Category desk

Vulnerabilities & CVEs

011 dispatches on file

Breaking

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that

The Hacker News·22 min ago·Vulnerabilities & CVEs·Critical·CVE-2026-16232

Root Evidence puts real-world evidence at the center of vulnerability prioritization

Root Evidence has launched the Evidence Platform, a vulnerability management platform that prioritizes vulnerabilities based on evidence of real-world exploitation and financial impact rather than severity scores alone. The platform is designed to help security teams focus on the vulnerabilities most likely to contribute to ransomware, business disruption, and financial loss. “The cybersecurity industry has become exceptionally good at finding vulnerabilities, but it has not become significantly better at preventing financial loss,” said Jeremiah Grossman, … More → The post Root Evidence puts real-world evidence at the center of vulnerability prioritization appeared first on Help Net Security .

Help Net Security·1 hr ago·Vulnerabilities & CVEs·Notable
Breaking

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The

The Hacker News·2 hr ago·Vulnerabilities & CVEs·Critical·CVE-2026-60004

Apple Patches Everything (July 2026), (Wed, Jul 29th)

I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions (14 and 15), while other operating system patches only covered the current 26 versions. A total of 187 vulnerabilities are addressed in this update. Many cover multiple operating systems. Apple did not label any of the vulnerabilities as already being exploited. Three vulnerabilities that caught my interest are CVE-2026-28849, CVE-2026-28900, and CVE-2026-28914. These issues appear to be the vulnerability described in https://mysk.blog/2026/07/23/macos-overwrite-app-executables/ earlier this week. But I have not seen a confirmation that this is the same issue. Other than th

SANS ISC·2 hr ago·Vulnerabilities & CVEs·High·CVE-2026-28849

OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach

OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's production environment, and also hacked multiple third-party accounts and services as part of the attack. The latest disclosure shows that the security incident, which stemmed from an internal security test, was more extensive in scope than

The Hacker News·3 hr ago·Vulnerabilities & CVEs·High

Specter: Open-source NFC reader bug sweep for Flipper Zero

Specter is a Flipper Zero app that finds powered NFC readers by listening for the radio field they give off. The readers it hunts work at 13.56 MHz. The Flipper’s own chip does the sensing The onboard ST25R3916 carries a hardware external-field detector, the same circuit that lets the device emulate a card and register when a reader starts talking to it. Specter reads that one bit, hundreds of times a second, with its own … More → The post Specter: Open-source NFC reader bug sweep for Flipper Zero appeared first on Help Net Security .

Help Net Security·4 hr ago·Vulnerabilities & CVEs·Notable