
CoreBreak Flaws Let Attackers Invoke AWS, Google, Vercel Tools
Stealth researchers disclosed CoreBreak flaws in AWS Bedrock, Google ADK, and Vercel harnesses that let attackers invoke agent tools without

Stealth researchers disclosed CoreBreak flaws in AWS Bedrock, Google ADK, and Vercel harnesses that let attackers invoke agent tools without

Cisco patched two dozen flaws including critical Catalyst SD-WAN and IOS XE command-injection bugs plus an FMC authentication bypass in

CISA added actively exploited Langflow and Apache Tomcat vulnerabilities to the KEV catalog, linking the Tomcat flaw to an AI-enabled

cPanel patched CVE-2026-58048, a CVSS 9.4 privilege-escalation flaw letting an authenticated hosting customer execute SQL in the database root context.

Forescout disclosed 15 TP-Link Omada zero-touch provisioning vulnerabilities that chain with earlier RCE flaws into full fleet-wide network compromise.

Thermo Fisher patched CVE-2026-17583 in Applied Biosystems DNA-testing software, allowing forensic evidence file alterations to pass with little detection.

FaceHugger flaws in Hugging Face Diffusers bypass trust_remote_code and let malicious model repositories execute arbitrary code when models are loaded.

N-able warns attackers exploited CVE-2026-18577 to take over N-central servers and reach managed endpoints, planting Cloudflare tunnels for persistent access.

CISA added the Cisco FMC zero-day CVE-2026-20316 to the KEV after active exploitation began. Cisco is also patching a critical

The Rails framework patched CVE-2026-66066, a critical Active Storage flaw letting unauthenticated attackers read server files via crafted image uploads.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.