#bug


Google halts open-source bug bounty program amid AI spam surge

Oct 5, 2026 // 12:37

Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. The company’s OSS VRP […]

D-Link warns of max severity zero-day bug in DIR-822A routers

Sep 22, 2026 // 15:56

D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers. This security […]

Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts

Sep 19, 2026 // 00:02

Microsoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates. In a Windows release […]

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

Sep 18, 2026 // 12:20

A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm […]

Google warns of new Chrome zero-day bug exploited in attacks

Sep 9, 2026 // 15:37

Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. […]

Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC

Sep 8, 2026 // 17:59

Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin’s public record shows. About […]

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

Sep 7, 2026 // 14:22

A TantoSec proof-of-concept turns an AES-CBC “padding oracle” in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in […]

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

Aug 20, 2026 // 17:57

A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. Identified as […]

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

Aug 5, 2026 // 19:08

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: […]

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

Aug 5, 2026 // 19:06

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: […]

1 2 3 … 5 Next