder-role users to bypass IP blacklist protections and access internal services and cloud metadata endpoints through malicious HTTP redirects. This vulnerability poses significant risk to organizations using Budibase for data integration, potentially enabling attackers with platform access to exfiltrate sensitive infrastructure information and compromise internal systems. IT organizations must immediately assess their Budibase deployments and implement strict access controls on Builder role assignments while planning urgent upgrades to version 3.38.1 or later.

  • Security & PrivacyVulners1m

    CVE-2026-54662: CVE-2026-54662 swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template (CVSS 8.3)

    swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfig copies servers[0].url into apiConfig.baseUrl, and templates/base/http-clients/fetch-http-client.ejs interpolates apiConfig.baseUrl into the generated HttpClient baseUrl field without escaping, allowing an attacker-controlled OpenAPI spec to inject TypeScript static field code that executes when the generated fetch client module is imported. This issue is fixed in version 13.12.2.

  • Security & PrivacyHacker News3m

    Document-borne AI worms can self-propagate through Copilot for Word

    AI-powered malicious instructions embedded in documents can self-propagate through Microsoft Copilot for Word, turning ordinary business documents into unwitting attack vectors that spread across trusted workflows without requiring the original malicious document. This represents a critical supply-chain risk where compromised source materials used in Copilot-assisted drafting can corrupt downstream documents and perpetuate the attack across organizational networks. IT leaders must immediately reassess document handling practices and AI tool governance, as no robust vendor-side mitigation currently exists and the vulnerability affects mainstream productivity suites already embedded in enterprise workflows.

  • Security & PrivacyVulners1m

    CVE-2026-59931: PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t... (CVSS 7.7)

    PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the WEBSERVICE() domain whitelist can be bypassed via an HTTP redirect (SSRF). In Calculation/Web/Service.php, the webService() method validates a URL's host against the whitelist set via Spreadsheet::setDomainWhiteList(), then fetches content with file_get_contents($url, false, $ctx); because PHP's HTTP stream wrapper follows 301/302 redirects automatically (up to 20 hops) and the redirect target is never re-validated, an attacker who can trigger a redirect from a whitelisted domain can reach arbitrary URLs, including internal addresses. An attacker able to upload XLSX files to an application that uses setDomainWhiteList() and getCalculatedValue() can achieve a full-read SSRF, returning up to 32,767 bytes of the response body as a cell's calculated value, which e...

  • Security & PrivacyVulners1m

    CVE-2026-59933: PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t... (CVSS 7.5)

    PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the OLE reader follows sector chains from attacker-controlled XLS/OLE metadata without detecting cycles or enforcing a maximum chain length. A tiny malformed .xls/OLE file can set the small-block depot sector chain to point back to itself. During normal XLS detection, OLERead::read() appends the same sector data repeatedly until the PHP process exhausts memory. This is reachable from Reader\Xls::canRead() and therefore from automatic spreadsheet type detection. Applications that accept attacker-controlled spreadsheet uploads can suffer denial of service from a very small file. This issue has been fixed in versions 5.8.1, 3.10.7, 2.4.7, 2.1.18 and 1.30.6.

  • Security & PrivacyAndroid PoliceChandra Steele2m

    Forget your PIN? Samsung’s One UI 9 update could factory reset your phone

    Samsung's One UI 9 update introduces a stricter lockscreen security policy that triggers a permanent factory reset after 13 failed PIN/password attempts, significantly reducing user tolerance for input errors and increasing data loss risk across enterprise and consumer Galaxy devices. This security hardening measure—designed to prevent unauthorized access and data breaches—creates operational challenges for IT organizations managing device deployments and support, requiring enhanced user communication, backup protocols, and potentially increased help desk volume for account recovery scenarios. Technology leaders must evaluate the business impact on their Samsung device fleet, implement mandatory backup strategies, and prepare support teams for increased authentication-related incidents.

  • Security & PrivacyVentureBeatlouiswcolumbus@gmail.com9m

    New ransomware targets AI model weights and can't even collect the ransom

    A sophisticated ransomware variant called ENCFORGE is specifically targeting AI model weights and training data—assets that cannot be quickly restored from backups—with recovery costs estimated at $75,000-$500,000 per model, representing a material business risk that traditional cybersecurity frameworks fail to address. The attacker exploits unpatched vulnerabilities (CVE-2025-3248) to gain persistence, demonstrating adaptive attack capabilities that can pivot strategies in minutes when initial approaches fail, indicating a shift toward lower-cost initial compromise followed by opportunistic lateral movement. This threat demands IT organizations align security investments with quantifiable business impact on AI assets rather than treating it as a purely technical cybersecurity issue, requiring new backup and recovery strategies specifically designed for machine learning infrastructure.

  • Security & PrivacyTechMemeJoseph Cox2m

    Apple says it fixed a vulnerability in its Hide My Email tool that let anyone see a user's real email address; researchers first reported the issue in June 2025 (Joseph Cox/404 Media)

    Apple disclosed a year-long vulnerability in its Hide My Email privacy feature that exposed users' real email addresses to potential attackers, representing a significant breach of user trust and privacy commitments that could impact customer confidence across Apple's ecosystem. This incident highlights critical risks in privacy-centric security features and underscores the importance of rapid vulnerability disclosure and remediation timelines, requiring IT leaders to reassess their own privacy tool implementations and incident response protocols. Organizations relying on Apple services for user privacy should audit their email masking dependencies and review vendor security disclosure practices as part of their overall risk management strategy.

  • Security & PrivacyWiredAndy Greenberg2m

    A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now

    Over 2 million US vehicles contain a vulnerable third-party aftermarket alarm system (KARR Security System) installed by dealers without owner awareness, exposing them to remote hacking attacks including vehicle unlocking, ignition disable, and tracking. This supply chain vulnerability represents a critical IT risk management challenge as organizations cannot rely on primary manufacturers for patching and affected parties are largely unaware of the threat. IT leaders should recognize this as a systemic problem affecting connected device ecosystems and strengthen vendor management protocols to identify and mitigate hidden third-party vulnerabilities in mission-critical systems.

  • Security & PrivacyHacker News3m

    Potential session/cache leakage between workspace instances or consumer accounts

    A critical security vulnerability has been identified where session data and cached information may leak between separate workspace instances or consumer accounts in Claude Code, potentially exposing sensitive enterprise data to unauthorized access. This represents a significant risk to organizations using Enterprise ZDR workspaces, as confidential chat sessions and proprietary information could be inadvertently shared across user sessions. IT leaders must treat this as a high-priority security incident that requires immediate investigation, potential credential rotation, and a comprehensive audit of session isolation mechanisms.

  • Security & PrivacyHacker News3m

    MSI Center – How to gain SYSTEM privileges in seconds

    A critical privilege escalation vulnerability in MSI Center (preinstalled on MSI laptops and desktops) allows any authenticated user to gain SYSTEM-level access within seconds by exploiting a named pipe service with weak encryption, potentially enabling malware to disable security controls and compromise entire fleets of MSI devices. This widespread vulnerability affects an estimated large user base and demonstrates a systemic risk in OEM software supply chains, requiring IT organizations to immediately audit their device inventory and implement compensating controls. The incident also highlights the need for organizations to establish vendor communication protocols and security update enforcement mechanisms, as MSI's vulnerability disclosure process failures nearly prevented the patch from being delivered.

  • Security & PrivacyHacker News3m

    Elevating Privileges from Firefox to Android Root

    Security researchers have demonstrated a critical full-chain remote code execution vulnerability affecting Android 17 that escalates from browser-level privileges (Firefox) to kernel root access, representing a severe supply chain and endpoint security risk for organizations deploying Android devices at scale. This exploit highlights a fundamental architectural weakness in Android's privilege isolation mechanisms and underscores the urgent need for IT organizations to implement enhanced mobile device management, kernel patching protocols, and browser sandboxing controls across their enterprise Android ecosystems. The public disclosure timeline and open-source availability of exploit code materially increases the threat surface for unpatched devices and demands immediate vulnerability assessment and mitigation strategies from security and infrastructure teams.

  • Security & Privacy9to5MacBen Lovejoy2m

    Three AirDrop vulnerabilities discovered, with Apple working on a full fix

    Three AirDrop vulnerabilities have been discovered that allow proximity attackers to remotely disable critical Apple services (AirDrop, AirPlay, Handoff, Universal Clipboard, and Continuity Camera) with a simple request loop, requiring no authentication or user interaction on devices set to "Everyone" mode. While no data theft is possible, the attack reflects a systemic engineering challenge in pre-authentication proximity protocols that also affect Android's Quick Share, creating a persistent denial-of-service risk for enterprise environments relying on Apple's Continuity features. Apple has patched one vulnerability with two others still in coordinated disclosure, necessitating immediate security updates and a review of enterprise configurations once patches are released.

  • Security & PrivacyHacker News3m

    Show HN: Exploiting Slack's video embeds to achieve E2EE communication

    A security researcher demonstrated a method to achieve end-to-end encryption within Slack by exploiting the video embed feature to execute client-side cryptographic operations, revealing a potential gap in Slack's platform security model. This highlights the risk of unintended feature misuse in enterprise communication platforms and raises questions about the security implications of embedded iframe capabilities. IT organizations should assess their Slack deployment configurations and consider whether additional governance controls are needed around third-party app permissions and embedded content handling.

  • Security & PrivacyHacker News3m

    Fooling Go's X.509 Certificate Verification

    A critical vulnerability exists in Go's X.509 certificate verification implementation where certificates with identical content but different ASN.1 encoding (specifically using tag 0x13 instead of 0x0c for string encoding) can bypass verification checks, while other standard tools like OpenSSL correctly validate them. This represents a significant security risk for Go applications relying on certificate validation for TLS, API authentication, and other cryptographic trust mechanisms. IT organizations must urgently audit Go-based systems handling certificate verification and prepare for patching once the Go team releases a fix.

  • Security & PrivacyHacker News3m

    Hacking your PC using your speaker without ever touching it

    A critical vulnerability has been discovered in Creative Sound Blaster Katana V2X speakers that allows attackers within 15 meters to remotely compromise PCs through Bluetooth without pairing or physical access, exploiting the exposure of a static authentication key and lack of firmware signature verification. This represents a significant supply chain risk for organizations with consumer IoT devices connected to corporate networks, as affected speakers can be weaponized as remote code execution vectors and surveillance tools. IT leaders must immediately audit connected audio devices in their environments, implement network segmentation for IoT/consumer devices, and establish policies restricting firmware update mechanisms to prevent similar vulnerabilities from being exploited.

  • Security & PrivacyWiredDan Goodin, Ars Technica2m

    Websites Can Now Spy on You Through Your Hard Drive

    A new browser-based attack called FROST exploits SSD timing side channels to allow websites to covertly identify other websites and applications active on a user's device, significantly expanding the attack surface of modern web browsers. This emerging threat requires IT organizations to reassess their endpoint security strategies and browser sandboxing assumptions, as traditional isolation boundaries prove insufficient against this class of physical-layer attacks. Organizations must work with browser vendors on mitigations such as OPFS file size limits while implementing detection mechanisms and endpoint monitoring to identify suspicious large file allocations.

  • Security & PrivacyHacker News3m

    BadHost – CVE-2026-48710: Starlette Host-Header Auth Bypass

    CVE-2026-48710 is a critical authentication bypass vulnerability affecting thousands of FastAPI and Starlette applications—including widely-used AI infrastructure like vLLM, LiteLLM, and MCP servers—that exploits unsanitized Host headers to circumvent path-based authentication middleware. This cross-layer vulnerability exposes model access, API keys, and internal tooling, with particular risk in AI/ML deployments and self-hosted instances running ASGI servers without reverse proxy protection. IT organizations must immediately patch to Starlette 1.0.1+, audit custom authentication middleware, and implement architectural controls such as endpoint-level security decorators and RFC-compliant reverse proxies.

  • Security & PrivacyHacker News3m

    New Nginx Exploit

    A critical remote code execution vulnerability (CVE-2026-42945) affecting NGINX versions 0.6.27-1.30.0 has been publicly disclosed with a working exploit, enabling unauthenticated attackers to execute arbitrary code on servers using rewrite and set directives. This represents an immediate and severe risk to any organization running vulnerable NGINX instances, potentially compromising web infrastructure, data, and backend systems. IT organizations must prioritize immediate patching to versions 1.31.0, 1.30.1, or appropriate NGINX Plus patch levels to prevent exploitation.

  • Security & PrivacyHacker News3m

    Mythos Finds a Curl Vulnerability

    Anthropic's Mythos AI model, designed to identify security vulnerabilities in source code, found only one confirmed vulnerability in the curl library after analysis—demonstrating that even advanced AI security tools have limitations when applied to mature, heavily-audited codebases. This finding suggests that while AI-powered security scanning is a valuable complementary tool for identifying bugs, it cannot replace comprehensive human security reviews, traditional static analysis, and established security practices that remain essential for enterprise software integrity.

  • Security & PrivacyHacker News3m

    Podman rootless containers and the Copy Fail exploit

    A critical Linux kernel vulnerability (Copy Fail/CVE-2026-31431) enables local privilege escalation within containers, but Podman's rootless container architecture significantly limits the blast radius compared to traditional Docker deployments. While attackers can gain root access within a compromised container, Podman's user namespace isolation and fork/exec model constrain their ability to escalate privileges on the host system, making it a more secure container runtime for IT organizations seeking defense-in-depth strategies.

  • Security & PrivacyHacker News3m

    Microsoft Edge stores all passwords in memory in clear text, even when unused

    Microsoft Edge has a critical security vulnerability where passwords are stored in memory in clear text, creating significant exposure to credential theft even when passwords are not actively being used. This finding has major implications for enterprise security posture, requiring IT organizations to reassess Edge deployment in sensitive environments and evaluate compensating controls or alternative browsers. Organizations relying on Edge for authenticated access to critical systems face increased risk of lateral movement and unauthorized access if systems are compromised.

  • Security & PrivacyHacker News3m

    Credit Cards Are Vulnerable to Brute Force Kind Attacks

    Credit card payment systems remain vulnerable to brute force attacks despite PCI DSS compliance, as attackers can derive full Primary Account Numbers using only publicly visible data (first 6 digits, last 4 digits, expiration date) and the Luhn algorithm, combined with permissive payment gateway response codes that leak validation information. This vulnerability is compounded by merchants implementing only bare-minimum PCI DSS requirements and some payment processors accepting incomplete card data, creating a significant fraud risk that extends beyond traditional account compromise scenarios. IT and security leaders must recognize that current industry compliance standards do not guarantee adequate protection and should implement additional controls such as stricter payment validation responses, mandatory CVV requirements, and enhanced fraud detection systems.

  • HardwareThe VergeTom Warren2m

    Your PS5 can now transform into a Linux PC

    A developer has successfully demonstrated a method to run Linux on older PlayStation 5 disc-based consoles, enabling PC games to execute on gaming hardware through a firmware exploit—representing a potential shift in device flexibility and cross-platform capability that IT leaders should monitor for implications around hardware control, support complexity, and emerging attack surfaces. While currently limited to outdated firmware versions and requiring technical expertise to implement, this development signals growing demand for interoperability and raises questions about device management, security policies, and the boundaries between consumer electronics and general-purpose computing that technology organizations may need to address. The lack of persistence and current limitation to legacy systems suggests manageable near-term risks, but the underlying vulnerability patterns warrant security assessment as similar techniques could emerge across enterprise and consumer IT ecosystems.

  • Security & PrivacyHacker News3m

    Patch applies fake diffs from commit messages

    A critical supply chain vulnerability exists where attackers can embed malicious code into Git commit messages that gets executed when patches are downloaded and applied using standard tools like wget/curl with GNU patch, potentially injecting unauthorized files or modifications into codebases without detection in GitHub's UI. This affects common patch distribution workflows across organizations and requires immediate review of patch handling procedures, especially in automated deployment and CI/CD pipelines. IT teams must evaluate whether their patch management practices use vulnerable tool combinations and implement controls to validate patch authenticity and content.

  • Security & PrivacyHacker News3m

    The Woes of Sanitizing SVGs

    Scratch's incremental approach to SVG sanitization has repeatedly failed, with new vulnerability classes discovered every 1-2 years (XSS via scripts, event handlers, HTTP leaks, CSS imports, and library bypasses), demonstrating that patching individual attack vectors is unsustainable and fundamentally flawed. This pattern illustrates a critical architectural risk for any IT organization handling user-generated content: attempting to whitelist safe content rather than eliminating dangerous operations at the source creates an endless vulnerability treadmill that wastes security resources and exposes systems to ongoing breach risk. Technology leaders should recognize this as a cautionary tale about the hidden costs of accepting and parsing untrusted input formats, and evaluate whether similar architectural decisions in their own applications present unacceptable security debt.

  • Security & PrivacyHacker News3m

    Fast16: High-precision software sabotage 5 years before Stuxnet

    Researchers have discovered fast16, a sophisticated cyber sabotage framework from 2005 that predates Stuxnet by five years and represents the earliest known targeted attack on high-precision computing systems used in critical national infrastructure like nuclear and cryptographic research. The framework combines a kernel driver for code injection with a Lua-based service module to selectively corrupt calculations across entire facilities, and was later referenced in NSA's own deconfliction tools, suggesting nation-state involvement in both the original attack and subsequent operations. This finding reveals that advanced persistent threats targeting critical computing workloads have a longer operational history than previously understood, with implications for legacy system vulnerabilities in defense and research organizations.

Browse all tags