Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
SUSE released important security updates for Node.js versions 22 and 24 on August 6, 2026, addressing multiple vulnerabilities. The updates include fixes for CVE-2026-54272, CVE-2026-56846, CVE-2026-56847,…
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
A critical remote code execution vulnerability (CVE-2025-34299) has been identified in Monsta FTP, a web-based file transfer client, allowing unauthenticated attackers to execute arbitrary code on affected systems. The…
A security researcher identified multiple vulnerabilities in Forgejo, a software platform used by Fedora, including SSRF, cryptographic issues, and authentication flaws. The researcher was able to chain these…
A remote code execution vulnerability, CVE-2025-34299, has been identified in Monsta FTP, affecting versions 2.11 and earlier. This flaw allows unauthenticated users to upload arbitrary files, enabling attackers to…
OpenAI has introduced GPT-5.4-Cyber, a specialized AI model for defensive cybersecurity, available only to vetted professionals through its Trusted Access for Cyber (TAC) program. This model is designed to facilitate…
Snyk conducted 300 vulnerability scans to evaluate the repeatability of LLM security reviews on identical code and prompts. The results showed that while reference-matched findings were stable, extra-model reports…
A critical pre-authentication remote code execution vulnerability, CVE-2026-1731, has been identified in BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA). This vulnerability…
Two vulnerabilities in the open-source AI framework Chainlit expose major enterprises' cloud environments to potential data leaks and full takeover. According to Zafran, these flaws allow attackers to read arbitrary…