MikeTrendsTrends right now

search

CVE

Trends

  1. 1
    Guide released for AndroidX Security State 1.1.0โ—A practical guide to AndroidX Security State 1.1.0, device security patch visibility, pending updates, CVE verification,MmastodonTechnologyMobile246 min ago

    A new practical guide covers AndroidX Security State 1.1.0, explaining how Android developers can check device security patch levels, surface pending updates to users, and verify CVEs. The walkthrough also covers building security-aware Android apps, with code examples in Kotlin using Jetpack libraries, and is being shared among developers in the Android and security engineering communities.

  2. 2
    Aon Ransomware Attack Linked to Termite Group Exploiting Cleo Flawโ—Aon Ransomware Attack Analysis: Termite Group Exploits CVE-2024-50623 in Cleo Softwareโœ‰newsTechnologyCybersecurity49 min ago

    A newly published analysis attributes an attack on insurance broker Aon to the Termite ransomware group, which allegedly exploited CVE-2024-50623, a vulnerability in Cleo file-transfer software. The flaw, disclosed in late 2024, allowed remote code execution and was widely exploited by multiple ransomware crews. Security experts continue to urge organizations using Cleo products to patch immediately, warning that unpatched file-transfer platforms remain a prime target for extortion operations.

  3. 3
    Critical Atlassian flaw CVE-2026-21589 already under attackโ—๐Ÿค– CVE-2026-21589 (CVSS 9.3): unauthenticated arbitrary file access in Atlassian Data Center products (Bitbucket, ConflueMmastodonTechnologyCybersecurity350 min ago

    Atlassian's Data Center products โ€” Bitbucket, Confluence and Jira โ€” are affected by CVE-2026-21589, a critical vulnerability (CVSS 9.3) allowing unauthenticated arbitrary file access. Security researchers report exploitation attempts began within two hours of public proof-of-concept details being released, making rapid patching urgent for organizations running affected software.

  4. 4
    Electric car catches fire at charging station in Turkeyโ—This is not a very strong marketing message. # ev # ElectricVehicle # Turkeye Electric car bursts into flames at charginMmastodonLifeAutos03 min ago

    An electric vehicle caught fire at a charging station in Turkey, an incident captured on video and circulated widely online. The footage drew mocking reactions, with commenters joking that it was not a strong marketing message for electric vehicles. No injuries or details about the cause of the fire were reported in the initial coverage.

  5. 5
    Critical code injection flaw hits Movable Type Cloud Editionโ—CVE-2026-96408 (CRITICAL): Movable Type Cloud Edition (v2.0 โ€“ 9.2.1) hit by code injection in upgrade script โ€” unauthentMmastodonTechnologyCybersecurity250 min ago

    A critical vulnerability, CVE-2026-96408, has been disclosed in Movable Type Cloud Edition versions 2.0 through 9.2.1. The flaw is a code injection in the upgrade script, allowing unauthenticated attackers to execute arbitrary Perl and SQL code. No patch is available yet, and administrators are being urged to restrict access to the upgrade script as an interim mitigation while a fix is awaited.

  6. 6
    Critical vulnerability disclosed in Eclipse ThreadX NetX Duoโ—CVE-2026-103416: CRITICAL out-of-bounds write in Eclipse ThreadX NetX Duo (โ‰ค6.5.1.202602). Exploitable pre-cert auth; riMmastodonTechnologyCybersecurity23 h ago

    A critical out-of-bounds write vulnerability, tracked as CVE-2026-103416, affects Eclipse ThreadX NetX Duo versions up to 6.5.1.202602. The flaw can be exploited before certificate authentication and may allow remote code execution or denial of service. No patch is available yet, and security researchers are urging users to monitor vendor updates for embedded and IoT devices running the stack.

  7. 7
    Jaguar unveils Type 01 production electric GT with 1,016hpโ—Jaguar Type 01 production version unveiled: 1,016hp electric GT, 720km range, 850V architecture # cars # electricvehicleMmastodonLifeAutos04 h ago

    Jaguar has revealed the production version of its Type 01 electric grand tourer, billed with 1,016 horsepower, a 720km range and an 850-volt electrical architecture. The figures position the car as a flagship for Jaguar's all-electric relaunch under parent company Jaguar Land Rover, and the unveiling is drawing attention from car and EV enthusiasts worldwide.

  8. 8
    LibreOffice and OpenOffice Patch Critical Code Execution Flawsโ—LibreOffice and OpenOffice Patch Critical Remote Code Execution Vulnerabilities LibreOffice and Apache OpenOffice patcheMmastodonTechnologyCybersecurity23 h ago

    The Document Foundation and Apache have released security updates for LibreOffice and OpenOffice fixing several critical vulnerabilities. Among them is CVE-2026-63277, a remote code execution flaw that lets attackers run malicious Java code through manipulated document files. Users are urged to install the patches promptly, as the flaw could allow full system compromise from simply opening a crafted file.

  9. 9
    Critical flaw in Manacle Technologies ERP system leaves users exposedโ—Manacle Technologies Multi-tenant ERP System hit by CVE-2026-107104 (CRITICAL, CVSS 9.3): Unsafe deserialization lets unMmastodonTechnologyCybersecurity24 h ago

    A critical vulnerability, CVE-2026-107104 with a CVSS score of 9.3, has been disclosed in Manacle Technologies' multi-tenant ERP system. Unsafe deserialization allows unauthenticated attackers to execute code remotely. No patch is available yet, so security researchers are urging users to restrict access and monitor affected systems until a fix is released.

  10. 10
    Flock becomes a CVE Numbering Authorityโ–ผFlock is now a CVE Numbering Authority assigning CVE IDs for Flock branded hardware and software products only. https://MmastodonTechnologyCybersecurity111 h ago

    Surveillance company Flock has been added to the CVE Program as a CVE Numbering Authority, meaning it can now assign official CVE identifiers to security vulnerabilities in its own Flock-branded hardware and software products. The designation, announced by the CVE Program, is drawing attention in the cybersecurity community given debate over Flock's surveillance footprint and how the company will handle disclosure of flaws in its own systems.

  11. 11
    Critical Atlassian flaw lets attackers read files unauthenticatedโ—๐Ÿค– CVE-2026-21589 (critical): unauthenticated arbitrary file access in self-hosted Atlassian Data Center โ€” Jira, ConfluenMmastodonTechnologyCybersecurity210 h ago

    Security researchers are flagging CVE-2026-21589, a critical vulnerability in self-hosted Atlassian Data Center products including Jira, Confluence, Bitbucket, Bamboo and Crowd. The flaw allows unauthenticated attackers to access arbitrary files, though they must know the exact file name or path since directory listing is not possible. Atlassian has released patched versions and reports no known exploitation so far. Administrators are urged to update their deployments promptly.

  12. 12
    wolfSSH flaw CVE-2026-16516 flagged over data authenticityโ—wolfSSH https:// radar.offseq.com/threat/cve-20 26-16516-cwe-345-insufficient-verification-of-data-authenticity-in-wolfsMmastodonTechnologyCybersecurity210 h ago

    A new vulnerability, CVE-2026-16516, has been catalogued in wolfSSH, the SSH library from wolfSSL Inc. The flaw is classified as CWE-345, insufficient verification of data authenticity, meaning the library may accept data without properly confirming it comes from a trusted source. The listing is circulating among security researchers, who are tracking it as a potential concern for products embedding wolfSSH.

  13. 13
    ShinyHunters exploited unpatched Oracle PeopleSoft flaw, FBI analysis findsโ–ผFBI Data Breach Analysis: ShinyHunters Exploit Unpatched Oracle PeopleSoft CVE-2026-35273 Due to Third-Party Patch Failureโœ‰newsTechnologyCybersecurity17 h ago

    An FBI breach analysis indicates the hacking group ShinyHunters exploited CVE-2026-35273, a vulnerability in Oracle PeopleSoft, which remained unpatched at affected organisations because of a failure in third-party patching processes. Security coverage of the finding is focused on the supply-chain lesson: even when vendors issue fixes, gaps in third-party patch management can leave enterprises exposed to data theft.

  14. 14
    Citrix and Fortinet zero-days under active exploitationโ—Recent news highlights critical cybersecurity threats as Citrix NetScaler (CVE-2026-88772) and FortiMail (CVE-2026-10428MmastodonTechnologyCybersecurity115 h ago

    Security researchers warn that newly disclosed zero-day vulnerabilities in Citrix NetScaler (CVE-2026-88772) and FortiMail (CVE-2026-104286) are being actively exploited, with critical infrastructure and government organisations among the targets. Apple has separately patched a CoreGraphics flaw already used in attacks. Administrators are urged to apply patches urgently and review systems for signs of compromise.

  15. 15
    Critical vulnerability disclosed in Payload CMSโ–ผ๐Ÿ”ด CVE-2026-105859 - Critical (9.8) Payload is a free and open source headless content management system. In versions befMmastodonTechnologyCybersecurity020 h ago

    A critical vulnerability, CVE-2026-105859 with a severity score of 9.8, has been disclosed in Payload, a free and open source headless content management system. Versions before 3.90.0 and canary versions before 4.0.0-canary.34 are affected: an attacker can submit a request to a specific update endpoint that modifies collection documents. Security teams using Payload are being urged to update to patched versions immediately.

  16. 16
    Critical file-access flaw hits self-hosted Atlassian productsโ—๐Ÿค– CVE-2026-21589: critical arbitrary file-access flaw in self-hosted Atlassian Data Center products (Confluence, Jira, BMmastodonTechnologyCybersecurity218 h ago

    Atlassian has disclosed CVE-2026-21589, a critical arbitrary file-access vulnerability affecting self-hosted Data Center versions of Confluence, Jira and Bitbucket. The flaw could let attackers read sensitive files on affected servers. Atlassian is urging administrators to patch immediately. Security commentators are sharing the advisory and warning self-hosted deployments to act quickly.

  17. 17
    Critical CVE in GitLab's AI Gateway Sparks Security Reviewโ—Earlier this month, a critical vulnerability showed up in GitLab's AI Gateway โ€” CVE-2026-90970, CVSS... # ai # securityMmastodonTechnologySoftware322 h ago

    A critical vulnerability, CVE-2026-90970, was discovered earlier this month in GitLab's AI Gateway, drawing attention to how AI agent permissions are handled in developer tools. The flaw, rated with a high CVSS severity score, has prompted security-minded developers to re-examine their own systems and question whether permission models for AI agents are properly isolated from core infrastructure.

  18. 18
    Critical flaw in Dell Container Storage Modules disclosedโ—๐Ÿ”ด CVE-2026-61421 - Critical (9.8) Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coMmastodonTechnologyCybersecurity021 h ago

    A critical vulnerability, CVE-2026-61421 with a severity score of 9.8, has been disclosed in Dell Container Storage Modules versions prior to 1.18.0. The flaw involves hard-coded credentials in the CSM Authorization component, meaning an unauthenticated attacker with remote access could potentially exploit it. Users are being urged to update to version 1.18.0 or later.