Vulnerability News
Open in Telegram
Every day new posts about vulnerabilities and cybersecurity news. Get the latest news about the cyberspace! Group: @VulnerabilityNewsGroup
Show more5 261
Subscribers
+324 hours
+377 days
+10130 days
Data loading in progress...
Similar Channels
Tags Cloud
Incoming and Outgoing Mentions
---
---
---
---
---
---
Attracting Subscribers
September '26
September '26
+29
in 0 channels
August '26
+157
in 0 channels
Get PRO
July '26
+185
in 0 channels
Get PRO
June '26
+156
in 0 channels
Get PRO
May '26
+204
in 0 channels
Get PRO
April '26
+187
in 0 channels
Get PRO
March '26
+254
in 0 channels
Get PRO
February '26
+116
in 0 channels
Get PRO
January '26
+166
in 0 channels
Get PRO
December '25
+134
in 0 channels
Get PRO
November '25
+139
in 0 channels
Get PRO
October '25
+8
in 0 channels
Get PRO
September '25
+12
in 0 channels
Get PRO
August '25
+13
in 0 channels
Get PRO
July '25
+11
in 0 channels
Get PRO
June '25
+12
in 0 channels
Get PRO
May '25
+18
in 1 channels
Get PRO
April '25
+14
in 0 channels
Get PRO
March '25
+21
in 0 channels
Get PRO
February '25
+17
in 0 channels
Get PRO
January '25
+15
in 1 channels
Get PRO
December '24
+262
in 1 channels
Get PRO
November '24
+206
in 1 channels
Get PRO
October '24
+166
in 0 channels
Get PRO
September '24
+146
in 0 channels
Get PRO
August '24
+137
in 0 channels
Get PRO
July '24
+96
in 1 channels
Get PRO
June '24
+91
in 0 channels
Get PRO
May '24
+95
in 0 channels
Get PRO
April '24
+104
in 0 channels
Get PRO
March '24
+149
in 0 channels
Get PRO
February '24
+279
in 0 channels
Get PRO
January '24
+395
in 0 channels
Get PRO
December '23
+327
in 0 channels
Get PRO
November '23
+38
in 0 channels
Get PRO
October '23
+32
in 0 channels
Get PRO
September '23
+47
in 0 channels
Get PRO
August '23
+53
in 0 channels
Get PRO
July '23
+51
in 0 channels
Get PRO
June '23
+42
in 0 channels
Get PRO
May '23
+43
in 0 channels
Get PRO
April '23
+67
in 0 channels
Get PRO
March '23
+65
in 0 channels
Get PRO
February '23
+45
in 0 channels
Get PRO
January '23
+67
in 0 channels
Get PRO
December '22
+62
in 0 channels
Get PRO
November '22
+71
in 0 channels
Get PRO
October '22
+70
in 0 channels
Get PRO
September '22
+55
in 0 channels
Get PRO
August '22
+44
in 0 channels
Get PRO
July '22
+54
in 0 channels
Get PRO
June '22
+78
in 0 channels
Get PRO
May '22
+46
in 0 channels
Get PRO
April '22
+77
in 0 channels
Get PRO
March '22
+105
in 0 channels
Get PRO
February '22
+48
in 0 channels
Get PRO
January '22
+61
in 0 channels
Get PRO
December '21
+99
in 0 channels
Get PRO
November '21
+68
in 0 channels
Get PRO
October '21
+170
in 0 channels
Get PRO
September '21
+72
in 0 channels
Get PRO
August '21
+104
in 0 channels
Get PRO
July '21
+72
in 0 channels
Get PRO
June '21
+292
in 0 channels
Get PRO
May '21
+1 344
in 0 channels
| Date | Subscriber Growth | Mentions | Channels | |
| 04 September | +5 | |||
| 03 September | +6 | |||
| 02 September | +11 | |||
| 01 September | +7 |
Channel Posts
[webapps] FreePBX 17.0.2 - Remote Code Execution (RCE)
FreePBX 17.0.2 - Remote Code Execution (RCE)
https://www.exploit-db.com/exploits/52681
| 2 | ASCII smuggling crosses over from AI prompt injection to phishing evasion
Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them.
The post ASCII smuggling crosses over from AI prompt injection to phishing evasion appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/ | 119 |
| 3 | Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
Publicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution and authentication bypass.
The post Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities appeared first on SecurityWeek.
https://www.securityweek.com/cisco-warns-of-unpatched-secure-email-flaws-patches-critical-switch-vulnerabilities/ | 87 |
| 4 | Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution.
The post Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability appeared first on SecurityWeek.
https://www.securityweek.com/over-3-million-wordpress-sites-affected-by-migration-plugin-vulnerability/ | 54 |
| 5 | 153 Million Driver License Images Offered on Dark Web
Cybercriminals are offering digital scans of US and Canadian driver’s licenses, likely stolen from IDScan.net.
The post 153 Million Driver License Images Offered on Dark Web appeared first on SecurityWeek.
https://www.securityweek.com/153-million-driver-license-images-offered-on-dark-web/ | 50 |
| 6 | AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million
The startup’s firewall evaluates AI skills, plugins and MCP servers for malicious instructions, excessive permissions and software supply chain risks.
The post AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million appeared first on SecurityWeek.
https://www.securityweek.com/ai-agent-firewall-startup-air-security-emerges-from-stealth-with-50-million/ | 35 |
| 7 | HiddenLayer Raises $100 Million for AI Runtime Security
The Austin-based company will invest in agentic runtime security capabilities to secure AI coding agents.
The post HiddenLayer Raises $100 Million for AI Runtime Security appeared first on SecurityWeek.
https://www.securityweek.com/hiddenlayer-raises-100-million-for-ai-runtime-security/ | 33 |
| 8 | Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents
New models, trained using NVIDIA Nemotron 3 Ultra, aim to catch rogue agent behavior before it executes, without the latency of large-model review.
The post Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents appeared first on SecurityWeek.
https://www.securityweek.com/capsule-security-launches-ai-circuit-breaker-to-stop-rogue-agents/ | 37 |
| 9 | Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal
Hacker group published roughly 550GB of data after MAG reportedly refused to pay a ransom demand; the group says it gained access via exposed admin keys.
The post Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal appeared first on SecurityWeek.
https://www.securityweek.com/manchester-airports-group-data-on-8-8-million-people-leaked-after-ransom-refusal/ | 31 |
| 10 | Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs
Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday. [...]
https://www.bleepingcomputer.com/news/microsoft/microsoft-teams-outlook-fail-to-launch-on-arm-based-windows-pcs/ | 28 |
| 11 | Plex warns users to patch security vulnerabilities immediately
Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. [...]
https://www.bleepingcomputer.com/news/security/plex-warns-users-to-patch-security-vulnerabilities-immediately/ | 28 |
| 12 | Microsoft says KB5120998 Windows update resets desktop settings
Microsoft has confirmed that desktop settings are lost or reset on some Windows devices after installing the KB5120998 August 2026 preview update. [...]
https://www.bleepingcomputer.com/news/microsoft/microsoft-says-kb5120998-windows-update-resets-desktop-settings/ | 26 |
| 13 | Your Employee’s Password Appeared in an Infostealer Log. Now What?
Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]
https://www.bleepingcomputer.com/news/security/your-employees-password-appeared-in-an-infostealer-log-now-what/ | 28 |
| 14 | Critical Elementor Pro flaw exploited to take over WordPress sites
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...]
https://www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-exploited-to-take-over-wordpress-sites/ | 32 |
| 15 | Anthropic confirms Claude is down, multiple models affected
Claude is experiencing an outage, with users encountering elevated errors when sending requests to multiple Anthropic AI models. [...]
https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-confirms-claude-is-down-multiple-models-affected/ | 34 |
| 16 | OpenAI confirms ChatGPT is down ahead of 'Astra' model launch
ChatGPT and Codex are experiencing a major outage, with users reporting errors across nearly every major ChatGPT feature. [...]
https://www.bleepingcomputer.com/news/artificial-intelligence/openai-confirms-chatgpt-is-down-ahead-of-astra-model-launch/ | 33 |
| 17 | Microsoft: KB5120998 mouse reset bug affects only non-English PCs
Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. [...]
https://www.bleepingcomputer.com/news/microsoft/microsoft-kb5120998-mouse-reset-bug-affects-only-non-english-pcs/ | 37 |
| 18 | HPE patches critical ArubaOS-CX remote code execution flaw
Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. [...]
https://www.bleepingcomputer.com/news/security/hpe-patches-critical-arubaos-cx-remote-code-execution-flaw/ | 41 |
| 19 | Coder's registry infrastructure compromised to push malicious modules
Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. [...]
https://www.bleepingcomputer.com/news/security/coders-registry-infrastructure-compromised-to-push-malicious-modules/ | 49 |
| 20 | French hospital fined €500,000 after breach exposes data of 727,000
France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients' and their relatives' data. [...]
https://www.bleepingcomputer.com/news/security/french-hospital-fined-500-000-after-breach-exposes-data-of-727-000/ | 64 |
