A fresh warning about exploited flaws in two Joomla extensions shows how the quietest part of a website can become the most dangerous one.
CISA’s KEV listing for iCagenda and Balbooa Forms underscores a hard lesson for site operators: third-party extensions can turn a routine form or attachment feature into a code-execution path.
Researchers demonstrated a naming attack against AI assistants that can move from hallucinated lookups to remote code execution and, in some cases, malware delivery.
A new research warning points to a dangerous pattern in agentic security tools: if untrusted content can steer the agent, the defender itself may become an execution path.
Several vulnerabilities have been resolved in PAN-OS and Prisma Access, and the technical lesson is clear: exposure depends on the exact branch, deployment model, and fix path, not just the product name.
Critical fixes for Foxit PDF Reader and Foxit PDF Editor highlight a familiar risk in document software: a malformed file can push a use-after-free bug toward remote code execution if the vulnerable path is reached.
A critical flaw in HP’s Linux imaging and printing stack shows how a routine print path can become a route to privilege escalation or code execution.
Reported exploitation of known WordPress plugin vulnerabilities is being used to reach remote code execution and drop webshells for persistent access.
A claimed prompt-injection path against Claude Desktop highlights a bigger problem: persistent AI preferences and local tool access can turn a chatbot into an attacker-directed control surface.
A newly disclosed use-after-free issue in Microsoft Edge raises remote code execution risk and again turns browser patching into a race against exposure.
A reported flaw in Gemini Live puts the spotlight on a fragile boundary in real-time AI: who gets to shape session setup, and what happens if that trust is misplaced.
Microsoft’s Chromium-based Edge has a high-severity use-after-free bug, and the real risk is not the label but the time it takes organizations to move vulnerable builds off their endpoints.
A reported attack chain tied to a Langflow flaw shows how an exposed AI orchestration service can become a fast path to credentials, databases, and configuration destruction.
A May Microsoft fix has already become a live defensive problem, with public vulnerability records pointing to a high-severity SharePoint server flaw now under attack.
A ransomware case tied to Langflow shows how a single exposed agent platform can become both the foothold and the vault, with destructive database access following close behind.
Two critical Cursor IDE flaws show how prompt-driven coding tools can turn path handling mistakes into non-sandboxed code execution.
Adobe’s June security updates for Campaign Classic and ColdFusion close high-risk holes in software that can sit close to web traffic, customer workflows, and administrative access.
Version 1.19.3 closes a critical remote code execution flaw and three high-severity bugs, underscoring how a logging collector can become a sensitive part of the attack surface.
A cluster of fixed flaws in Fluentd shows how a logging hub can become a pivot point for code execution, internal probing, disruption, and sensitive-data leakage.
Seven high-severity bugs in ColdFusion and one critical Campaign Classic flaw turned a routine patch note into a reminder that business platforms can become attack paths overnight.