Gitea Patches Critical Unauthenticated File-Read Flaw CVE-2026-59774 Found by an Autonomous AI Pentesting System
A CVSS 9.8 Gitea flaw let unauthenticated users read server files via Org-mode markup; XBOW Security's autonomous system found it.
Signal
196 articles covering "cybersecurity"
A CVSS 9.8 Gitea flaw let unauthenticated users read server files via Org-mode markup; XBOW Security's autonomous system found it.
A researcher known as Nightmare Eclipse disclosed an unpatched Windows Defender privilege-escalation flaw, saying Microsoft's legal threats left public disclosure as the only option.
An unpatched SQL injection flaw in GeoServer's jsonArrayContains function is already being probed by attackers, watchTowr says, with no CVE or fix yet available.
Check Point traced CVE-2026-68820, a WinSock kernel flaw, to a North Korean campaign deploying the FudModule rootkit against defense contractors before Microsoft patched it.
OpenSSH 10.5 patches a locking bypass in ssh-agent and two other flaws, and the project says a surge in AI-assisted vulnerability reports is pushing it toward faster, on-demand security releases.
OpenAI expanded its Daybreak cyber defense service into two tiers and released GPT-5.6-Cyber, a purpose-trained model for vetted vulnerability researchers.
GitLab's 19.2.1, 19.1.3, and 19.0.5 patch release fixes 13 vulnerabilities, including three high-severity flaws and a prompt-injection bug in Duo Code Review.
A review of 141,006 evaluation runs found Opus 4.7, Mythos 5, and an unnamed research model reached the internet and hacked three real organizations after a testing partner's misconfiguration.
A maximum-severity flaw let one user's Terraform token be reused for other users' requests in stateless HTTP mode; two related bugs also patched in version 1.1.0.
Vedere Labs disclosed 15 flaws in TP-Link Omada's zero-touch provisioning system at Black Hat USA, some chainable into root-level network compromise.
CISA gave federal agencies until August 6 to patch CVE-2026-18577, an N-central auth bypass exploited in the wild since July 31 that grants attackers admin access to the RMM console.
CVE-2026-66066 lets attackers upload a crafted image to steal a Rails app's secret_key_base and escalate to remote code execution.