Software Vulnerabilities
Ongoing coverage on Software Vulnerabilities.
Latest coverage
Nintendo identifies Switch exploit in which bad actor could run code or obtain information stored on the console
Nintendo has issued a security notice regarding an exploit that could allow unauthorized code execution or data access on Nintendo Switch consoles. The vulnerability requires a bad actor to scan a QR code displayed on the Switch screen when using the 'Send to Smartphone' feature or playing Mario Kart Live: Home Circuit. Nintendo recommends updating the console to firmware version 23.0.0 to mitigate the risk.
It's time to update Asus Armoury Crate and several other Asus software tools again, as another high severity security vulnerability has been discovered
Asus has released updates for its Armoury Crate, GPU Tweak III, and GPU Tweak II software to address a newly discovered high-severity security vulnerability (CVE-2026-8917). This vulnerability allows local attackers to potentially escalate privileges. Users are advised to update their Asus software to ensure optimal protection against such threats.
Morning Safety Dance
Google Chrome requires patching twice a week due to a bug discovered through AI-driven analysis. This addresses a critical vulnerability in Exchange servers, highlighting the ongoing need for frequent security updates.
Morning Safety Dance
Adobe ColdFusion is being actively exploited in the wild, prompting an urgent call for users to update their software. Separately, Hesai Technology is expanding its U.S. presence despite being blacklisted by the Pentagon.
Evening Safety Dance
Microsoft has largely fixed a flaw in its Surface hardware that could render unprotected devices unusable with a single packet. Separately, a zero-day vulnerability affecting PeopleSoft is impacting hundreds of organizations.
Two high-rated motherboard security vulnerabilities have been identified in Gigabyte Control Center, so come update your…
Gigabyte has released advisories for two high-severity security vulnerabilities found in its Gigabyte Control Center (GCC) software. The vulnerabilities, CVE-2026-4415 and CVE-2026-4416, affect file handling and the EasyTune Engine Service respectively, potentially allowing for arbitrary code execution. Gigabyte strongly advises users to update to the latest version of GCC immediately to patch these issues.
Evening Safety Dance
OpenAI has addressed a DNS data smuggling vulnerability within its ChatGPT service. The flaw, reported by The Register, allowed for potential data exfiltration through DNS queries.
Evening Safety Dance
Federal authorities are investigating mysterious circumstances surrounding exploited iOS vulnerabilities. Separately, Microsoft's Secure Boot certificates are set to expire in June 2026, with older PCs potentially not receiving a fix.