CVE Tools

Security news, decoded.

What happened, who is affected, and what to do next. Every story is linked to CVEs and enriched with product, exploitation, and patch context.

RSS
TodayMon, Aug 312 stories
Earlier this weekTue, Jul 28 – Sun, Aug 226 stories
Fri3 d ago
The Hacker News Exploited Langflow knaithe6 min read

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

A Chinese-speaking threat actor leveraged the DeepSeek AI model through the Hermes Agent framework to execute autonomous cyberattacks. Using Telegram for initial instructions, the agent identified vulnerable internet-facing systems and deployed public exploits without further human input. The operation targeted over 460 systems across several high-risk vulnerabilities, including CVE-2026-3055 (NetScaler) and CVE-2026-39987 (Marimo), though only three successful breaches were confirmed. Organizations are urged to apply patches for exposed Langflow, n8n, and Marimo systems, as well as secure customer-managed NetScaler appliances.

Fri4 d ago
SecurityWeek Research Google ai-ml5 min read

Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace

Google has revealed that its recent surge in identifying Chrome vulnerabilities has been significantly boosted by the integration of artificial intelligence tools. This year alone, over 1,800 security flaws have been addressed, including a critical 13-year-old sandbox escape vulnerability tracked as CVE-2026-3545 (CVSS score 9.8). The flaw was discovered using an AI agent harness powered by Gemini and patched in Chrome 145 in early May. It could allow malicious HTML pages to trigger a sandbox escape, potentially exposing local files. Google continues to refine its AI systems for detecting, validating, and even generating patches for security issues, aiming to reduce response times and improve overall browser security.

Fri4 d ago
SecurityWeek Patch JetBrains rce2 min read

Critical Code Execution Vulnerability Patched in TeamCity

JetBrains has addressed a high-severity vulnerability in TeamCity On-Premises that allows unauthenticated attackers to execute arbitrary code remotely. Tracked as CVE-2026-63077 (CVSS score 9.8), the flaw impacts all on-premises editions and could allow access to sensitive data, server tampering, and CI/CD pipeline manipulation. Patches are available in versions 2025.11.7 and 2026.1.3, with a security plugin offered for older versions.

Fri4 d ago
Help Net Security Research PX4 Autopilot ics-ot-iot7 min read

Aviation cyber risk sits on the ground, the blindness sits in the air

Eliran Almong, CEO of Cyviation, highlights that most aviation cyber losses stem from ground operations—such as reservations, MRO IT, and airport systems—rather than airborne threats. Despite the hype around 'hacking a plane,' real risks lie in unsecured data flows and outdated protocols like GNSS jamming, which evade traditional monitoring tools. A critical vulnerability, CVE-2026-1579, was recently disclosed in PX4 Autopilot, allowing attackers to send unsigned commands via MAVLink. This flaw underscores the broader issue of unauthenticated communication channels in aviation systems. Almong emphasizes the need for better visibility into both ground infrastructure and aircraft data chains, advocating for digital twins and rigorous inventory management.

Thu4 d ago
BleepingComputer Patch JetBrains rce3 min read

JetBrains warns of critical TeamCity remote code execution flaw

JetBrains has issued a warning about a severe vulnerability in its TeamCity On-Premises software, which could allow attackers to execute arbitrary code remotely. The flaw, identified as CVE-2026-63077, affects all versions of the on-premises edition and allows unauthorized users with HTTPS access to bypass authentication mechanisms. This could lead to full server compromise, including access to sensitive data and credentials. While no active exploitation has been observed yet, previous TeamCity vulnerabilities have been widely abused by ransomware groups and state-sponsored hackers. JetBrains recommends upgrading to version 2025.11.7 or later, or applying a security patch plugin for older versions.

Thu4 d ago
Ars Technica (Security) Exploited Outlook Web Access (OWA) TA4882 min read

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

Russian state-backed hackers are actively exploiting a high-severity vulnerability in Microsoft's Exchange Server, CVE-2026-42897, to deploy a new browser-based backdoor called OWAReaper. The flaw, a cross-site scripting (XSS) issue, allows attackers to execute malicious JavaScript simply by having users open an email in Outlook Web Access (OWA). Security firm Proofpoint reported that the group, known as TA488 and linked to the Kremlin, uses this method to gain persistent access to unpatched systems and steal sensitive data. Microsoft rated the vulnerability as maximum severity and issued a patch in July.

Thu4 d ago
BleepingComputer Patch vCenter auth-bypass5 min read

VMware fixes three critical flaws allowing auth bypass, VM escapes

Broadcom has issued security updates addressing five vulnerabilities in VMware products, including three critical flaws that enable authentication bypass, remote code execution, and virtual machine escape. The most severe issues—CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876—affect vCenter and ESX systems, with CVSS scores up to 9.8. These flaws could allow unauthenticated attackers to gain unauthorized access or escalate privileges to the host system. Affected products include VMware Cloud Foundation, vSphere Foundation, and Telco Cloud platforms. Broadcom urges immediate patching, noting no workarounds are available and that delays could expose infrastructure to potential attacks.

Thu4 d ago
Rapid7 Blog PoC Active Storage rce4 min read

KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails

A critical vulnerability, CVE-2026-66066, was disclosed in Ruby on Rails on July 29, 2026, impacting applications using the libvips image processing library with Active Storage. This flaw allows unauthenticated attackers to read files accessible by the application process, potentially leading to remote code execution (RCE). The issue affects Rails 7.0 and newer versions where libvips is the default image processor. Affected organizations are urged to update to fixed versions like 7.2.3.2, 8.0.5.1, or 8.1.3.1, along with ensuring libvips is at least version 8.13. Applications using ImageMagick instead of libvips are not impacted.

Thu4 d ago
The Hacker News Roundup xplogs22 phishing21 min read

ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

Google has released a major update for Chrome addressing 370 security flaws, including seven rated critical (CVE-2026-17650 to CVE-2026-17656). These issues were discovered using advanced tools like AddressSanitizer and libFuzzer. Meanwhile, a credential stuffing campaign targeting SonicWall devices has led to unauthorized access across 30 organizations. Attackers used five IP addresses and infrastructure on DigitalOcean to compromise accounts since July 25, 2026. Both developments highlight the ongoing need for timely patching and strong authentication practices.

Thu4 d ago
Help Net Security Exploited Outlook Web Access (OWA) TA4884 min read

Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)

A Russian-affiliated hacking group, Laundry Bear (also known as Void Blizzard or TA488), is actively exploiting a cross-site scripting vulnerability in Microsoft Exchange (CVE-2026-42897) to deploy a sophisticated backdoor called OWAReaper. The exploit targets government and private sector organizations in the U.S. and Europe through seemingly innocuous emails that trigger malicious code when opened. Once activated, the malware steals credentials, grants unauthorized access to mailboxes, and persists across device reimages. Microsoft issued a patch for this flaw in June 2026, but attackers had already been using it as a zero-day since March. Organizations are urged to apply the fix immediately and scan for signs of compromise.

Thu4 d ago
Help Net Security Exploited Secure Firewall Management Center (FMC) network-edge4 min read

Cisco FMC static credentials exploited by attackers (CVE-2026-20316)

Attackers are actively exploiting a static credentials vulnerability (CVE-2026-20316) in Cisco's Secure Firewall Management Center (FMC), according to CISA. This issue allows unauthorized access using default account details, potentially leading to data exposure and privilege escalation. Cisco has issued hotfixes and guidance for detecting signs of compromise. Organizations are urged to update systems and rotate credentials immediately.

Thu4 d ago
Rapid7 Blog Patch vCenter Server cloud4 min read

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

Broadcom has issued a security update addressing two high-severity vulnerabilities in VMware vCenter Server—CVE-2026-59309 and CVE-2026-59310—that could allow unauthenticated attackers to bypass authentication or execute arbitrary code remotely. Both flaws have a CVSSv3.1 score of 9.8 and affect widely used vCenter versions. While no active exploitation has been observed yet, the lack of workarounds makes immediate patching crucial. Affected organizations are advised to apply the fixes detailed in VMSA-2026-0006 without delay.

Thu5 d ago
The Hacker News Exploited AnySign4PC web-app10 min read

Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

South Korean authorities and multiple security firms have revealed a state-sponsored cyber campaign that leveraged hacked domestic websites to exploit vulnerabilities in locally installed financial-security software, including AnySign4PC. The attackers successfully deployed backdoors like SIGNBT and COPPERHEDGE without requiring any user interaction or download prompts. KISA has confirmed that AnySign4PC versions 1.1.4.4 through 1.1.4.6 are vulnerable, with version 1.1.5.0 being the patched release. AhnLab identified two other unnamed financial-security products as targets but did not disclose their specific versions or CVE identifiers. This incident highlights the growing threat of sophisticated, unpatched exploits being actively used against critical infrastructure.

Thu5 d ago
SecurityWeek Exploitation Ruflo ai-ml3 min read

Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms

Researchers at Noma Labs discovered a critical vulnerability in the open-source AI agent orchestration platform Ruflo, tracked as CVE-2026-59726 (CVSS score of 10/10). The flaw stems from an unauthenticated POST /mcp endpoint in the Model Context Protocol (MCP) bridge, allowing attackers to execute arbitrary commands within the container. This could lead to full system compromise, including stealing API keys, spawning rogue agent swarms, and manipulating AI outputs. The issue was fixed in version 3.16.3, with detailed remediation steps provided by the project maintainers.

Thu5 d ago
Patchstack Research web-app7 min read

The WordPress update button isn’t telling the truth anymore

New research reveals that the recent changes to WordPress.org’s update process—designed to improve security—have introduced a critical lag between when patches are made available and when they appear in user dashboards. Despite reducing the delay from 24 to 6 hours, this gap still allows attackers to exploit publicly disclosed vulnerabilities before site owners are notified of an update. The issue affects over 9.9 million installations across 79 plugins, including high-severity fixes rated up to CVSS 10.0. Hosting companies and agencies using automated tools face similar limitations due to reliance on the same delayed API. Patchstack now offers free 30-day protection for hosting partners to close this window immediately.

Thu5 d ago
The Hacker News Exploited Microsoft Outlook Web Access Laundry Bear8 min read

Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

Russian threat actors, identified as Laundry Bear, have been exploiting a patched vulnerability in Microsoft Outlook Web Access (OWA) to maintain unauthorized access to email accounts even after credentials are rotated. The flaw, CVE-2026-42897, is being used to target U.S. and European government agencies and various industries including telecommunications, finance, and aerospace. This attack method allows attackers to deploy a sophisticated JavaScript implant called OWAReaper, which persists across device reboots and credential changes.

Thu5 d ago
The Hacker News Advisory Mobile Robots supply-chain5 min read

FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks

On July 28, the Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List, effectively blocking new models from obtaining the necessary authorization for import, marketing, or sale in the U.S. This decision aims to mitigate cybersecurity risks associated with these technologies. Previously authorized models can still be sold, but future imports will require conditional approval from the FCC or relevant federal agencies like the Department of War or Homeland Security. The move follows two similar actions targeting foreign-made drones and consumer routers earlier this year.

Thu5 d ago
Risky Business News Research ai-ml12 min read

Srsly Risky Biz: Chipping Away at Chinese AI Risks

The Trump administration is addressing dual AI-related risks from China: national security threats and global access to powerful hacking tools. A proposed bill aims to help U.S. AI companies combat Chinese espionage through shared information without violating antitrust laws. Meanwhile, a coordinated cyberattack on Minnesota water systems has raised concerns about Iranian state-backed hackers targeting critical infrastructure. Security firm Tenable linked the attack pattern to CyberAv3ngers, an IRGC-associated group. Although no formal attribution exists, the timing aligns with recent U.S. warnings about increased Iranian cyber activity.

Thu5 d ago
SecurityWeek Exploited Cisco Secure Firewall Management Center (FMC) Software network-edge2 min read

Cisco Secure FMC Zero-Day Exploited in the Wild

Cisco has issued patches for a zero-day vulnerability in its Secure Firewall Management Center (FMC) software that is currently being exploited in real-world attacks. The flaw, identified as CVE-2026-20316, involves hardcoded default credentials for a low-privilege user account, enabling attackers to gain unauthorized access and retrieve sensitive data. Cisco labeled the issue 'high severity' and warned that it could be combined with other vulnerabilities to escalate privileges. Organizations are urged to apply updates immediately to mitigate risks.

Thu5 d ago
Help Net Security Research ai-ml8 min read

200 new CVEs a day and no realistic way to patch them all

Ryan Dewhurst, CEO of KEVIntel, outlines how his team detects exploited vulnerabilities that have not yet been included in CISA’s catalog. Using a global honeypot network, AI triage, and manual verification, the company has identified over a thousand known exploited vulnerabilities (KEVs) not present in official records. The research highlights challenges faced by organizations in managing the growing volume of daily CVEs—now averaging 200 per day—and emphasizes the importance of prioritizing high-risk exploits. Dewhurst also warns about misleading AI-generated proof-of-concept code and the limitations of relying solely on CISA’s guidance for private-sector security decisions.