Hi, what are you looking for?
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
To deploy AI tools securely and ethically, teams must balance innovation with accountability—establishing strong governance, upskilling developers, and enforcing rigorous code reviews.
The two bugs are high-severity type confusion and inappropriate implementation issues in the browser’s V8 JavaScript engine.
Broadcom has updated its advisory on CVE-2025-41244 to mention the vulnerability’s in-the-wild exploitation.
The critical-severity flaw allows attackers to smuggle HTTP requests and access sensitive data, modify server files, or cause DoS conditions.
Roughly 9 million exploit attempts were observed this month as mass exploitation of the critical vulnerabilities recommenced.
The threat actor behind Operation ForumTroll used the same toolset typically employed in Dante spyware attacks.
WhatsApp told SecurityWeek that the two low-impact vulnerabilities cannot be used for arbitrary code execution.
Researchers have discovered that a prompt can be disguised as an url, and accepted by Atlas as an url in the omnibox.
CVE-2025-59287 allows a remote, unauthenticated attacker to execute arbitrary code and a PoC exploit is available.
Questions have been raised over the technical viability of the purported WhatsApp exploit, but the researcher says he wants to keep his identity private.
As AI coding tools flood enterprises with functional but flawed software, researchers urge embedding security checks directly into the AI workflow.
Patched in September, the SessionReaper bug could be exploited without authentication to bypass a security feature.
The vulnerabilities allow attackers to predict source ports and query IDs BIND will use, and to inject forged records into the cache.
The bug has been exploited in the wild as a zero-day and the US cybersecurity agency CISA has added it to its KEV catalog.
The vulnerability impacts multiple Rust tar parsers, allowing attackers to smuggle additional archive entries.
The Critical Patch Update contains 374 new security patches that resolve many vulnerabilities.
Participants exploited 34 previously unknown vulnerabilities to hack printers, NAS devices, and smart home products.
Leading to code execution, authentication bypass, and privilege escalation, the flaws were added to CISA’s KEV list.
Affecting the Fireware OS iked process, the vulnerability can lead to remote code execution and does not require authentication.
The cybersecurity agency has added CVE-2025-61884 to its Known Exploited Vulnerabilities (KEV) catalog.