vulnerability
239 stories on vulnerability, newest first, from 273 briefings. Each is a plain-language summary written here for Australian business, with a link to the original reporting. Where several outlets covered the same event, the rest sit under it as extra coverage.
-
Citrix NetScaler Under Attack Again: Critical Flaws Being Exploited Right Now
Also covered by The Hacker News
- Citrix Confirms Active Attacks on Netscaler Zero-Day Flaws, Urgent Patching Advised
- ACSC Issues Critical Alert on Actively Exploited Citrix NetScaler Vulnerabilities
- Urgent: Citrix NetScaler Devices Under Active Attack, Patch Immediately
- Attackers Bypass Firewalls to Exploit Critical Oracle PeopleSoft Flaw
- CISA Flags Actively Exploited Flaws in Microsoft SharePoint and MikroTik Routers
- Kiteworks Tells Customers to Shut Down Systems Amid Zero-Day Threat Warning
- CISA Warns of Active Exploitation of WSO2 and Adobe Commerce Vulnerabilities
- Unpatched OnePlus Bugs Let Malicious Apps Gain Root Access Without Warning
- Critical WordPress Flaw Under Active Attack Within Hours of Patch Release
- Two Chained MikroTik Flaws Let Attackers Bypass Login Entirely: Patch Now
- Critical cPanel Flaw Lets Hosting Customers Seize Full Server Control
- Unpatched Ubuntu Kernel Flaw Lets Attackers Escape Containers and Take Over the Host
- F5 Patches Critical BIG-IP Flaw Already Being Exploited to Hijack Systems Without a Password
- Critical Next.js Flaw Lets Attackers Run Code via Image Previews
- WordPress Patches Critical Flaw Allowing Unauthenticated Code Execution on Some Sites
- Critical Bifrost AI Gateway Bug Lets Attackers Run Commands With No Login Required
- New Unpatched Tool Can Silently Stop Microsoft Defender Updates
- Critical Flaw in VeloCloud SD-WAN Management Server Under Active Attack
- Linux Kernel Bug Lets ARM64 Virtual Machines Peek Into Host Memory
- Mislabelled SharePoint Bug Was Actually a Critical Remote Code Execution Flaw
- WordPress Fixes 'Comment2Shell' Flaw That Let Anonymous Comments Hijack Admin Sessions
- Researcher Warns Against Installing Meta's Muse AI Assistant on Mac
- Cisco Fixes Critical ISE Flaw Already Under Attack, Plus Rising ClickFix and Browser Threats
- SolarWinds Fixes Critical Flaw Letting Attackers Take Over Access Rights Manager Without Login
- Critical Flaw in Orkes Conductor Being Actively Exploited, Patch Now
- Public Exploits Now Available for Four Linux Kernel Root Flaws
- AI-Discovered Flaw in Common Image Decoders Could Expose Business Data
- WordPress Patches 'Click2Shell' Flaw That Could Let Attackers Hijack Admin Sessions
- 'Plugin4Shell' Flaw Lets Malicious Code Slip Past Version Locks in AI Coding Agents
- Critical Docker Sandboxes Flaw Let Malicious Code Escape to macOS Host Files
- Critical Flaw in Unbound DNS Software Could Let Attackers Run Malicious Code
- Cisco Warns Critical ISE Flaw Is Being Actively Exploited
- Cisco Warns of Actively Exploited Flaw in Secure Email Gateway Devices
- Critical Issabel PBX Flaw Under Active Attack: Hard-Coded Key Lets Hackers Run Commands
- One Malicious Browser Extension Could Hijack AI Assistants in Chrome, Edge, Comet and Opera Neon
- Acronis Warns of Actively Exploited Flaw in cPanel Backup Plugin
- Google Patches Pixel Zero-Day Exploited in Targeted Attacks
- Critical WooCommerce Plugin Flaw Lets Hackers Plant Backdoors on WordPress Sites
- Critical WSO2 API Manager Flaw Under Active Attack: Patch Now
-
Cisco Email Gateways Under Active Attack: Patch Now
Also covered by The Hacker News
- Siemens Mendix SAML Flaw Could Let Attackers Hijack Login Sessions
- Attackers Are Scanning for Exposed Vite Dev Servers to Steal Cloud Credentials
- Telegram Desktop Bug Let Hidden Code Steal Messages From Exported Chat Files
-
Critical GitLab Flaw Under Active Attack: Patch Now or Take Servers Offline
Also covered by Infosecurity Magazine, CyberScoop
- Critical Bug Fixed in Bitcoin Lightning Network Development Kit
- Bitcoin Bridge Bug Lets Hacker Mint Billions in Fake Tokens
- XPR Network Loses $9M in Smart Contract Exploit, Shaking Investor Confidence
- AI Agents Linked to Mass Upload of Malicious Packages on RubyGems
-
Blockstream Refuses Ransom Demand After $46 Million Bitcoin Theft on Liquid Network
Also covered by Blockonomi
- Maximum-Severity GitLab Flaw Under Active Attack Within Hours of Disclosure
- Liquid Network Bug Let Attacker Mint Fake Bitcoin Without a Single Stolen Key
- Actively Exploited GitLab Vulnerability Added to US Government Threat List
- Critical Flaw in Alby Hub Bitcoin Lightning Node Software: Check Your Version Now
- PaperCut Rolls Out Full Fixes as Attackers Use AI Agents to Exploit Print Software Flaws
-
Liquid Network Restores Operations After $320M Bitcoin Sidechain Exploit
Also covered by Blockonomi, Cointelegraph, Bitcoin
- JFrog Artifactory Under Active Attack: Patch These Three Vulnerabilities Now
- Security Flaws Found in NextGen Healthcare's Mirth Connect Software
- Critical Adobe Commerce and Magento Flaw Under Active Attack: Patch Now
- Cisco Firewall Management Software Under Active Attack: Patch Now
- Critical Flaws in Popular AI Gateway LiteLLM Let Attackers Hijack Servers and Steal Cloud Credentials
- DeepSeek AI Coding Tool Flaw Let Agents Turn Off Their Own Security Sandbox
- Critical Flaw in Alby Hub Bitcoin Wallet Software: Update Now if Internet-Exposed
- Google Patches Actively Exploited Chrome Zero-Day: Update Now
- cPanel Patches Flaw Letting a Single Mail Account Seize Root Control of Your Server
- F5 BIG-IP APM Attackers Hide Malware in Memory to Dodge Disk Scans
- Microsoft Defender's ShieldBreak Fix Bypassed: New PoC Shows Flaw Still Exploitable
- Maximum-Severity SAP Flaw Lets Attackers Take Over Systems Without a Password
- Critical N-able N-central Flaw Actively Exploited, CISA Sets Patch Deadline
- Liquid Network Hackers Return Most of $320M in Bitcoin After Elements Bug Exploit
- Critical FreeIPA Bug Lets Anonymous Users Create Their Own Admin Account
- Bitcoin Bridge Hack Sees $270 Million Returned, But Not All of It
-
Liquid Network Recovers Most of $320M After Bitcoin Bridge Flaw Exploited
Also covered by Crypto Briefing
- Liquid Network Bridge Exploit: $269M Returned, $47M Still Missing
- Hackers Return Most of $320M Stolen from Liquid Bitcoin Network, Keep $47M
- Weekly Threat Report: Authentication Bypass Flaw Found in JFrog Artifactory
- Weekly Threat Recap: Trusted Software Turned Malicious, Critical N-central Flaws Under Attack
- Coldcard Wallet Exploit: Stolen Bitcoin Now Being Laundered as Attacker Cashes Out
- N-able Patches Critical Flaw in N-central Remote Management Platform
- Public Exploit Released for Telerik UI Flaw Chain Enabling Unauthenticated Server Takeover
- N-able Rushes Out Fourth N-central Hotfix in Five Weeks for Critical Unauthenticated RCE Bug
- Hackers Behind $320M Liquid Network Withdrawal Signal Willingness to Return Funds
- $320 Million in Bitcoin Withdrawn from Liquid Network by Self-Described 'White Hat' Hackers
- JetBrains Cadence Breach: Attackers Exploited Unpatched TeamCity to Steal AWS Credentials
- VMware Patches Critical Flaw That Lets VM Users Break Out to the Host Machine
- Schools and Universities Targeted as Hackers Exploit PaperCut Print Software Flaws
- HPE Fixes Critical Flaws in AOS-CX Switch Software
- PostgreSQL Patches Decade-Old Flaw Allowing Code Execution via Replication Accounts
- 12-Year-Old PostgreSQL Flaw Could Let Attackers Hijack Your Database and Server
- Critical VMware Flaws Could Let Attackers Break Out of Virtual Machines
- 440,000+ Attacks Target Critical WordPress Plugin Flaws — Is Your Site at Risk?
- Critical Security Flaws Found in Citrix NetScaler Devices — Patch Immediately
- Cisco Flags Unpatched Email Encryption Flaws, Rushes Fixes for Critical Switch Bugs
- Critical Flaw Chain in GeoNetwork Could Let Attackers Take Over Government Geoportal Systems
- Critical Flaw in Sangoma Switchvox VoIP Systems Being Actively Exploited
-
SonicWall Warns of Two Zero-Day Flaws Under Active Attack in SMA1000 Devices
Also covered by Sophos
-
Critical Flaw in JFrog Artifactory Under Active Attack—Patch Now
Also covered by Security Week
- Hackers Race to Exploit Critical JFrog Artifactory Bug Just Days After Patch Release
-
Critical Langflow Flaw Under Active Attack — Patch Now
Also covered by The Hacker News, Security Week
- Critical Flaws Found in WatchGuard Firewalls — Patch Now
- Rounding Flaw in Old DeFi Protocol Leads to $234,000 Theft
- Vulnerability Found in Kaspersky Endpoint Security Now Patched
- ServiceNow Fixes Three Critical Flaws That Could Let Attackers Hijack Systems
-
Urgent: Actively Exploited Vulnerabilities Found in PaperCut Print Management Software
Also covered by The Hacker News
- PaperCut Issues Second Emergency Patch as Attackers Exploit Print Management Software
- Crypto Card Vulnerability Exploited: Rain Refunds Affected Customers After Avici Incident
- Critical WordPress Plugin and Theme Bugs Put Sites at Risk of Takeover
- Urgent Patch Needed: PaperCut Print Software Flaws Let Hackers Take Over Without Login
- Critical ownCloud Flaw Exploited in Attack on Philippine Nuclear Research Agency
- Security Researchers Replicate Ledger Hardware Wallet Vulnerability
- Ledger Patches Ethereum App Flaw That Could Have Let Attackers Swap Transactions
- Next.js Rushes Out Fixes for Two Critical Bugs Allowing Remote Takeover
- Emergency Security Warning Issued for Bitcoin's Core Lightning Software
- US Cybersecurity Agency Flags 3 Actively Exploited Software Flaws — Check If You Use Them
- Critical Security Flaws Found in Xiiaozet LK100W Devices
- Critical Security Flaws Found in Ebyte NA111-M Industrial Device
- Critical Flaws Found in ASE2000 Industrial Test Tool Used in Energy and Water Sectors
- AI Uncovers Critical Security Flaw in Bitcoin's Lightning Network
- Urgent: Citrix NetScaler Flaw Under Active Attack — Patch Now
- Bitcoin Lightning Network Flaws Confirmed – Patch Coming Soon
-
Critical Flaw Found in Ledger's Ethereum Wallet App
Also covered by Blockonomi, Crypto news, Crypto Briefing
- Unpatched Flaws in Popular Video Player Software Could Let Hackers Steal Files and Run Code
- Critical Gitea Flaw Under Active Attack — Patch Now Before It Drops Malware
- CISA Alerts Businesses to Actively Exploited Gitea Vulnerability
- Security Flaw in NVIDIA AI Tool Could Let Hackers Poison Business AI Assistants
- Security Flaw in NVIDIA's NemoClaw Could Let Hackers Hijack Local AI Models
- Security Flaw Found in Rently Smart Home Devices Could Expose User Data
- Security Flaw Found in PayRange Payment API Could Expose Sensitive Data
- Critical Flaws Found in Bendix Truck Brake Control Systems
- Critical Flaw in ZoneMinder Video Surveillance Software Could Allow Full Server Takeover
- Hackers Actively Exploiting WordPress SAML Login Plugin Flaws
- CISA Warns of Active Exploitation of Oracle WebLogic Vulnerability
- Urgent Zimbra Email Flaw Under Attack: Patch Now, Experts Warn
-
CISA Flags Actively Exploited Oracle Server Vulnerability - Patch Now
Also covered by CISA
- Critical Keycloak Flaw Lets Hackers Hijack Accounts Without a Password
- Urgent: Active Attacks Targeting TeamCity Servers in Australia
- Crypto Bridge Exploit Shows How a Single Coding Flaw Can Be Catastrophic
- Coldcard Wallet Maker Tightens Security After $130M Bitcoin Theft Linked to Old Flaw
- BounceBit Shuts Down Its Blockchain After Hackers Exploit Security Flaw
- Critical Flaw in 'Isolated-vm' Tool Could Let Attackers Take Over Host Systems
- Actively Exploited Zimbra Flaw Added to CISA's Must-Patch List
- CISA Warns Businesses to Urgently Patch Exploited TrueConf Software Flaws
-
Critical GitLab Flaw Under Active Attack — Patch Immediately
Also covered by Security Week, The Hacker News
- Critical Microsoft Entra ID Flaw Exploited in the Wild — But No Action Needed From Customers
- Password Vault Flaw Puts MSP and SMB Credentials at Risk
- Active Attacks Target Zimbra Email Servers via Newly Disclosed Flaw
- Critical Flaw Found in Popular JavaScript Sandbox Tool 'isolated-vm'
- Critical MLflow Flaw Being Exploited to Steal Cloud Credentials
- Critical Flaws Found in NASA Spacecraft Control Software Could Allow Unauthorized Commands
- Critical Citrix NetScaler Flaw Lets Attackers Bypass Login — Patch Now
- Critical Elementor Pro Flaw Lets Hackers Take Over WordPress Sites Without Logging In
- Maya Protocol Halted After Attacker Exploits Six Bugs to Steal $1.4 Million in Bitcoin
- Over 14,500 Dahua Cameras Hacked in Global Attack Campaign
- Urgent: Patch Now — Microsoft, VMware and Apple Flaws Under Active Attack
- Decred Cryptocurrency Network Patches Critical Security Flaws
- Cross-Chain Trading Platform Loses $11 Million in Bitcoin After Exploit
- Critical GitLab Zero-Click Flaw Leaves Self-Managed Users Guessing
- Siemens Simcenter Nastran Vulnerability Could Allow Remote Code Execution
- Multiple Security Flaws Found in CISA's Malcolm Network Monitoring Tool
- WordPress Form Plugin Flaw Puts 300,000 Sites at Risk of Takeover
- Critical GitLab Flaw Let Attackers Tamper With Data Without Logging In
-
Attackers Exploit macOS Screen Sharing Flaw to Hijack Macs for Crypto Mining
Also covered by Security Week, The Currency Analytics
- Apple Patches Dozens of WebKit Flaws in Latest macOS and iOS Updates
- US Cybersecurity Agency Warns of Actively Exploited Flaw in AI Framework 'Ray'
- Old Coldcard Wallet Flaw Blamed for $115 Million in Stolen Bitcoin
- Years-Old Coldcard Wallet Flaw Still Being Exploited to Steal Bitcoin
- Answering a Video Call Could Hijack Your Android Phone, Researchers Warn
-
macOS Screen Sharing Flaw Exploited to Secretly Mine Cryptocurrency
Also covered by Dailycoin, Blockonomi, The Block
- SAP Commerce Cloud Under Attack Just Days After Critical Flaw Disclosed
- Suspected China-Linked Hackers Exploit Critical VMware vCenter Flaw to Deploy Ransomware
- SafePal Data Breach Exposes Nearly 40,000 Users' Personal Information
- Critical macOS Screen Sharing Bug Actively Exploited to Install Crypto Miners
- Security Audit Catches Critical XRP Ledger Bugs Before They Could Be Exploited
- Security Scanner Bug, Not LiteLLM, Behind Breach Affecting 2,500 Organisations
- Hackers Actively Exploiting Unpatched Flaw in GeoServer Software
-
Critical VMware vCenter Vulnerability Under Active Global Attack
Also covered by Security Week
- Hackers Move Fast: Adobe Commerce Flaw Exploited Right After Patch Release
- WordPress Patch Fixes Serious Remote Code Execution Flaw
- Siemens Solid Edge Software Vulnerable to Malicious File Attacks
- Siemens Parasolid Software Vulnerable to File-Based Attack, Update Urged
- Siemens LOGO! Soft Comfort Software Has Encryption Flaws — Update Now
- Siemens License Server Flaws Could Let Attackers Elevate Privileges, Access Files
- Security Flaw Found in Flow Neuroscience Brain Stimulation Device
- Critical Flaw Found in Siemens Video Management Software—Update Now
- Fortinet Fixes Critical Login Flaws in FortiWeb and FortiManager
-
New Windows Zero-Day 'ShieldBreak' Lets Attackers Gain Full System Control
Also covered by The Hacker News
-
Hackers Actively Targeting SharePoint Flaw After Exploit Code Goes Public
Also covered by Security Week
- Adobe Issues Urgent Patches for Critical ColdFusion and Campaign Classic Vulnerabilities
- Critical VMware vCenter Flaw Now Under Active Attack, Giving Hackers Persistent Access
- Ivanti Patches Remotely Exploitable Flaws in Endpoint Manager
- Critical SAP Commerce Cloud Flaw Rated Maximum Severity — Patch Now
- Cisco Firewall Flaw Being Actively Exploited to Crash Devices
- Fake Deposit Bug Lets Hackers Steal $200K in Cryptocurrency Bridge Attack
- Zoom's Drawing Tool Had a Dangerous Flaw — Update Now
-
BTCPay Server Community Offers Bounty After Critical Flaw Exploited
Also covered by Crypto Economy
- Zoom Fixes Serious Flaw That Let Meeting Attendees Hack Other Participants
- Hardware Wallet Exploit Sparks Wave of Bitcoin Fund Transfers
- Critical Flaws Found in Johnson Controls Access Control Systems
- Ravencoin Warns of Critical Bug That Could Let Attackers Rewrite Transaction History
- Critical Flaw in Ravencoin's KAWPOW Algorithm Exploited, Forcing Major Blockchain Rollback
- BTCPay Server Backers Offer 3 BTC Bounty Following Critical Exploit
- BTCPay Server Hit by Critical Exploit; Bounty Offered for Recovery
- Cisco Flags High-Severity Flaws in ClamAV Antivirus Software—Exploit Code Already Public
-
Urgent Patch Alert: Actively Exploited Flaw Found in Progress LoadMaster Software
Also covered by CISA
-
Critical BTCPay Server Flaw Lets Attackers Drain Bitcoin Lightning Nodes
Also covered by Blockonomi
- One-Click Flaw in Atlassian's Rovo AI Could Have Exposed Business Data
- Critical Metabase Flaw Being Actively Exploited — Patch Immediately
-
BTCPay Server Users Urged to Update After Critical Flaw Exploited to Steal Funds
Also covered by Bitcoin, Crypto Economy
- Bitcoin Payment Tool Exploit Lets Attackers Drain Merchant Wallets
- BTCPay Server Rushes Out Emergency Patch After Two-Factor Bypass Found
- Bitcoin Users Targeted: Trezor Phishing Ad and BTCPay Server Flaw Under Active Attack
- Critical WordPress Flaw Could Let Hackers Take Over Your Website — Update Now
- Decades-Old Linux Kernel Flaw Lets Attackers Escape Containers and Seize Root Access
- Microsoft and Apple Roll Out Critical Security Patches — Update Now
- Volunteer Hackers Uncover Nearly 5,000 Flaws in Bitcoin Software After Wallet Hack
- New 'Zapscape' Flaw Could Let Attackers Break Out of Virtual Machines
- Cisco Fixes 12 Security Flaws in SD-WAN and IOS XE Software, Three Rated Critical
- Bitcoin Ecosystem Audit Uncovers Nearly 5,000 Security Flaws
- Security Flaw Found in Medixant RadiAnt DICOM Medical Imaging Software
- Critical Flaw in Paperclip Software Could Have Let Attackers Seize Admin Control
- Critical JetBrains TeamCity Flaw Now Under Active Attack
- Researchers Uncover $50,000 Exploit Chain Targeting Samsung Phones via Bixby
- 15 Security Flaws Found in TP-Link Devices Raise Questions About Automated Network Setup
- Critical Flaws Patched in Veeam, HashiCorp Terraform MCP, and Django - Update Now
- Linux Kernel Flaw Lets Local Users Seize Full Control of Systems
- US Cyber Agency Warns: Attackers Actively Exploiting Flaws in Popular Business Software
- Coldcard Wallet Flaw Blamed on Faulty Code, Losses Near $120M
-
Coldcard Wallet Flaw Linked to $100 Million in Bitcoin Losses
Also covered by Crypto news
- 15 Security Flaws Found in TP-Link Omada Networking Gear
- cPanel Fixes Critical Flaw Allowing Hosting Customers to Run SQL as Database Root
- Coldcard Warns Bitcoin Hardware Wallet Users: Active Exploit Still Draining Funds
- CISA Warns: N-able N-central Flaw Actively Exploited, Patch Now
- Urgent: New Bypass Flaw Found in N-able RMM Software Gives Attackers Admin Access
- Coldcard Hardware Wallet Flaw Exposes Weakness in Bitcoin Key Generation
- Coldcard Wallet Exploit Shows Even 'Offline' Storage Isn't Foolproof
- N-able Rushes Out Fix After Hackers Bypass Patch for N-central Servers
- Actively Exploited Flaw Found in N-able N-central: What SMBs Using Remote Management Tools Need to Know
- Hardware Wallet Flaw Blamed for Nearly $90 Million in Bitcoin Thefts
- Apple Patches macOS Terminal Flaw Used to Sneak Data Out via DNS Requests