Search results for CVE
AI & Enterprise
CrowdStrike report flags vulnerability exploitation concentrated within 48 hours
CrowdStrike, in its 2026 Threat Hunting Report, said AI is shifting from an attack tool to a direct target and that the pace of vulnerability exploitation is speeding up to hours. It said attacks are spreading across AI infrastructure, access rights to corporate large language models, software supply chains and cloud resources. The report tracks more than 290 named attack groups from July 2025 to June 2026 and includes automated attacks. From January to June, 88 percent of cases saw exploitation within 48 hours of public proof-of-concept release.
AI & Enterprise
Ruby on Rails patches critical CVSS 9.5 flaw, urges update
Ruby-based web development framework Ruby on Rails has released a patch for a serious vulnerability that could allow unauthenticated attackers to execute remote code, SecurityWeek reported. The flaw, tracked as CVE-2026-66066 and rated 9.5 on the CVSS scale, involves arbitrary file reads that could expose secrets and enable lateral movement. Administrators urged users to update affected Active Storage versions and raise libvips to at least 8.13.
AI & Enterprise
JSecurity launches domain-based attack surface management, dark web data leak detection solution in Korea
JSecurity, a Japanese unit of Jiransoft Group, said it launched its domain-based attack surface management and dark web data leak detection solution, SafeIntelligence, in South Korea. The product is the first output from JSecurity X, the company’s R&D centre established in Korea. JSecurity said it is shifting from localising and distributing proven security tools in Japan to developing products itself, validating them in Korea first and then rolling them out in Japan.
-
AI & Enterprise
Ransomware targeting AI models emerges, encrypting training weights and raising recovery cost concerns
-
AI & Enterprise
Cl0p ransomware affiliate shows signs of exploiting PTC Windchill, FlexPLM flaw
-
AI & Enterprise
No time to respond to ultra-fast AI attacks, \'patch gap\' alarm
-
AI & Enterprise
Rise of zero trust, zero CVE security requires zero ops strategy
-
Games & Commerce
18-year-old Excel bug still used in attacks, warning for legacy Office users
-
AI & Enterprise
Tech Insight: Why software supply chains are being breached quickly amid the spread of AI coding
-
AI & Enterprise
VMware Aria Operations flaw exploited in real-world attacks