PublicCVE

Newsroom

Security reporting and coverage, linked to the vulnerabilities it references.

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
The Hacker News · 2d ago

SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior. "SolarWinds

News
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
The Hacker News · 2d ago

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. "Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote

News
BragJack attacks hijack AI browser agents through malicious extensions
BleepingComputer · 1d ago

BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in bounties and two CVEs. [...]

North Korean WaterPlum hackers infected 30,000 devices worldwide
BleepingComputer · 1d ago

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
BleepingComputer · 1d ago

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The Hacker News · 2d ago

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2025-39682 (CVSS score: 9.8) - An improper check for unusual or exceptional conditions vulnerability in the TLS receive path

News
Viral AI actress' hotline face-scans every caller, watches their mood
BleepingComputer · 2d ago

AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her "Talking Tilly" video call service face-scans every caller for an 18+ age check, senses callers' moods during calls, and shuts down permanently on September 27. We tried it and read the fine print. [...]

Calling viral AI actress Tilly Norwood? Agree to a face scan first
BleepingComputer · 2d ago

AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her "Talking Tilly" video call service face-scans every caller for an 18+ age check, senses callers' moods during calls, and shuts down permanently on September 27. We tried it and read the fine print. [...]

Identity Visibility in 2026: The Foundation of Identity Security
The Hacker News · 1d ago

Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what identity visibility means in IAM, why cloud and multicloud environments complicate it, which capabilities matter in

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
The Hacker News · 2d ago

Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system. This was security research,

Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
The Hacker News · 2d ago

Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
The Hacker News · 2d ago

An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May's supply chain attack on TanStack, in which malicious versions of TanStack's npm packages stole credentials from

Cisco Zero-Day Highlights API Endpoint Authentication Issues
Dark Reading · 2d ago

The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.

News
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
The Hacker News · 2d ago

Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. "Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,"

News
Gyazo server flaw exploited to steal 23.6 million user records
BleepingComputer · 2d ago

The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. [...]

Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
BleepingComputer · 2d ago

An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. [...]

Secure enterprise sharing with access reviews for Microsoft 365
BleepingComputer · 2d ago

Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and remove unnecessary access. [...]

Microsoft Teams will let admins block custom file extensions
BleepingComputer · 2d ago

Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company's security requirements. [...]

Webinar: Which Google Workspace security controls actually matter?
BleepingComputer · 2d ago

Fast-growing companies face countless recommendations for securing Google Workspace, but not every control provides the same value. This webinar examines real-world breaches to explore which security controls matter most, which may be overrated, and where lean security teams should focus their resources. [...]

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
The Hacker News · 2d ago

A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now public, and any machine still running an older kernel should be updated. The flaws

Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts
BleepingComputer · 2d ago

Microsoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates. [...]

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
The Hacker News · 2d ago

WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install. The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
The Hacker News · 2d ago

The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation

New Check Point flaw lets hackers execute code with root privileges
BleepingComputer · 3d ago

Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. [...]

Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
Dark Reading · 2d ago

The new program expands Vectra AI's partner strategy as increasingly complex security environments and the growing use of AI create demand for broader AI expertise, services, and security outcomes.

EY Survey Finds Autonomous AI Implementation Outpaces Oversight
Dark Reading · 2d ago

A new survey of senior AI execs shows that while organizations are rapidly deploying AI and autonomous systems, their process and controls are not keeping pace.

Microsoft fixes broken copy and paste for Excel 2016 users
BleepingComputer · 3d ago

Microsoft has fixed a known issue that causes copy-and-paste failures for some Excel users after installing the September 2026 KB5002914 security update. [...]