
Google pauses open-source bug bounty amid AI spam
Google has suspended its Open Source Software Vulnerability Rewards Program after an influx of AI-generated submissions overwhelmed triage teams.

Google has suspended its Open Source Software Vulnerability Rewards Program after an influx of AI-generated submissions overwhelmed triage teams.

GitLab issued an urgent patch for a critical remote-code-execution vulnerability in its AI Gateway service, affecting self-managed instances.

Fortinet has disclosed a critical vulnerability in FortiMail being exploited as a zero-day, urging customers to monitor updates and apply mitigations.

Cisco has released emergency fixes for a zero-day vulnerability in its Catalyst SD-WAN Manager that attackers are already exploiting to gain admin privileges. The flaw, tracked as CVE-2026-76504, was discovered during ongoing investigations into active intrusions targeting enterprise networks.

Cloudflare has rolled out beta support for an IETF draft extension that prevents quantum downgrade attacks on IPsec by requiring full transcript authentication, available to enterprise customers via feature flag.

Over 16,000 Supabase databases were found misconfigured, exposing personally identifiable information, passwords, and authentication tokens due to improper access controls.

Two unpatched Citrix NetScaler zero-day vulnerabilities are under active exploitation, with patches expected next week. Operators are advised to shut down appliances until fixes are released.

Cloudflare fixed a vulnerability in its Workers platform that allowed paid customers to recover residual data from other users' containers on shared hosts, exposing sensitive information.

Kiteworks instructed all customers to shut down servers for six hours on Saturday after receiving threat intelligence about a potential zero-day attack, with no patch available.

Research by OX Security finds widespread Model Context Protocol servers lacking governance over location, domain ownership, and persistent access, complicating data residency and supply chain oversight for enterprises.

A recently identified malware strain, Carbonato, is targeting exposed Docker hosts to deploy AI-driven agents, enabling remote control and potential lateral movement within infrastructure.

A critical Roundcube Webmail vulnerability patched in May 2026 is now under active exploitation, with attackers injecting malicious code into unpatched instances.

cPanel released fixes for a privilege-escalation vulnerability that allowed authenticated users to execute code as root. The same researcher also reported critical flaws in Plesk’s Backup Manager during the same period.

Security researchers detail how Google Kubernetes Config Connector permissions may allow privilege escalation from a single Kubernetes user to an entire Google Cloud organization.

Arista Networks released emergency patches for a zero-day vulnerability in VeloCloud Orchestrator On-Prem deployments, which was being actively exploited in the wild.

A newly disclosed cross-site request forgery vulnerability in WordPress Core, dubbed Click2Shell, lets unauthenticated attackers execute arbitrary PHP code on vulnerable servers. Technical details and a proof-of-concept exploit are now public.

A mid-size company discovered a test environment connected to live customer data remained accessible externally for six months, risking a major breach during a routine security audit.

The KB5124008 security update for Windows 11 is preventing some enterprise users from authenticating with domain credentials, Microsoft confirmed on Wednesday.

Acronis has disclosed a high-severity vulnerability in its cPanel, WHM, and Plesk backup plugin, with evidence of active exploitation on Linux systems.

The U.S. Cybersecurity and Infrastructure Security Agency reports that ransomware gangs are now targeting a critical remote-code-execution vulnerability in VMware vCenter, patched in July 2026.