Hi, what are you looking for?
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
The first exploitation attempts were observed less than four hours after the authentication bypass was publicly disclosed.
The patch was announced as Broadcom is attending the Pwn2Own hacking competition in Berlin this week.
YellowKey is a BitLocker bypass that requires physical access. GreenPlasma enables elevation of privileges to System.
Microsoft’s MDASH discovered 16 of the Patch Tuesday vulnerabilities, and Palo Alto used Mythos to find dozens of flaws.
New “Sweet Attack” platform uses runtime intelligence and continuous agentic red teaming to identify exploitable attack chains human teams may miss.
CVE-2026-40361 is similar to a vulnerability found a decade ago, BadWinmail, which at the time was dubbed an “enterprise killer”.
Successful exploitation of these flaws could lead to arbitrary code execution and information disclosure.
The two chip giants have published over two dozen advisories describing recently identified security defects.
Fresh security updates resolve critical flaws in Azure, Windows, Dynamics 365, and the SSO Plugin for Jira & Confluence.
While none of the flaws have been exploited in the wild, many of them could lead to arbitrary code execution.
The tech giant has also ported the patch for a recent deleted chats recovery issue to older versions of iOS.
The flaws could allow attackers to inject malicious code, leading to information disclosure and code execution.
Curl’s lead developer says Mythos claims are marketing, but many in the industry believe the results stem from Curl’s robust security.
Rather than scanning code alone, Build Application Firewalls inspect runtime behavior inside the software build pipeline.
Also called Copy Fail 2 and tracked as CVE-2026-43284 and CVE-2026-43500, the exploit was disclosed before a patch was released.
Lax extension permissions and improper trust implementation allow attackers to inject prompts in the Claude Chrome extension.
CVE-2026-6973 is a high-severity vulnerability that allows an attacker who has admin privileges to execute arbitrary code.
The cybersecurity firm has not explicitly accused China of being behind the attack, but the evidence suggests it was.
Mitiga researchers say attackers can silently redirect Claude Code MCP traffic, intercept OAuth tokens, and maintain persistent access to connected SaaS platforms.
The fresh browser update resolves critical-severity integer overflow and use-after-free vulnerabilities.