Subscribe to Updates
Get the latest business software news from BitComme.
Browsing: Flaw
Researchers warn the vulnerability could be used by state-linked actors for espionage.
Japan ‘s Digital Agency disclosed that attackers exploited a vulnerability in a VPN device to access its Government Solution Service (GSS), potentially leaking personal information belonging to approximately 246,000 government employees, public officials, and contractors. The breach was detected on June 25 and confirmed as a VPN exploitation on July 9, meaning the public disclosure…
GitLab users are being urged to patch a maximum severity vulnerability in the platform after reports of “in-the-wild” exploitation.
Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (FMC) flaws. The main target is CVE-2026-20079, a critical authentication bypass that lets unauthenticated attackers remotely bypass security controls, run scripts and potentially gain root access. Attackers also exploit CVE-2026-20316 to access sensitive data through a low-privilege account. The…
Users are urged to be careful about what they connect to AI services and the data shared
Security researchers warned the company of unusual threat activity in a recently updated N-able environment.
The vulnerability has a maximum severity score of 10, indicating serious potential impact and relative ease to exploit by an attacker.
A serious vulnerability in Apple’s macOS Screen Sharing service is being actively exploited to compromise internet-connected Macs, obtain root-level access and install Monero cryptocurrency miners, according to an urgent warning from the Netherlands’ National Cyber Security Centre.
The Dutch National Cyber Security Centre confirmed active exploitation of a critical macOS authentication flaw, tracked as CVE-2026-65400 (CVSS score of 9.8), less than two weeks after Apple shipped the fix.
A maximum-severity vulnerability in SAP Commerce Cloud is already attracting malicious activity, with researchers detecting exploitation attempts only three days after SAP released a security update.