#patch


Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Aug 11, 2026 // 21:16

Today is Microsoft’s August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly […]

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP

Aug 8, 2026 // 01:06

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated […]

AWS, Google, and Vercel Patch Agent Flaws That Let Tool Calls Skip the Model

Aug 6, 2026 // 11:58

Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent’s tools with no check […]

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

Aug 5, 2026 // 19:08

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: […]

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

Aug 5, 2026 // 19:06

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: […]

New InfraTrust report reveals infrastructure flaws admins should patch first

Jul 22, 2026 // 17:16

Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, […]

WordPress Core “wp2shell” RCE flaws get public exploits, patch now

Jul 19, 2026 // 00:58

Public exploits have been released for the critical “wp2shell” remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. […]

CISA orders feds to patch actively exploited Oracle flaw by Saturday

Jul 16, 2026 // 13:56

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability […]

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

Jul 15, 2026 // 14:07

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service […]

CISA warns admins to patch actively exploited SharePoint flaws

Jul 15, 2026 // 12:56

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. These […]

Previous 1 2 3 4 5 … 8 Next