Apache HTTP Server 2.4.69 Fixes 20 Flaws Across CGI, WebDAV and Proxy Modules
Apache HTTP Server 2.4.69 addresses 20 vulnerabilities that can cause code execution, memory corruption, crashes, data exposure or authentication problems under particular configurations. Administrators should upgrade, but risk-based...
ServiceNow Rushes Fixes for Five AI Platform Bugs After Two Are Rated Critical
ServiceNow has patched five vulnerabilities in its AI Platform, including a SQL injection flaw and a missing-authorization bug that together could let an unauthenticated attacker read, alter, or...
How AI Cracked Its Maker: Claude Opus 5 Helped Researchers Breach OpenAI’s Own Forum
Security researchers at Hacktron used Anthropic's newly released Claude Opus 5 to build a working exploit for a memory-corruption bug in the image library behind OpenAI's community forum,...
Chrome 153 Patches 42 Security Flaws, Including Three Critical Memory Bugs
Google’s Chrome 153 stable update closes 42 vulnerabilities, including three critical memory-safety issues in Internals, Workers and WebGL. Users and administrators should ensure the browser has restarted on...
MapLibre Sanitizer Bug Puts 2.7 Million Sites at Risk of Zero-Click Code Execution
A critical flaw in the widely used MapLibre GL JS mapping library lets attackers slip malicious event handlers past its HTML sanitizer, triggering code execution with no clicks...
Critical ServiceNow AI Flaws Expose Enterprise Data and Code Execution Paths
ServiceNow has patched three critical AI-platform vulnerabilities and a high-severity Now Platform sandbox escape. Self-hosted customers should urgently verify fixed releases and investigate signs of unauthorized code execution...
Arista VeloCloud SD-WAN Orchestrators Under Active Attack via Maximum-Severity Command Injection Flaw
A perfect-10 command injection vulnerability in on-premises Arista VeloCloud Orchestrator deployments is being actively exploited, letting unauthenticated attackers reach privileged internal functions over the exposed web interface. Patches...
Five-Year-Old Bugs in a JSON Parser Open a Code Execution Hole in Self-Managed GitLab
Researchers chained two long-dormant memory-safety bugs in Ruby's Oj JSON parser to achieve remote code execution on self-managed GitLab instances, using nothing more than an ordinary commit and...