Vulnerabilities
120 articles RSS
Critical Type Confusion Flaw in isolated-vm Node.js Sandbox Let Guest Code Escape to the Host
A type confusion bug in isolated-vm's ExternalCopy let sandboxed JavaScript corrupt host memory, up to control-flow hijack; patched in 7.0.1 and 6.2.0.
Critical Metabase SQL Injection Zero-Day Hits CISA's KEV Catalog After Breaching Framework and n8n
A maximum-severity SQL injection zero-day in Metabase, CVE-2026-72898, gave attackers admin access and was used to breach Framework, n8n, and other customers before landing on CISA's KEV catalog.
GitLab Finds Critical Template-Injection Flaw in Serena, an MCP Coding Agent, Bypassing Its Untrusted-Project Safeguard
A critical Jinja2 template-injection bug let attacker-controlled repository files execute code in the Serena coding agent, bypassing its own trust gate.
Wiz Discloses GitHub Actions Workflow Injection in Snowflake Repo, Exposing a Live Jira API Token
Wiz's autonomous Red Agent found and exploited a GitHub Actions injection flaw in a Snowflake repo that GitHub's own scanner had missed, exfiltrating a live Jira token.
rsync 3.5.0 Fixes 33 CVEs, Including a Critical Proxy-Spoofing Flaw, as Outside Researchers Join the Project's Admin Team
rsync 3.5.0, released August 13, patches 33 CVEs found through an audit, fuzzing, and outside researchers, following the disruptive May 3.4.3 security release.
Gitea Patches Critical Unauthenticated File-Read Flaw CVE-2026-59774 Found by an Autonomous AI Pentesting System
A CVSS 9.8 Gitea flaw let unauthenticated users read server files via Org-mode markup; XBOW Security's autonomous system found it.
Security Researcher Publishes Windows Defender 'ShieldBreak' Zero-Day, Says Microsoft Threatened Legal Action
A researcher known as Nightmare Eclipse disclosed an unpatched Windows Defender privilege-escalation flaw, saying Microsoft's legal threats left public disclosure as the only option.
Mozilla Rotates Firefox and Thunderbird GPG Signing Key After Accidental GitHub Exposure
Mozilla revoked and replaced a GPG signing subkey after an unencrypted copy leaked into a private GitHub repo, finding no evidence of unauthorized use.
Varonis Discloses RovoBlast, a One-Click Prompt Injection Flaw in Atlassian's Rovo AI Assistant
A crafted link could seed attacker instructions into a user's Rovo session, letting the assistant's browsing agent exfiltrate Jira and Confluence data.
Novee Security Finds Zero-Privilege Flaws in Claude Code, Gemini CLI, and Codex Around Black Hat USA 2026
Researcher Elad Meged showed a privilege-less GitHub issue could reach CI secrets in Claude Code, Gemini CLI, and Codex; two flaws got CVEs, one didn't.
Unpatched GeoServer Zero-Day Sees Active Exploitation Within Hours of Public Disclosure
An unpatched SQL injection flaw in GeoServer's jsonArrayContains function is already being probed by attackers, watchTowr says, with no CVE or fix yet available.
OpenAI Open-Sources Codex Security CLI, Leaving the Scanner Behind a Gate
OpenAI released the command-line tool and SDK for Codex Security, formerly Aardvark, under Apache-2.0, while the underlying scanner stays limited-beta.