Tech News
← Home  ·  All topics

Security Vulnerabilities

6 GoKawiil briefs on this topic

Apple patches over 200 security flaws across macOS 27, Tahoe 26.7, Sequoia 15.8

Apple released detailed security changelogs for macOS 27 Golden Gate, macOS Tahoe 26.7, and macOS Sequoia 15.8, collectively addressing more than 200 vulnerabilities. The flaws include bugs that could let attackers execute code with kernel or root privileges, escape the sandbox, bypass Gatekeeper, or trigger remote code execution via Bluetooth, CUPS, and WebDAV.

36,000+ exposed Plex Media Servers still unpatched against known vulnerabilities

Security researchers found more than 36,000 internet-facing Plex Media Server instances that have not applied fixes for previously disclosed security flaws. These unpatched servers remain publicly reachable, leaving them open to exploitation by attackers.

Vibe coding debate intensifies as security flaws surface in AI-generated code

Vibe coding, the practice of using AI language models to write software with minimal manual coding, is drawing scrutiny after Georgia Tech researchers linked dozens of security vulnerabilities directly to AI-generated code in just a three-month sample. Despite these risks, a survey of over 1,100 professional programmers found that 72 percent use AI coding tools daily, with AI-generated or -assisted code making up 42 percent of their codebases and expected to exceed half by next year.

Plex Pushes Emergency Update for Media Server and Desktop App Over Security Flaws

Plex is urging all users to immediately update Plex Media Server to version 1.43.3 and Plex Desktop to version 1.115.0, both released earlier this year, to fix multiple unspecified security vulnerabilities. The company emailed affected customers directly and said CVE identifiers have been requested but not yet published, though the flaws are known to impact Media Server v1.43.2 and earlier.

Curl Defends Its Own CVE Assignment Process Amid Scrutiny

The curl project explains that after becoming a CVE Numbering Authority (CNA) years ago, it now independently issues its own CVE identifiers for security flaws in its codebase, having assigned 57 so far. The maintainers describe a rigorous assessment process that grades each report as LOW, MEDIUM, HIGH, or CRITICAL, and note that some minor issues are deliberately left without a CVE if the risk of exploitation is deemed negligible.

Security researchers flag multiple serious flaws in Omarchy 4.0 Linux distro

A security researcher's report describes Omarchy 4.0, the Linux distribution promoted by DHH, as riddled with basic vulnerabilities, including bash injection triggered by video titles and notifications capable of executing arbitrary commands. The report argues these are not obscure edge cases but well-known classes of input-handling flaws that mature software practices routinely prevent, and suggests some scripts may have been AI-generated without proper review.