The cybersecurity companies patched critical and high-severity vulnerabilities in some of their products.
Hi, what are you looking for?
The cybersecurity companies patched critical and high-severity vulnerabilities in some of their products.
An attacker can create a malicious repository containing a git.exe in the project root, and Cursor executes it automatically.
Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days.
Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products.
The suspects and their companies were previously sanctioned by the United States and its allies.
A critical security defect in the ServiceNow AI platform could allow remote attackers to execute arbitrary code.
The new program stems from an AI-focused Executive Order signed by President Trump on June 2.
The company has rolled out a fix and is restoring access for Storage Zones Controller customers who apply it.
The industrial giants fixed dozens of vulnerabilities across their ICS products, with advisories also released by CISA and VDE CERT.
Public exploit code targeting the Firefox flaws exists, but no in-the-wild exploitation has been observed.
SonicWall SMA1000 zero-day vulnerabilities CVE-2026-15409 and CVE-2026-15410 can be exploited for remote code execution.
Two flaws in Active Directory and SharePoint Server have been exploited as zero-days, and a BitLocker bug was publicly disclosed.
The D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid.
The ColdFusion security defects could allow attackers to execute arbitrary code or elevate their privileges.
The flaws can be exploited for authentication bypass, remote code execution, privilege escalation, and directory traversal.
A ClaudeBleed-linked vulnerability reportedly persists across eight patches, exposing potentially sensitive data to other extensions.
The flaws could allow attackers to access and modify data, and cause system unavailability and request-response desynchronization.
Multiple state-sponsored APTs are compromising poorly secured devices across critical infrastructure sector networks.
UK-based cybersecurity firm Valarian has raised a total of $70 million for its ACRA technology.
A threat actor poisoned several Jscrambler NPM package versions to drop a cross-platform credential stealer.