uz
Feedback
Vulnerability News

Vulnerability News

Kanalga Telegram’da o‘tish

Every day new posts about vulnerabilities and cybersecurity news. Get the latest news about the cyberspace! Group: @VulnerabilityNewsGroup

Ko'proq ko'rsatish
5 256
Obunachilar
+324 soatlar
+377 kun
+10130 kun
Obunachilarni jalb qilish
Sentabr '26
Sentabr '26
+24
0 kanalda
Avgust '26
+157
0 kanalda
Get PRO
Iyul '26
+185
0 kanalda
Get PRO
Iyun '26
+156
0 kanalda
Get PRO
May '26
+204
0 kanalda
Get PRO
Aprel '26
+187
0 kanalda
Get PRO
Mart '26
+254
0 kanalda
Get PRO
Fevral '26
+116
0 kanalda
Get PRO
Yanvar '26
+166
0 kanalda
Get PRO
Dekabr '25
+134
0 kanalda
Get PRO
Noyabr '25
+139
0 kanalda
Get PRO
Oktabr '25
+8
0 kanalda
Get PRO
Sentabr '25
+12
0 kanalda
Get PRO
Avgust '25
+13
0 kanalda
Get PRO
Iyul '25
+11
0 kanalda
Get PRO
Iyun '25
+12
0 kanalda
Get PRO
May '25
+18
1 kanalda
Get PRO
Aprel '25
+14
0 kanalda
Get PRO
Mart '25
+21
0 kanalda
Get PRO
Fevral '25
+17
0 kanalda
Get PRO
Yanvar '25
+15
1 kanalda
Get PRO
Dekabr '24
+262
1 kanalda
Get PRO
Noyabr '24
+206
1 kanalda
Get PRO
Oktabr '24
+166
0 kanalda
Get PRO
Sentabr '24
+146
0 kanalda
Get PRO
Avgust '24
+137
0 kanalda
Get PRO
Iyul '24
+96
1 kanalda
Get PRO
Iyun '24
+91
0 kanalda
Get PRO
May '24
+95
0 kanalda
Get PRO
Aprel '24
+104
0 kanalda
Get PRO
Mart '24
+149
0 kanalda
Get PRO
Fevral '24
+279
0 kanalda
Get PRO
Yanvar '24
+395
0 kanalda
Get PRO
Dekabr '23
+327
0 kanalda
Get PRO
Noyabr '23
+38
0 kanalda
Get PRO
Oktabr '23
+32
0 kanalda
Get PRO
Sentabr '23
+47
0 kanalda
Get PRO
Avgust '23
+53
0 kanalda
Get PRO
Iyul '23
+51
0 kanalda
Get PRO
Iyun '23
+42
0 kanalda
Get PRO
May '23
+43
0 kanalda
Get PRO
Aprel '23
+67
0 kanalda
Get PRO
Mart '23
+65
0 kanalda
Get PRO
Fevral '23
+45
0 kanalda
Get PRO
Yanvar '23
+67
0 kanalda
Get PRO
Dekabr '22
+62
0 kanalda
Get PRO
Noyabr '22
+71
0 kanalda
Get PRO
Oktabr '22
+70
0 kanalda
Get PRO
Sentabr '22
+55
0 kanalda
Get PRO
Avgust '22
+44
0 kanalda
Get PRO
Iyul '22
+54
0 kanalda
Get PRO
Iyun '22
+78
0 kanalda
Get PRO
May '22
+46
0 kanalda
Get PRO
Aprel '22
+77
0 kanalda
Get PRO
Mart '22
+105
0 kanalda
Get PRO
Fevral '22
+48
0 kanalda
Get PRO
Yanvar '22
+61
0 kanalda
Get PRO
Dekabr '21
+99
0 kanalda
Get PRO
Noyabr '21
+68
0 kanalda
Get PRO
Oktabr '21
+170
0 kanalda
Get PRO
Sentabr '21
+72
0 kanalda
Get PRO
Avgust '21
+104
0 kanalda
Get PRO
Iyul '21
+72
0 kanalda
Get PRO
Iyun '21
+292
0 kanalda
Get PRO
May '21
+1 344
0 kanalda
Sana
Obunachilarni jalb qilish
Esdaliklar
Kanallar
04 Sentabr0
03 Sentabr+6
02 Sentabr+11
01 Sentabr+7
Kanal postlari
[webapps] FreePBX 17.0.2 - Remote Code Execution (RCE) FreePBX 17.0.2 - Remote Code Execution (RCE) https://www.exploit-db.com/exploits/52681

2
ASCII smuggling crosses over from AI prompt injection to phishing evasion Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to phishing evasion appeared first on Microsoft Security Blog. https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/
80
3
Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities Publicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution and authentication bypass. The post Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities appeared first on SecurityWeek. https://www.securityweek.com/cisco-warns-of-unpatched-secure-email-flaws-patches-critical-switch-vulnerabilities/
60
4
Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution. The post Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability appeared first on SecurityWeek. https://www.securityweek.com/over-3-million-wordpress-sites-affected-by-migration-plugin-vulnerability/
37
5
153 Million Driver License Images Offered on Dark Web Cybercriminals are offering digital scans of US and Canadian driver’s licenses, likely stolen from IDScan.net. The post 153 Million Driver License Images Offered on Dark Web appeared first on SecurityWeek. https://www.securityweek.com/153-million-driver-license-images-offered-on-dark-web/
37
6
AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million The startup’s firewall evaluates AI skills, plugins and MCP servers for malicious instructions, excessive permissions and software supply chain risks. The post AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million appeared first on SecurityWeek. https://www.securityweek.com/ai-agent-firewall-startup-air-security-emerges-from-stealth-with-50-million/
26
7
HiddenLayer Raises $100 Million for AI Runtime Security The Austin-based company will invest in agentic runtime security capabilities to secure AI coding agents. The post HiddenLayer Raises $100 Million for AI Runtime Security appeared first on SecurityWeek. https://www.securityweek.com/hiddenlayer-raises-100-million-for-ai-runtime-security/
26
8
Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents New models, trained using NVIDIA Nemotron 3 Ultra, aim to catch rogue agent behavior before it executes, without the latency of large-model review. The post Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents appeared first on SecurityWeek. https://www.securityweek.com/capsule-security-launches-ai-circuit-breaker-to-stop-rogue-agents/
30
9
Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal Hacker group published roughly 550GB of data after MAG reportedly refused to pay a ransom demand; the group says it gained access via exposed admin keys. The post Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal appeared first on SecurityWeek. https://www.securityweek.com/manchester-airports-group-data-on-8-8-million-people-leaked-after-ransom-refusal/
26
10
Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday. [...] https://www.bleepingcomputer.com/news/microsoft/microsoft-teams-outlook-fail-to-launch-on-arm-based-windows-pcs/
23
11
Plex warns users to patch security vulnerabilities immediately Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. [...] https://www.bleepingcomputer.com/news/security/plex-warns-users-to-patch-security-vulnerabilities-immediately/
23
12
Microsoft says KB5120998 Windows update resets desktop settings Microsoft has confirmed that desktop settings are lost or reset on some Windows devices after installing the KB5120998 August 2026 preview update. [...] https://www.bleepingcomputer.com/news/microsoft/microsoft-says-kb5120998-windows-update-resets-desktop-settings/
22
13
Your Employee’s Password Appeared in an Infostealer Log. Now What? Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...] https://www.bleepingcomputer.com/news/security/your-employees-password-appeared-in-an-infostealer-log-now-what/
23
14
Critical Elementor Pro flaw exploited to take over WordPress sites A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...] https://www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-exploited-to-take-over-wordpress-sites/
26
15
Anthropic confirms Claude is down, multiple models affected Claude is experiencing an outage, with users encountering elevated errors when sending requests to multiple Anthropic AI models. [...] https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-confirms-claude-is-down-multiple-models-affected/
27
16
OpenAI confirms ChatGPT is down ahead of 'Astra' model launch ChatGPT and Codex are experiencing a major outage, with users reporting errors across nearly every major ChatGPT feature. [...] https://www.bleepingcomputer.com/news/artificial-intelligence/openai-confirms-chatgpt-is-down-ahead-of-astra-model-launch/
27
17
Microsoft: KB5120998 mouse reset bug affects only non-English PCs Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. [...] https://www.bleepingcomputer.com/news/microsoft/microsoft-kb5120998-mouse-reset-bug-affects-only-non-english-pcs/
31
18
HPE patches critical ArubaOS-CX remote code execution flaw Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. [...] https://www.bleepingcomputer.com/news/security/hpe-patches-critical-arubaos-cx-remote-code-execution-flaw/
33
19
Coder's registry infrastructure compromised to push malicious modules Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. [...] https://www.bleepingcomputer.com/news/security/coders-registry-infrastructure-compromised-to-push-malicious-modules/
40
20
French hospital fined €500,000 after breach exposes data of 727,000 France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients' and their relatives' data. [...] https://www.bleepingcomputer.com/news/security/french-hospital-fined-500-000-after-breach-exposes-data-of-727-000/
49