Vulnerabilities
Ongoing coverage on Vulnerabilities.
Latest coverage
A Zoom Zero-Click Was Found in Under a Day — With AI Tools Anyone Can Download
The cybersecurity firm A Security discovered a zero-click remote code execution vulnerability in Zoom's annotation tool using publicly available AI models and fewer than 20 prompts. This flaw allowed attackers to execute code on a victim's machine simply by sharing their screen, even with end-to-end encryption enabled. Zoom has released a patch, and users are urged to update their software immediately.
PSA: Apple has released security updates for Mac
Apple has released security updates for its macOS operating systems, including Tahoe, Sequoia, and Sonoma. These patches address a vulnerability found in the Screen Sharing feature.
Apple has reportedly fixed its Hide My Email vulnerability
Apple has reportedly addressed a vulnerability within its Hide My Email feature for iCloud+ users. This fix ensures that users' email addresses are no longer exposed when using the service.
It's probably time to update 7-Zip as the app has just been patched to fix a pretty big vulnerability
A significant vulnerability in the file compression application 7-Zip has been patched, requiring users to manually update to version 26.02 or later. The vulnerability allows for arbitrary code execution if a user interacts with a malicious file or webpage. This fix was reported by Lunbun LLC and released by 7-Zip after a few weeks.
Evening Safety Dance
A vulnerability in Apple's 'Hide My Email' feature has been discovered, potentially exposing users' real email addresses. Separately, the EvilTokens device-code phishing kit is noted for its advanced malicious capabilities.
Morning Safety Dance
A critical vulnerability in Microsoft's Copilot has been discovered, allowing hackers to steal two-factor authentication codes from users. This exploit poses a significant security risk, potentially compromising user accounts.
Sunday Safety Dance
Cisco is facing attacks on a zero-day vulnerability within its SD-WAN solution, with no patch currently available. The article also touches on physical security threats involving USB sticks and mentions Oxford University.
Evening Safety Dance
Meta's AI chatbot has allegedly been used by hackers to hijack Instagram accounts. Separately, a Windows Server vulnerability has been discovered that could grant system privileges through a malformed packet, posing a risk to domain controllers.
Security researcher describes freshly uncovered Windows 11 vulnerability as 'one of the most insane discoveries I…
A security researcher known as Nightmare-Eclipse has discovered a BitLocker bypass vulnerability in Windows 11, dubbed YellowKey. The exploit allows attackers to access encrypted drives by abusing the Windows Recovery Environment, a vulnerability that does not appear to affect Windows 10. Microsoft has acknowledged the issue as a security feature bypass.
NVIDIA reveal more GPU driver security flaws for May 2026
NVIDIA has revealed multiple security vulnerabilities affecting its GPU drivers for Windows and Linux, with potential impacts including denial of service, privilege escalation, and code execution. These flaws, detailed with CVE identifiers and severity ratings, highlight ongoing security concerns within graphics driver software.
Fragnesia and ssh-keysign-pwn are the latest Linux security problems
Two new Linux security vulnerabilities, Fragnesia and ssh-keysign-pwn, have been disclosed. Fragnesia is a local privilege escalation exploit within the Dirty Frag class, allowing arbitrary writes to read-only kernel files. Ssh-keysign-pwn enables unprivileged users to read root-owned files. Users are advised to keep their systems updated.
Linux security flaws Dirty Frag and Copy Fail are a good reminder to stay up to date
Two significant security vulnerabilities, Dirty Frag and Copy Fail, have been discovered in Linux systems, allowing unprivileged local users to gain root access. Patches are being rolled out across various distributions, and a temporary workaround for Dirty Frag is available via the terminal. Users are advised to update their systems promptly.
Evening Safety Dance
Microsoft's Edge browser reportedly has a vulnerability that could easily leak user passwords, a feature Microsoft claims is "by design." This information comes from a Neowin report and is part of a broader vulnerability summary for the week of April 27, 2026, from CISA.
Canonical, the company that makes Ubuntu Linux, says its web infrastructure is under a 'sustained, cross-border…
Canonical, the company behind Ubuntu Linux, is experiencing a sustained, cross-border cyberattack that has impacted its website, blog, and potentially its software repositories. The company is working to address the issue and provide updates through official channels. Reports suggest a hacktivist group may have claimed responsibility for the attack.
A 17-year-old Excel vulnerability is currently being exploited by threat actors, and it's been flagged by the…
A 17-year-old vulnerability in Microsoft Office, originally reported in 2009, is now being actively exploited by threat actors, according to CISA. The agency has flagged the exploit, which has a severity score of 8.8, and is urging Microsoft to patch it again. A separate, less severe but automatable exploit in Microsoft Office SharePoint has also been identified.
X.Org X server and Xwayland security advisory released for multiple issues
X.Org and Xwayland developers have released security advisories detailing multiple vulnerabilities affecting previous versions of the X server and Xwayland. Newly released versions, xorg-server-21.1.22 and xwayland-24.1.10, include fixes for these issues, such as integer underflows and out-of-bounds reads, discovered by Jan-Niklas Sohn working with TrendAI Zero Day Initiative.
Morning Safety Dance
A zero-day vulnerability in Adobe Reader is being exploited through PDFs, allowing attackers to target users. Separately, Microsoft has stated that a reported glitch in Windows 11 and Windows 10 is considered 'by design' and will not be fixed.
Anthropic's new Claude Mythos AI model has apparently found thousands of vulnerabilities in 'every major operating system and every major web browser, along with a range of other important pieces of software'
Anthropic's new AI model, Claude Mythos, has identified thousands of high-severity vulnerabilities across major operating systems and web browsers. This discovery was made as part of Project Glasswing, an initiative involving major tech companies aimed at securing critical software. The AI's ability to detect these flaws quickly raises hopes for staying ahead of cyber threats.
Morning Safety Dance
The FBI has declared a suspected Chinese hack of a US surveillance system a major cyber incident. Additionally, two significant security vulnerabilities have been discovered in Gigabyte's Control Center software.
Intel has published a whole host of security vulnerabilities, with mitigations rolling out, but attackers will need…
Intel has disclosed numerous security vulnerabilities found in the UEFI firmware of its products, with some registering a CVSS score of 8.7. These vulnerabilities could allow for privilege escalation and local code execution. Mitigations are being rolled out, and users are advised to update their systems.