Tech News
← Home  ·  All topics

Vulnerabilities

21 GoKawiil briefs on this topic

Eclypsium report finds infrastructure management platforms top target for exploited flaws

Eclypsium's September InfraTrust Pulse report logged 158 new security advisories across 17 vendors between August 25 and September 17, covering 1,699 vulnerabilities. Of these, 42 were rated critical, eight scored a maximum 10.0 severity, 71 could be exploited remotely without authentication, and five advisories included flaws later added to CISA's Known Exploited Vulnerabilities catalog. The report singles out a maximum-severity Cisco Secure Firewall Management Center authentication bypass, CVE-2026-20079, which Cisco confirmed on September 9 was being actively exploited, allowing attackers to run commands as root without credentials.

GreyNoise ties Red Heron-linked group to WordPress, ZyXEL exploits hitting 996 devices

GreyNoise's Global Observation Grid detected a Chinese-speaking threat actor exploiting flaws in ZyXEL GS1900 switches and WordPress's wp2shell vulnerabilities to compromise 996 devices and steal over 18,500 records. The group, linked to the Red Heron actor previously tied to a Gitea flaw, breached at least 49 organizations across 29 countries since early June 2026, including an unnamed Western government agency.

CISA mandates federal patch for actively exploited Zyxel GS1900 switch flaw

CISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 series switches, to its Known Exploited Vulnerabilities catalog after confirming active attacks. The flaw allows unauthenticated LAN attackers to run OS commands via crafted HTTP requests, and federal agencies must secure affected devices by Thursday under Binding Operational Directive 26-04. Zyxel issued firmware fixes on June 16 but has not yet updated its advisory to acknowledge exploitation.

Forcepoint Warns AI Agents Can Cause 'Denial of Wallet' Cost Overruns

Forcepoint published research showing how AI applications lacking limits on compute and resource usage can rack up massive, unbudgeted bills, a vulnerability now ranked sixth on OWASP's 2026 Top 10 for LLM Applications. Researcher Jyotika Singh outlined five scenarios, including leaked API credentials being used to flood pay-per-use AI services with requests, driving costs far past expected budgets.

AI-Assisted Bug Hunting Triggers Record Surge in Software Vulnerability Disclosures

Major tech firms including Microsoft, Oracle and Google reported unprecedented numbers of security patches this year, with Microsoft issuing 974 CVE fixes this month alone and Oracle shipping 1,448 patches in July compared to 309 a year earlier. Analysts tracking cve.icu counted 66,401 confirmed vulnerabilities as of this week, nearly double last September's tally, a jump attributed largely to AI tools now used for automated bug discovery.

Apple patches over 200 security flaws across macOS 27, Tahoe 26.7, Sequoia 15.8

Apple released detailed security changelogs for macOS 27 Golden Gate, macOS Tahoe 26.7, and macOS Sequoia 15.8, collectively addressing more than 200 vulnerabilities. The flaws include bugs that could let attackers execute code with kernel or root privileges, escape the sandbox, bypass Gatekeeper, or trigger remote code execution via Bluetooth, CUPS, and WebDAV.

Apple ships macOS Tahoe 26.7 and Sequoia 15.8 with security patches

Alongside its new macOS 27 Golden Gate release, Apple has pushed out macOS Tahoe 26.7 and macOS Sequoia 15.8 as updates for users who haven't moved to the newest OS. Apple describes both as containing important security fixes recommended for all users, though it has not yet published detailed release notes on its security page.

Action1 CTO warns fast patch automation can spread failures as quickly as fixes

Gene Moody, Field CTO at Action1, argues that IT teams face an unsustainable mismatch between the growing volume of software patches and the shrinking time available to test them, forcing many organizations to skip review steps and push updates straight to production. He warns that simply automating patch deployment to go faster does not solve the underlying problem, since automation can propagate a bad update across thousands of endpoints just as quickly as a good one.

Anthropic grants EU cybersecurity agency early access to Mythos 5 AI model

Anthropic has provided the EU's cybersecurity agency with access to its Mythos 5 model, following months of negotiations with the European Commission. The model is capable of detecting vulnerabilities in computer code, a capability that had previously raised national security concerns among officials.

36,000+ exposed Plex Media Servers still unpatched against known vulnerabilities

Security researchers found more than 36,000 internet-facing Plex Media Server instances that have not applied fixes for previously disclosed security flaws. These unpatched servers remain publicly reachable, leaving them open to exploitation by attackers.

Google patches actively exploited Chrome zero-day, seventh this year

Google released security updates fixing 230 vulnerabilities, including a Chrome zero-day flaw that attackers are already exploiting in the wild. This marks the seventh Chrome zero-day patched by Google since the beginning of the year.

Microsoft's September Patch Tuesday Fixes Record 974 Vulnerabilities

Microsoft's September security update addressed 974 unique CVEs, the largest Patch Tuesday release yet, including two zero-day flaws already being actively exploited. Windows accounted for the vast majority of fixes at 723, with Office, SQL, SharePoint and Azure making up the rest, while 13 issues were rated Critical.