Researchers flagged exploitable flaws in Microsoft’s passkey handling, a reminder that passwordless systems still depend on careful implementation, especially around privileged access.
A high-severity warning on some ASUS drivers shows how a trusted software layer can become a privilege-escalation path when its permissions are too broad and its checks are too thin.
Version 4.6.7 closes 12 security flaws, underscoring how a trusted network analyzer can become fragile when it ingests hostile traffic or capture files.
A multi-model agentic scanning harness is designed to find Windows flaws earlier, yet the security gain depends on validation, triage, and the patch pipeline behind it.
A wide 2026.1.2 patch cycle for Foxit Reader and Editor shows how parsing bugs, scripts, and rich media can turn routine PDFs into serious endpoint risk.
Two ModSecurity flaws underline a stubborn truth in web security: if request parsing drifts out of sync, even a well-tuned firewall can miss what the application will later accept.
A cluster of fixed flaws in Fluentd shows how a logging hub can become a pivot point for code execution, internal probing, disruption, and sensitive-data leakage.
A new security notice around Apache NiFi puts the spotlight on control-plane weaknesses, where a single authorization lapse can matter as much as a code bug in the data path.
Nine vulnerabilities in the X.Org X server and Xwayland show how a compatibility layer can still carry meaningful risk for availability and privilege boundaries.
A weekly security roundup points to three pressure points at once: Linux, PAN-OS, and identity abuse, with AI now helping attackers move faster.
Microsoft began rolling out fixes for two Microsoft Defender flaws after they were reportedly exploited before a public patch was broadly available.
A cluster of vulnerabilities in the file-sync staple shows why exposure is shaped less by product name than by the way the service is deployed.
Una divulgación del 8 de mayo vinculada a cPanel, WHM y WP Squared muestra cómo pequeños errores en la lógica de control del alojamiento pueden crear un riesgo desproporcionado cuando el código vulnerable se sitúa cerca de la administración del servidor.
Recent discoveries reveal that popular messaging app WhatsApp harbors security flaws leaving users open to code execution and malicious redirects.
A high-profile AI disaster at PocketOS exposes dangerous gaps in security guardrails and infrastructure controls.
Mozilla’s latest Firefox update patches a wave of high-risk vulnerabilities, spotlighting the escalating cyber arms race between browser makers and attackers.
Mozilla’s latest browser update tackles a wave of critical code execution vulnerabilities-here’s how AI and researchers joined forces to avert disaster.