Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > cve
#cve

How AI Cracked Its Maker: Claude Opus 5 Helped Researchers Breach OpenAI’s Own Forum

19 September 2026  |  dark6  |  Vulnerability

Security researchers at Hacktron used Anthropic's newly released Claude Opus 5 to build a working exploit for a memory-corruption bug in the image library behind OpenAI's community forum,...

>> read more

Chrome 153 Patches 42 Security Flaws, Including Three Critical Memory Bugs

16 September 2026  |  dark6  |  Vulnerability

Google’s Chrome 153 stable update closes 42 vulnerabilities, including three critical memory-safety issues in Internals, Workers and WebGL. Users and administrators should ensure the browser has restarted on...

>> read more

MapLibre Sanitizer Bug Puts 2.7 Million Sites at Risk of Zero-Click Code Execution

10 September 2026  |  dark6  |  Vulnerability

A critical flaw in the widely used MapLibre GL JS mapping library lets attackers slip malicious event handlers past its HTML sanitizer, triggering code execution with no clicks...

>> read more

Critical ServiceNow AI Flaws Expose Enterprise Data and Code Execution Paths

29 August 2026  |  dark6  |  Vulnerability

ServiceNow has patched three critical AI-platform vulnerabilities and a high-severity Now Platform sandbox escape. Self-hosted customers should urgently verify fixed releases and investigate signs of unauthorized code execution...

>> read more

Arista VeloCloud SD-WAN Orchestrators Under Active Attack via Maximum-Severity Command Injection Flaw

4 August 2026  |  dark6  |  Vulnerability

A perfect-10 command injection vulnerability in on-premises Arista VeloCloud Orchestrator deployments is being actively exploited, letting unauthenticated attackers reach privileged internal functions over the exposed web interface. Patches...

>> read more

Five-Year-Old Bugs in a JSON Parser Open a Code Execution Hole in Self-Managed GitLab

27 July 2026  |  dark6  |  Vulnerability

Researchers chained two long-dormant memory-safety bugs in Ruby's Oj JSON parser to achieve remote code execution on self-managed GitLab instances, using nothing more than an ordinary commit and...

>> read more

JetBrains Patches a Wave of Critical Flaws Across IntelliJ IDEA and TeamCity

27 July 2026  |  dark6  |  Vulnerability

JetBrains has released fixes for a critical remote-code-execution flaw in IntelliJ IDEA and four high-severity vulnerabilities in TeamCity, including a critical RCE reachable through malicious Git repository configuration....

>> read more

RefluXFS: A Nine-Year-Old Race Condition in Linux’s XFS Filesystem Opens a Silent Road to Root

23 July 2026  |  dark6  |  Vulnerability

Qualys researchers have disclosed RefluXFS (CVE-2026-64600), a race condition in the Linux kernel's XFS copy-on-write path that lets a local, unprivileged user seize root access while leaving no...

>> read more