WeSearch
Hub / Tags / Vulnerability
TAG · #VULNERABILITY

Vulnerability coverage.

Every story in the WeSearch catalog tagged with #vulnerability, chronological, with view counts. Subscribe to the per-tag RSS feed to follow this topic in your reader of choice.

60 stories tagged with #vulnerability, in publish-time order across the WeSearch catalog. Tag pages update as new stories ingest.

⌘ RSS feed for this tag →   or   search "Vulnerability"

RELATED TAGS
#security43#cybersecurity32#ai15#exploit9#microsoft8#linux8#windows7#open-source7#macos4#technology4#cve-2020-171034#devops3
PJ MEDIA

Platner’s Greatest Vulnerability Isn’t What You Think. It’s THIS — and Collins Must Use It ASAP

So how do you counterprogram an abusive Nazi weirdo extremist loser?…

15 views ·
TECHMEME

Privacy token Zcash plunges after the disclosure of a 2022 vulnerability in its Orchard shielded pool that could have allowed undetectable ZEC counterfeiting (Akash Girimath/Decrypt)

11 views ·
R/CYBERSECURITY

Hands Free: What LLM Driven Vulnerability Research Looks Like

21 views ·
R/CYBERSECURITY

Anthropic's coordinated vulnerability disclosure dashboard

25 views ·
R/NETSEC

EU CRA mandatory vulnerability reporting enters into force September 11, 2026 — what the 24-hour obligation requires

14 views ·
THE REGISTER

Another bug hunter leaks Microsoft exploits in defiance of company’s handling of vulnerability disclosures

Researchers follow in Nightmare Eclipse’s footsteps, flipping off Redmond in favor of insta-leaks…

22 views ·
#cybersecurity#microsoft
DEV.TO (TOP)

Genetic Diversity and Cyber Diversity: Why Monocultures Are Dangerous in Both Worlds

When I first learned about genetic diversity in biology, the idea felt simple: systems survive when...…

18 views ·
#cybersecurity#ai#diversity
LE MONDE (EN)

Romania wakes up to its vulnerability to Russian drones: 'We are theoretically in a country at peace, and this should not happen'

For the first time since Russia invaded Ukraine, a Russian drone struck a residential building in Romania on May 29, injuring two people. The incident, which occurred in the city o…

18 views ·
#military#security#international relations
THEREGISTER

Microsoft reaches for olive branch after public dustup with 0-day researcher

Following days of criticism from the security community, Redmond dials back rhetoric, insists vulnerability hunters not in its legal crosshairs…

20 views ·
#cybersecurity#research
CRYPTO BRIEFING

Microsoft threatens legal action against researcher Nightmare Eclipse for exploit disclosure

Microsoft threatens legal action against security researcher Nightmare Eclipse over zero-day exploit disclosures, raising concerns about chilling effects on crypto security researc…

15 views ·
#cybersecurity#legal
R/CYBERSECURITY

PAN-OS added to KEV, Langflow exploit activity, and a surprising Windows EPSS jump — today's most actionable vulnerability signals [Threat Intel 2026/5/29}

16 views ·
DEV.TO (TOP)

Automate Kubernetes Image Vulnerability Scanning

Security in a cloud-native environment is only as strong as its weakest link. A recent security audit...…

14 views ·
#kubernetes#devops#security
MICROSOFT

Microsoft: Protecting customers through Coordinated Vulnerability Disclosure

19 views ·
#cybersecurity#vulnerabilities#microsoft
GITHUB

CVE-Bench: testing LLM agents on real-world vulnerability patches

Benchmarking LLMs on real-world CVE patching…

20 views ·
#ai#security#vulnerabilities
THE REGISTER

No fix yet for critical RCE bug in open-source Git service Gogs - exploit module is out

Researcher reported the vuln in March. Maintainers haven't responded to his messages since…

18 views ·
#security#open-source
ARM NEWSROOM

Arm Metis with GPT5.5 Cyber scores 98% on firmware vulnerability benchmark

Arm Metis is an open-source agentic AI security framework that helps detect software vulnerabilities earlier.…

13 views ·
#technology#security#software
OPENCVE

Glibc CVE-2026-5450 9.8

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width gr…

9 views ·
#security#linux
MYSK BLOG – IN-DEPTH CYBERSECU

Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps

Until macOS 26.4, Archive Utility had nearly unrestricted filesystem access. Combined with a drag-and-drop sandbox quirk, this let an attacker bypass App Sandbox data containers, T…

17 views ·
#security#macos
NOSCOPE

Gitea CVE-2026-27771 exposed private container images without authentication

Gitea private container images were accessible to anyone on the internet, no credentials required, across healthcare, aerospace, and critical infrastructure worldwide.…

16 views ·
#security#gitea
ERLEF

Atom Exhaustion Is Not a Footgun. It's One Third of Our CVEs

9 views ·
#security#atom-exhaustion
R/LINUX

New Linux CIFSwitch Kernel Vulnerability Allows Attackers to Gain Root Access

17 views ·
PWN2NIMRON

Show HN: CVE-2026-40369 Windows Kernel Arbitrary Write Chrome SBX

16 views ·
#cybersecurity#exploit
ARXIV.ORG

Multi-Agent LLM System for Automated Vulnerability Discovery and Reproduction

Software vulnerabilities pose critical security threats, with nearly 50,000 CVEs reported in 2025. While Large Language Models (LLMs) show promise for automated vulnerability detec…

16 views ·
#security#software
TECHMEME

Starlette, an open-source Python framework underpinning FastAPI, has a vulnerability, called BadHost, that can allow hackers to bypass authorization (Dan Goodin/Ars Technica)

21 views ·
TECHRADAR

Worrying open-source security issue 'BadHost' could affect millions of AI agents, experts warn

The risk is "materially understated", researchers are saying as passwords and critical data can be exfiltrated.…

10 views ·
#security#open-source#ai
FIRETHERING

A One-Character Host Header Bug in Starlette Exposed AI Agents

One character. That's what it took to bypass authentication on millions of servers running AI agents, MCP tools, and the infrastructure connecting them to user data, email accounts…

17 views ·
#cybersecurity#ai#software
DEV.TO (TOP)

A Flask Vulnerability Walkthrough

Machine Problem 3 Group Members: Deen, Ligero, Torres Web applications, even simple ones, can carry...…

16 views ·
#flask#security#vulnerabilities
LITERARY HUB

What Happens When You Show Your Parents Your Debut Novel?

I gave my book to my partner before I gave it to my parents, figuring it was better to conquer one gut-churning fear at a time. I refused to watch him read it, but I was aware when…

22 views ·
#writing#family
R/PYTHON

Millions of AI agents imperiled by critical vulnerability in open source package

18 views ·
ARS TECHNICA

AI agents imperiled by critical vulnerability in open source package

BadHost" was found in Starlette, a package with 325 million weekly downloads.…

30 views ·
#cybersecurity#open-source
CRYPTO BRIEFING

Starlette vulnerability exposes millions of AI agents to hackers

A critical Starlette framework vulnerability threatens millions of AI agents, including crypto trading bots and DeFi tools built on FastAPI and Python.…

22 views ·
#cybersecurity#ai#crypto
SECWEST.NET - SECURE VIRTUAL E

BadHost: One Char Bypasses Host-Based Security Across the Python AI Stack

23 views ·
#security#python#ai
TECHRADAR

Ghost CMS flaw hijacked to target hundreds of websites with ClickFix attacks — here's how to stay safe

A critical-level flaw in a popular CMS, patched months ago, is now being abused.…

19 views ·
#cybersecurity#malware
DEV.TO (TOP)

The Business Context Problem: Why Vulnerability Severity Scores Lie

A critical vulnerability on an Alpine-based reverse proxy sitting behind three layers of network...…

15 views ·
#security#risk management
DEV.TO (TOP)

Your Clean Domain Could Be Masking an Attack: The Underminr Vulnerability Explained

Your domain has a good reputation. It resolves to a CDN edge IP that firewalls and protective DNS...…

18 views ·
#security#cyberattack
GITHUB

OWASP CVE Lite CLI

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remed…

15 views ·
#security#development
DEV.TO (TOP)

LLM Agents Are Now Finding Zero-Days: How AI is Autonomously Rewriting the Rules of Vulnerability Research

LLM Agents Are Now Finding Zero-Days: How AI is Autonomously Rewriting the Rules of...…

16 views ·
#security#ai#vulnerability-research
ZAUFANA TRZECIA STRONA

Login bypass vulnerability in Social Insurance, eCourt, and eHealth systems

Podatność umożliwiająca zalogowanie się na konto dowolnego użytkownika występowała w kilkunastu systemach administracji publicznej, w tym ZUS i CEZ. Wymagania? Dostęp do internetu,…

21 views ·
#cybersecurity#public administration
RUST-LANG

Security Advisory for Cargo (CVE-2026-5222)

Empowering everyone to build reliable and efficient software.…

15 views ·
#security#cargo
TECHRADAR

Trend Micro users beware - dangerous Apex One zero-day exploited in the wild

CISA has already added the flaw to its KEV database.…

17 views ·
#cybersecurity#trend micro
BRUTECAT

StubZero: $148,337 RCE in Google Cloud Production

A chance Discord message, two missing pieces, and one hour before the window closed: From info leak to RCE on Google Cloud. Three months later, it happened again.…

13 views ·
#security#google#cloud
DEV.TO (TOP)

I Benchmarked 17 ESLint Security Plugins. Only One Found Every Vulnerability.

I ran 40 real-world vulnerable patterns through every major ESLint security plugin — from eslint-plugin-security to SonarJS to Microsoft SDL. The detection gaps are alarming.…

15 views ·
#security#eslint#javascript
TENZAI RESEARCH

Vulnerability report written by AI hacker agent

Our AI Hacker found this, fixed it, and then (bragged) wrote about it: one endpoint, leaking tech stack info, whispering all its secrets to anyone who knew how to listen!…

11 views ·
#cybersecurity#ai#vulnerabilities
DEV.TO (TOP)

An npm Package for AI Agent Orchestration Just Shipped With Its Front Door Unlocked. Here's What the CVE Actually Reveals.

MCP ecosystem is growing fast enough that security researchers are now hunting it like any other...…

15 views ·
#security#ai#npm
VULNERABILITYSPOILERALERT

Vulnerability Spoiler Alert – Exposing Patches Before CVEs

AI-powered early warning for open-source security patches — before the CVE drops.…

14 views ·
#django#security
ARXIV CS.AI

Are Frontier LLMs Ready for Cybersecurity? Evidence for Vertical Foundation Models from Dual-Mode Vulnerability Benchmarks

We evaluate whether frontier LLMs are ready for cybersecurity through a dual-mode benchmark: white-box function-level vulnerability detection (VulnLLM-R, across C/Java/Python) and …

14 views ·
#cybersecurity#artificial intelligence#machine learning
R/CHANGEMYVIEW

CMV: Showing vulnerability as man is disadvantageous a majority of time

7 views ·
BLEEPINGCOMPUTER

Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows.…

15 views ·
#cybersecurity#ghost cms
THE GLOBE AND MAIL

Balancing intimacy and solitude in the shadow of cancer

Breast cancer has not changed who I am. It has clarified who I’ve always been…

16 views ·
#cancer#intimacy#solitude
BLOGSPOT

I bypassed AWS API Gateway auth with a trailing slash. Got $12K bounty

I was poking at a fintech’s mobile API and noticed something that made no sense. GET /v1/accounts returned 401. GET /v1/accounts/ returned...…

15 views ·
#api#security
QUALYS

Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel

The Qualys Threat Research Unit (TRU) has discovered and published the full advisory for CVE-2026-46333, a logic flaw in the Linux kernel’s __ptrace_may_access() function that perm…

16 views ·
#linux#security
R/CYBERSECURITY

How to continue when finding a possible Vulnerability but local law prohibits me from investigating further

11 views ·
ANTHROPIC

Anthropic's coordinated vulnerability disclosure dashboard

14 views ·
#security#open-source#vulnerabilities
VECHRON

I reproduced a Claude Code RCE. The bug pattern is everywhere

Last week, security researcher Joernchen published a clever RCE in Claude Code 2.1.118. I spent Saturday reproducing it from the advisory to understand the…

17 views ·
#security#ai
DEV.TO (TOP)

Why your vulnerability dashboard is lying to you (and how to fix it)

You open your vulnerability dashboard on a Monday morning and see 47 critical CVEs across 12 assets....…

16 views ·
#security#devsecops#vulnerabilities
SOCKET

Laravel Lang Compromised with RCE Backdoor Across 700 Versions

Laravel Lang packages were compromised with an RCE backdoor across hundreds of versions, exposing cloud, CI/CD, and developer secrets.…

12 views ·
#security#laravel
SOCKET

Malicious Postinstall Hook Found in 700 GitHub Repos, Including Node Projects

Socket found a malicious postinstall hook across 700+ GitHub repos, including PHP packages on Packagist and Node.js project repositories.…

13 views ·
#security#github#nodejs
TECHRADAR

Another major Linux security flaw revealed — nine-year old issue could spell disaster for users

There was a way to elevate normal Linux users' privileges to root, granting threat actors admin access.…

13 views ·
#linux#security
PUSH SQUARE (PS)

'It's Nuts': Major PS5 Security Vulnerability Exposed, And We're All At Risk

Social engineering scam uncovered…

13 views ·
#gaming#security#sony
PHYS.ORG

Heat vulnerability follows more than temperature, and this global map exposes the overlooked fault lines

14 views ·