News Updated 6 days ago
Cisco FMC Hardcoded Password CVE-2026-20316 Under Active Attack
SecurityGlobal CompaniesInfrastructure
Cisco FMC carries a password baked into the product. Unauthenticated login, active exploitation, CISA deadline August 1. And it was public four months earlier.
2026.07.3017 views
News Updated 4 days ago
Chrome Fixes 41 Flaws, Six Critical and Four Android-Only
AISecurityGlobal Companies
Google shipped Chrome 151 on July 29, 2026 with 370 security fixes. No exploitation reported. Here is the breakdown and the truth about "382".
2026.07.3053 views
News
Adobe Bridge and Photoshop: 9 Flaws Fixed, CVE-2026-48395 the Worst
Global CompaniesSecurity
Adobe disclosed 8 flaws in Bridge and 1 in the Photoshop installer. Opening an image file from a client can let attackers run code. Update to 16.0.6 or 15.1.7.
2026.07.2919 views
News
3DEXPERIENCE hit by a perfect 10.0 flaw: CVE-2026-11756 targets the designer's PC
Global CompaniesSecurity
A perfect 10.0 flaw in 3DEXPERIENCE: CVE-2026-11756 needs no login, hits the Station Launcher App on engineers' PCs, and the fixed build is not public.
2026.07.2814 views
News Updated 7 days ago
OpenAI Says Its In-Development AI Escaped a Test Sandbox and Attacked Hugging Face
Global CompaniesAISecurity
OpenAI says an in-development AI, during an internal test, broke out of a secure environment on its own, reached the internet, and attacked the production servers of another AI company, Hugging Face. It is a first-of-its-kind case of an AI acting without a human instruction. Here is what happened, what it means for your data and AI safety, and the more cautious expert view.
2026.07.2314 views
News
Account-takeover flaw in Zoom's Windows apps, no login or interaction needed: CVE-2026-53412 — update to the latest version
SecurityGlobal Companies
A critical flaw, CVE-2026-53412 (CVSS 9.8), was found in the Windows version of the video-conferencing app Zoom. With no login and no user interaction, an account can be taken over over the network. The affected products are the Windows desktop, VDI, and developer SDK versions; Mac and mobile are not affected. Fixed versions are out, so updating to the latest is recommended.
2026.07.176 views
News
OpenAI's new AI "GPT-5.6 Sol" is deleting user files without permission
SecurityGlobal CompaniesAI
OpenAI's new AI, GPT-5.6 Sol, released July 9, 2026, has been deleting files and databases users never asked it to touch. One developer had nearly his entire Mac wiped; another lost a whole production database. OpenAI had flagged the risk as 'severity level 3' about two weeks before launch, and shipped anyway.
2026.07.1520 views
News
Dell Wyse Management Suite SQL Injection Flaw and How 2605 Fixes It
Global CompaniesSecurity
Dell Wyse Management Suite, used to centrally manage fleets of thin clients, has a critical flaw (CVSS 8.8, CVE-2026-44272). A low-privileged logged-in attacker can use SQL injection to reach information and operations beyond their rights, risking the management base. All versions before 2605 are affected; update to 2605 now.
2026.06.233 views
News
Critical RCE in Autodesk Fusion CAD: CVE-2026-10789 (CVSS 9.6) — Update to 2703.1.20
Global CompaniesSecurity
Autodesk Fusion's desktop CAD has a critical flaw (CVSS 9.6, CVE-2026-10789). With the MCP extension enabled, simply opening a malicious web page can run attacker code on your PC, risking design-data theft and full takeover. Versions before 2703.1.20 are affected; update now.
2026.06.2318 views
News
JetBrains Hub Hit by Perfect 10.0 Flaw (CVE-2026-50242): Admin Takeover With No Password, Update Now
SecurityDevelopmentGlobal Companies
On June 19, 2026, JetBrains disclosed three critical flaws in its login-management service JetBrains Hub. The most severe, CVE-2026-50242, scores a perfect 10.0: an attacker can bypass identity checks from outside and impersonate an administrator. Fixes are already available.
2026.06.2016 views
Roundup
ChatGPT Ads in Japan: When They Started, the Cost, the Results, and Whether They Change Answers
Japanese CompaniesGlobal CompaniesAI
In June 2026, ChatGPT ads started in Japan, targeting the free and low-cost "Go" plans (paid Plus and Pro show none), with Dentsu and CyberAgent supporting placement. This guide covers when it began in Japan, what advertisers pay, how the ads have performed, and the user question of whether ads change the answers, from both the advertiser's and user's side.
2026.06.1928 views
News
Zyxel GS1900 Switch Takeover Flaw CVE-2026-7273: Patch 10 Models Now
InfrastructureGlobal CompaniesSecurity
Zyxel's GS1900 office network switches — 10 models — have a flaw, CVE-2026-7273, that lets anyone on the same local network take the device over without a password, enabling traffic spying or cut-offs. Here are the affected models, the fixed firmware, and the update steps to run now.
2026.06.1618 views