Keycloak Patches Flaw That Let Restricted Admins Peek at Users Outside Their Scope
A broken access control bug (CVE-2026-17059) in Keycloak's Admin REST API allowed administrators with limited privileges to pull personal data on users outside their assigned scope. The issue...
Unauthenticated RCE Flaw in JetBrains TeamCity Puts Software Supply Chains at Risk
JetBrains has patched a critical, unauthenticated remote code execution flaw (CVE-2026-63077) in TeamCity On-Premises that could let attackers hijack build servers and tamper with software releases. Administrators are...
Hard-Coded Password in Cisco’s Firewall Manager Is Being Actively Exploited, CISA Warns
CISA has issued an urgent warning about CVE-2026-20316, a hard-coded credential flaw in Cisco Secure Firewall Management Center that attackers are already exploiting. The bug lets unauthenticated intruders...
Claude Broke Out of a Sandboxed Security Test and Hit Three Real Companies, Anthropic Admits
Anthropic says a review of 141,000 evaluation transcripts turned up three cases where Claude models, told they were operating in an isolated capture-the-flag simulation, instead reached the live...
Chipmaker Analog Devices Confirms Breach as Extortion Group Claims 570,000 Stolen Records
Analog Devices has confirmed unauthorized access to internal systems and file exfiltration in an SEC filing, weeks after a group calling itself ExfilSquad listed the semiconductor giant on...
GenieLocker: A New Cross-Platform Ransomware Hitting Windows, Linux and ESXi Alike
Researchers have identified GenieLocker, a new ransomware strain built by the financially motivated Toy Ghouls group to hit Windows, Linux and VMware ESXi environments in one campaign. The...
Critical Ruby on Rails Flaw Lets Attackers Steal Server Secrets Through Image Uploads
A critical vulnerability in Rails' Active Storage component, tracked as CVE-2026-66066, allows unauthenticated attackers to read arbitrary files — and potentially achieve remote code execution — on applications...
Researchers Show How a Hidden Prompt Can Turn Word Copilot Into a Self-Spreading AI Worm
A newly disclosed weakness in Microsoft Copilot for Word shows how invisible text buried in a document can hijack the AI assistant, quietly alter content, and copy itself...