Latest CVE

The Hacker News

  • Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar

    @ (The Hacker News)
    A new CVE drops. Your scanner finds it. The severity score looks ugly.

    But that still does not answer the question that matters: Can it actually be exploited in your environment?

    Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still validate risk on weekly or quarterly cycles. The dangerous gap is no longer just technical. It is
  • Identity Visibility in 2026: The Foundation of Identity Security

    @ (The Hacker News)
    Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what identity visibility means in IAM, why cloud and multicloud environments complicate it, which capabilities matter in
  • Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

    @ (The Hacker News)
    Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository.

    The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system.

    This was security research,
  • SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

    @ (The Hacker News)
    SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability.

    The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior.

    "SolarWinds
  • Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

    @ (The Hacker News)
    A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet.

    The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution.

    "Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote
  • Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

    @ (The Hacker News)
    Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal.

    The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed
  • CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

    @ (The Hacker News)
    An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.

    The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May's supply chain attack on TanStack, in which malicious versions of TanStack's npm packages stole credentials from
  • CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

    @ (The Hacker News)
    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

    The vulnerabilities are listed below -


    CVE-2025-39682 (CVSS score: 9.8) - An improper check for unusual or exceptional conditions vulnerability in the TLS receive path
  • Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

    @ (The Hacker News)
    A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine.

    Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now public, and any machine still running an older kernel should be updated.

    The flaws
  • New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

    @ (The Hacker News)
    WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install.

    The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only
| Date published: Sat, 19 Sep 2026 20:43:01 +0530
Back to newsfeed list