Security

RSS

Breaches, vulnerabilities, privacy and staying safe online.

Security

Dell patches Secure Connect Gateway flaws - but is CVE-2026-79941 really 'critical'?

A newly listed Dell bug is tagged critical severity despite carrying a CVSS score that normally means 'medium' - here's what's actually confirmed.

NerdBite ·

Security

ConnectWise ScreenConnect flaw is being actively exploited, says CISA — but details are thin

A newly catalogued bug in the popular remote-access tool has US federal agencies scrambling to patch by Monday, though who's behind the attacks and how remains unclear.

NerdBite ·

Security

Netis router bug hands out the admin password to anyone who asks

A newly disclosed flaw in the Netis NX10 lets unauthenticated attackers read the admin password straight off the web interface - but the headline 9.8 score doesn't match what the researcher's own advisory says.

NerdBite ·

Security

MikroTik RouterOS flaw added to US 'actively exploited' list — but details are thin on the ground

CISA says CVE-2026-86060 is being used in real attacks against MikroTik routers, yet neither the agency nor NVD has published what the bug actually does.

NerdBite ·

Security

Critical bug in Linksys RE7000 Wi-Fi extender lets attackers hijack the ping test tool

A newly catalogued flaw scores a near-maximum 9.9 for severity, but the fine print matters more than the number.

NerdBite ·

Security

Citrix NetScaler flaw now on CISA's exploited list — but the details are strangely thin

A new NetScaler bug has made the US government's most urgent watchlist, yet nobody outside CISA seems to know exactly how it's being abused.

NerdBite ·

Security

Charity Commission clears four charities of theft - but not of reckless chequebook habits

No money went missing at these four charities, the regulator says, but blank cheques and weak oversight were enough to earn a formal finding of mismanagement - and the bigger 105-charity inquiry grinds on.

NerdBite ·

Security

Critical flaw in Advantech industrial gateways lets attackers become root over the network

A near-maximum severity score sounds terrifying, but the catch is who actually owns one of these boxes - and whether Advantech has fixed it yet.

NerdBite ·

Security

CISA confirms active attacks on Adobe Commerce and Magento flaw — but details are scarce

A newly catalogued Adobe Commerce and Magento bug is already being exploited, says CISA, though it's telling us very little about how.

NerdBite ·

Security

Researcher cracks a 1999 CA's 512-bit keys - but the only victim is his own VM

A hobby project spent 61 hours of desktop compute breaking encryption that Netscape itself gave up on in 2002 - here's why nobody today should lose sleep over it.

NerdBite ·

Security

Critical flaw in open-source 'Cua' AI agent server lets anyone skip the login screen

A missing environment variable is all it takes to bypass authentication entirely — but only if you've actually installed the thing.

NerdBite ·

Security

JFrog Artifactory flaw added to US 'actively exploited' list — here's what we actually know

CISA says attackers are already using CVE-2026-82329 in the wild, but the public record is short on detail about how it works and who exactly is exposed.

NerdBite ·

Security

Critical flaw in a popular Excel AI tool could let attackers read and write any file

A newly disclosed bug in excel-mcp-server scores a maximum-alarm 9.8 out of 10 - but the danger depends entirely on a setting most people won't have touched.

NerdBite ·

Security

Kestra OSS flaw added to US 'actively exploited' list — but the details are thin

CVE-2026-49869 has landed on America's known-exploited-vulnerabilities list with a three-day patch deadline for federal agencies, yet neither CISA nor NVD have published what the bug actually does.

NerdBite ·

Security

Critical flaw in Taipy's web server config lets any website hijack your session, CVE says

A newly disclosed bug in the Python framework Taipy scores a near-maximum severity rating - but whether it's actually being exploited, or even patched, is still an open question.

NerdBite ·

Security

US cyber agency confirms Starlette bug is being exploited, but won't say how

A vulnerability in a widely used Python web framework has made America's most-watched vulnerability list, yet the public record is oddly thin on what the bug actually does.

NerdBite ·

Security

Chromium's newest RCE is already being used against people, and Google paid £790 for it

A sandbox-escaping bug in every version of Chromium is under active attack, but the size of the bounty is raising more eyebrows than the bug itself.

NerdBite ·

Security

Critical flaw found in obscure TOTOLINK router model, but check before you panic

A newly logged bug scores a maximum-alarm 9.9 out of 10, but the fine print matters more than the number.

NerdBite ·

Security

Chromium's V8 engine has a bug under active attack, but the details are suspiciously thin

CISA says CVE-2026-85046 is being exploited right now, yet the public record barely tells us what the bug does or which Chrome version fixes it.

NerdBite ·

Security

A 'critical' Firefox Focus bug just got a CVSS 9.8 - but the details are oddly thin

A newly listed flaw in Firefox Focus for Android carries a maximum-alarm score, yet Mozilla's own paperwork barely says what it actually does.

NerdBite ·

Security

US cyber agency confirms active exploitation of bug in AI proxy tool LiteLLM

CISA says the flaw is being exploited right now, but its own listing is oddly light on what the bug actually does or who's behind the attacks.

NerdBite ·

Security

Critical bug in obscure npm tool could let wildcard logins sneak past AWS security checks

A flaw in a niche policy-checking package let attackers hide dangerous wildcard rules from GitHub's cloud login guardrails, but only a small slice of DevOps setups will ever encounter it.

NerdBite ·

Security

PaperCut NG/MF flaw added to US exploited-bugs list - but the details are thin

CISA says CVE-2026-81578 is being actively exploited in the wild, yet the public record offers almost nothing on how the attack actually works.

NerdBite ·

Security

Critical flaw in Argo CD's AI helper let anyone with network access hijack deployments

A maximum-severity bug in the argocd-mcp server skipped login checks entirely - but only if you'd switched it on and pointed it at the open network in the first place.

NerdBite ·

Security

PaperCut NG/MF flaw added to US 'actively exploited' list, but details are thin

CISA says CVE-2026-82078 is being exploited right now, yet the public record says almost nothing about how, by whom, or whether a fix even exists.

NerdBite ·

Security

Redpanda's Admin API defaults to 'trust everyone' - here's what that actually means

A critical-rated flaw in the Kafka-alternative streaming platform boils down to an insecure default, not some exotic exploit - but that doesn't make it harmless.

NerdBite ·

Security

That 'critical' OpenSSL CVE isn't OpenSSL - it's a two-star Python package

A 9.8-rated bug can forge fingerprint checks in a niche identity tool called openssl_encrypt - which, despite the name, has nothing to do with the actual OpenSSL library.

NerdBite ·

Security

JFrog Artifactory bug added to US 'actively exploited' list, but details are thin

CISA says CVE-2026-66384 is being exploited in the wild right now, yet the public record barely says what it actually does.

NerdBite ·

Security

Critical-rated bug in obscure Python encryption tool lets attackers swap in their own keys

A flaw in the little-used openssl_encrypt package could let an attacker fake a trusted contact's key - but the 'critical' label needs a reality check.

NerdBite ·

Security

Linux kernel bug added to US 'actively exploited' list, but nobody's saying much else

CISA says CVE-2026-53362 is being used in real attacks right now, yet the public record is almost entirely blank on what the bug actually does.

NerdBite ·

Security

Critical flaw in obscure Turkish repository software scores 9.8 - but almost nobody outside Turkey will care

CVE-2026-16286 lets attackers upload dangerous files to TRtek's Software Repository Management tool, yet the advisory says nothing about a fix, active abuse, or how many people actually run it.

NerdBite ·

Security

US cyber agency confirms an ownCloud flaw is being actively exploited

CISA has flagged CVE-2023-49105 as under real-world attack, but the small print matters: this is a federal-agency deadline, not a nationwide emergency.

NerdBite ·

Security

US cyber agency flags old Ajax.NET Professional bug as actively exploited, but details are thin on the ground

CVE-2021-23758 has just landed on America's most-watched vulnerability list, five years after it was first catalogued, and the public record explains almost nothing about how it's being abused.

NerdBite ·

Security

That 'critical' 9.8 bug in justhtml? GitHub itself only calls it 'Moderate'

A Python HTML-sanitiser has patched several sanitisation bypasses - but the severity score depends entirely on who you ask, and mostly on how you've configured it.

NerdBite ·

Security

Gitea flaw added to US 'actively exploited' list, but the technical details are still a mystery

America's cyber-security agency says a bug in the popular self-hosted Git platform Gitea is already being used in real attacks, yet the public record barely explains what it actually does.

NerdBite ·

Security

TRENDnet router bug gets a 'perfect' CVSS 10 - but the score comes from the bug hunter, not NIST

A stack overflow in a niche WiFi access point has been rated maximum severity, though the number attached to it deserves more scrutiny than the bug itself.

NerdBite ·

Security

Oracle server bug hits maximum severity score as US cyber agency confirms active attacks

CVE-2026-21962 scores a perfect 10 out of 10 and is already being exploited in the wild - but this is squarely an enterprise problem, not one for home users.

NerdBite ·

Security

A developer used an AI coding agent to hack his own webcam, mic and desk light, here's the catch

One person's viral blog post shows how far AI-assisted reverse engineering has come, but this is a personal experiment, not a security alert for the rest of us.

NerdBite ·

Security

Critical flaw in Mailgun for WordPress plugin could let attackers hijack admin accounts

A newly published CVE rates 9.8 out of 10, but before anyone panics it's worth asking who actually runs this plugin, and whether it's even fixed yet.

NerdBite ·

Security

VMware vCenter flaw added to US 'actively exploited' list, here's what's actually confirmed

A critical bug in vCenter's Syslog server has earned a place on America's most-wanted vulnerability list, but the scarier detail, Chinese hackers, hundreds of victims, comes from a blog post, not CISA.

NerdBite ·

Security

IBM patches critical AIX and PowerVM flaw letting attackers overwrite files remotely

A 9.1-rated bug sounds terrifying, but check who's actually running this before you panic - it's not your laptop.

NerdBite ·

Security

TrueConf Server bug now on CISA's exploited-in-the-wild list, should you care?

A critical flaw in a Russian videoconferencing platform is being actively abused, but unless you're running TrueConf's server software yourself, this one passes you by.

NerdBite ·

Security

A 9.9-rated flaw in Red Hat's Kubernetes management tool isn't as apocalyptic as the score implies

CVE-2026-70496 hands a helper component cluster-admin-level powers on paper, but Red Hat's own rating and the fine print tell a calmer story.

NerdBite ·

Security

Zimbra email servers under active attack via obscure SNMP flaw

A serious, unauthenticated bug in Zimbra Collaboration Suite is already being exploited, but only a specific, non-default setup is actually exposed.

NerdBite ·

Security

SIA marks first 'National Day for Victims and Survivors of Terrorism', but don't mistake it for new law

The security regulator has issued a solidarity statement, not a policy change, here's what's actually new and what isn't.

NerdBite ·

Security

Firefox patches a critical use-after-free bug - but is it really a 9.8?

A newly disclosed WebAssembly flaw in Firefox scores near the top of the danger scale, though Mozilla's own rating and the lack of any known attacks tell a calmer story.

NerdBite ·

Security

TrueConf Server flaw let attackers break out of its sandbox, CISA says it's already being exploited

A critical bug in the self-hosted video conferencing platform is now on the US government's confirmed-exploited list, but this is an enterprise problem, not a household one.

NerdBite ·

Security

'Perfect 10' bug in an old TRENDnet Wi-Fi controller's nginx binary - but check who actually owns one

A stack overflow in a bundled nginx binary has earned the maximum CVSS score, but the affected device is a niche, ageing wireless controller rather than anything on your desk.

NerdBite ·

Security

MLflow webhook bug now under active attack, CISA confirms

A validation gap in MLflow's webhook testing feature can be abused to sneak past security checks and reach internal systems, and someone is already doing it.

NerdBite ·

Security

Critical flaw in Red Hat's cluster management tool needs a privileged account to matter

A 9.1-rated bug sounds terrifying, but check the small print: you need admin-level access to abuse it in the first place.

NerdBite ·

Security

Critical Windows networking flaw is being actively exploited, CISA confirms

A 9.8-rated bug in Microsoft's IKE service lets attackers run code with no clicks and no credentials, and it's already being used in the wild, not just theorised.

NerdBite ·

Security

Charity Commission flags rising abuse of charitable status, but the numbers need context

The regulator's own risk assessment shows a real rise in cases, but that's likely as much about better detection as it is about scarier criminals.

NerdBite ·

Security

Another Tenda router flaw scores 9.8 - but check your firmware before panicking

A critical authentication bypass has been logged against a single Tenda AC10 firmware build - here's what's actually confirmed and what's still guesswork.

NerdBite ·

Security

US cyber agency flags actively exploited flaw in Ray, the AI developer tool

A browser trick and some old-fashioned DNS trickery can apparently hijack machines running Ray in dev mode, but only if you're the kind of person running Ray in dev mode.

NerdBite ·

Security

Critical Grav CMS plugin bug let low-privilege API keys mint themselves 'super' access

A scoring of 9.8 sounds terrifying, but the flaw only bites sites running Grav's API plugin with super-user API keys already in play - here's what actually happened and who needs to patch.

NerdBite ·

Security

Progress LoadMaster flaw is being actively exploited, here's who needs to care

A critical bug lets attackers run commands on LoadMaster boxes with no login required, but this is an enterprise networking story, not one for home routers.

NerdBite ·

Security

Windows has a zero-day that hands attackers full control - and it is already being used

CVE-2026-68820, a use-after-free bug in the WinSock driver, lets someone already on your PC escalate to SYSTEM. CISA has told federal agencies to patch by 25 August. Here is who is actually at risk, and who is not.

NerdBite ·

Security

The Windows flaw added to CISA's exploited list this week is one of the few that reaches home machines

CVE-2026-68820 is a privilege escalation in a Windows networking driver. It cannot get an attacker in, which is the point: it is what they use once they are already there.

NerdBite ·

Security

Federal agencies had until today to patch a Cisco firewall flaw that is already being exploited

CVE-2026-20349 lets an unauthenticated attacker reboot a Cisco firewall from the internet. It does not steal anything, which is exactly why it is easy to underrate.

NerdBite ·

Security

CISA gives federal agencies three days to patch a Cisco firewall flaw already being exploited

Two Cisco Secure Firewall products were added to the US catalogue of actively exploited vulnerabilities on 11 August, with a deadline of 14 August. The short clock is the tell.

NerdBite ·

Security

Signicat certified under the UK digital identity framework - but the policy backdrop is not what the announcement says

The identity firm has passed a Kantara audit covering Right to Work, Right to Rent and DBS checks. Its announcement also claims the government has ended its digital ID scheme, which is not what happened.

NerdBite ·