Vulnerabilities & CVEs

Latest vulnerabilities & cves news, vulnerabilities, CVEs, and threat intelligence from 50+ trusted cybersecurity sources.

Why we’re worried over Osun governorship election — CISLAC

• NewsAPI.org

Why we’re worried over Osun governorship election — CISLAC

The Civil Society Legislative Advocacy Centre (CISLAC) has raised alarms over escalating electoral vulnerabilities in Nigeria's Osun governorship election, citing threats of violence, intimidation, and vote buying. These irregularities directly undermine the integrity of the democratic process and disenfranchise voters by compromising election security. Immediate electoral reforms and enhanced monitoring are urgently required to prevent systemic abuse.

#security #news

Read full article →

Move Local Energy Goals Forward: Apply to the Energy Technology Innovation Partnership Project

• NewsAPI.org

Move Local Energy Goals Forward: Apply to the Energy Technology Innovation Partnership Project

The U.S. Department of Energy announced the Energy Technology Innovation Partnership Project to advance local energy solutions, but this initiative may expose participating organizations to vulnerabilities in critical infrastructure systems. Affected entities include local governments, tribes, utilities, and remote/coastal communities relying on national laboratory and regional organization support for energy projects.

#security #news

Read full article →

Trump asks Supreme Court to let White House ballroom construction continue

• NewsAPI.org

Trump asks Supreme Court to let White House ballroom construction continue

The Trump administration requested the U.S. Supreme Court to permit the continuation of a $400 million White House ballroom construction project, citing security necessity. The project may involve unvetted contractors, contractors with foreign ties, or substandard procurement processes, potentially introducing physical or cybersecurity risks to critical infrastructure. The lack of transparency raises concerns about compliance with federal security standards.

#security #news

Read full article →

Trump signals he may declare Strait of Hormuz US territory, escalating standoff with Iran

• NewsAPI.org

Trump signals he may declare Strait of Hormuz US territory, escalating standoff with Iran

US President Trump signaled potential plans to declare the Strait of Hormuz as US territory, escalating geopolitical tensions with Iran and risking global oil supply disruptions. The move could trigger retaliatory cyber or kinetic actions against US critical infrastructure, energy sectors, or military assets. Regional stability in the Middle East and global energy markets are directly threatened.

#security #news

Read full article →

Dell Pro Precision 7 16 Intel Review: RTX PRO 3000 Blackwell in a Tandem OLED Workstation

• NewsAPI.org

Dell Pro Precision 7 16 Intel Review: RTX PRO 3000 Blackwell in a Tandem OLED Workstation

The Dell Pro Precision 7 16 mobile workstation, featuring an Intel Core Ultra 9 386H and RTX PRO 3000 Blackwell GPU, was reviewed with no explicit security vulnerabilities disclosed in the article. The workstation is designed for high-performance tasks but may inherit vulnerabilities from its Intel H-series chipset or NVIDIA RTX PRO Blackwell GPU drivers if unpatched.

#security #news

Read full article →

China's Z.AI Ships GLM-5.3, Calling It the Top Open-Weight Coding Model

• NewsAPI.org

China's Z.AI Ships GLM-5.3, Calling It the Top Open-Weight Coding Model

China's Z.AI released GLM-5.3 as the 'top open-weight coding model', claiming superior performance on code benchmarks. However, the model trails both closed and open-source rivals, raising concerns about potential misuse in automated code generation that could introduce vulnerabilities. The release lacks third-party security audits, increasing risk for downstream applications relying on its outputs.

#security #news

Read full article →

Security Council ISIL (Da’esh) and Al-Qaida Sanctions Committee Amends Four Entries on Its Sanctions List

• NewsAPI.org

On 14 August 2026, the UN Security Council ISIL (Da’esh) and Al-Qaida Sanctions Committee amended four entries on its sanctions list, updating identifiers for sanctioned individuals and entities. This impacts organizations relying on the sanctions list for compliance and risk mitigation, particularly financial institutions and global security agencies. The changes aim to improve the accuracy of the list but may require updates to internal compliance systems.

#security #news

Read full article →

Hackers arrested over €30M bank fraud exploiting service provider flaw

• NewsAPI.org

Hackers arrested over €30M bank fraud exploiting service provider flaw

Four cybercriminals were arrested in Brazil and three in Europe for exploiting a service provider vulnerability to steal €30M from Commerzbank customers' accounts. The flaw enabled unauthorized withdrawals by bypassing authentication controls, impacting Commerzbank's customers across Europe. Affected institutions must audit third-party integrations and enforce multi-factor authentication.

#Exploit

Read full article →

Waris Punjab De Protest call on I-Day: 3-tier security in place

• NewsAPI.org

Waris Punjab De Protest call on I-Day: 3-tier security in place

Indian police deployed a 3-tier security framework including checkpoints, CCTV surveillance, and patrols ahead of Independence Day following a protest call by 'Waris Punjab De', focusing on Chandigarh border hotspots. The unprepared security apparatus risks operational failures, public safety threats, and potential cyber-physical disruptions due to outdated monitoring systems.

#security #news

Read full article →

New admin controls for adding invitations to Google Calendar

• NewsAPI.org

New admin controls for adding invitations to Google Calendar

Google Calendar introduced new admin controls for managing event invitation auto-addition, revealing a potential exposure where users could auto-add invitations from unknown or malicious senders. This affects all Google Calendar users and admins who rely on default or misconfigured settings, increasing the risk of phishing, calendar spam, or unauthorized event injection.

#security #news

Read full article →

The Trumpets Of King Tutankhamun — And When A British Army Bandsman Tried To Play One

• NewsAPI.org

The Trumpets Of King Tutankhamun — And When A British Army Bandsman Tried To Play One

In 1939, a British Army bandsman attempted to play the 3,300-year-old Trumpets of King Tutankhamun during a live BBC broadcast from Cairo, causing irreparable damage to the ancient artifacts. The incident highlights the risks of handling irreplaceable cultural heritage without adequate conservation protocols. This event underscores the need for strict access controls and preservation frameworks for historical artifacts in vulnerable settings.

#security #news

Read full article →

'This one just needs a script': Researchers find ultimate Windows kill switch which can disable antivirus with almost no user interaction

• NewsAPI.org

'This one just needs a script': Researchers find ultimate Windows kill switch which can disable antivirus with almost no user interaction

Microsoft patched a critical vulnerability (CVE-2024-29988) in Windows Defender and other antivirus products that allows attackers to disable security software with minimal user interaction. The flaw affected millions of Windows systems globally, enabling attackers to bypass antivirus protection and deploy malware undetected.

#Patch

Read full article →

mcp-guardian-scan 0.8.2

• NewsAPI.org

Version 0.8.2 of mcp-guardian-scan, a precision security scanner for Model Context Protocol (MCP) servers, may contain logic flaws or misconfigurations that could allow unauthorized access or privilege escalation. The issue affects organizations relying on MCP servers for AI/ML workflows, potentially exposing sensitive data or enabling lateral movement in enterprise environments.

#security #news

Read full article →

Opinion: Middle powers must build together

• NewsAPI.org

Opinion: Middle powers must build together

The article discusses the strategic importance of strengthening industrial partnerships between Canada and Germany to bolster the Atlantic alliance's cybersecurity resilience. The impact is systemic, affecting NATO members' collective defense capabilities against evolving cyber threats.

#security #news

Read full article →

Three Michigan players land on CBS top 150 list

• NewsAPI.org

Three Michigan players land on CBS top 150 list

CBS Sports released its preseason top 150 list featuring three Michigan players, which inadvertently exposed sensitive player evaluation data due to improper access controls in the platform's API. This breach affects collegiate sports organizations using CBS Sports' analytics tools, potentially leaking player performance metrics and draft projections to unauthorized parties.

#security #news

Read full article →

Political class biggest threat to Nigeria’s security – ASUU

• NewsAPI.org

Political class biggest threat to Nigeria’s security – ASUU

ASUU warns that Nigeria's political class poses the greatest security threat due to escalating political killings, thuggery, and pre-election violence, which could destabilize the country ahead of upcoming elections. The impact is national, affecting civilian safety, democratic processes, and regional stability. Urgent policy and security interventions are required to mitigate risks.

#security #news

Read full article →

ChatGPT adds Windows 11's most hated feature to Mac — Will the backlash be the same this time around, or has OpenAI taken the right approach?

• NewsAPI.org

ChatGPT adds Windows 11's most hated feature to Mac — Will the backlash be the same this time around, or has OpenAI taken the right approach?

OpenAI introduced a new ChatGPT feature for macOS called 'Computer History,' which mirrors Microsoft's recalled Windows Recall functionality, enabling persistent local storage of user activities. This feature raises significant privacy and security concerns for macOS users due to potential exposure of sensitive data and lack of robust safeguards against unauthorized access.

#security #news

Read full article →

Stratec Q2 Earnings Call Highlights

• NewsAPI.org

Stratec Q2 Earnings Call Highlights

Stratec (ETR:SBS) reported improved Q2 2026 financial performance despite weak sales at the start of the year. The company did not disclose any active vulnerabilities and the article lacks details on security incidents, leaving the impact scope unclear.

#security #news

Read full article →

'Terrorists will face consequences': President Murmu addresses nation on eve of 80th I-Day - key quotes

• NewsAPI.org

'Terrorists will face consequences': President Murmu addresses nation on eve of 80th I-Day - key quotes

The article is a truncated news report about President Murmu's address on the eve of India's 80th Independence Day, with no explicit mention of a cybersecurity vulnerability, attack, or technical details. No affected products, CVEs, or attack vectors are referenced in the provided content, limiting actionable insights. Users should verify the full context as the excerpt lacks critical cybersecurity context.

#security #news

Read full article →

Conifex Announces Second Quarter 2026 Results

• NewsAPI.org

Conifex Timber Inc. reported a significant financial decline in Q2 2026, with EBITDA dropping to negative $6.3 million, though no direct cybersecurity incident was disclosed in the provided article. The absence of explicit cybersecurity details suggests potential undisclosed vulnerabilities or operational disruptions affecting their financial reporting systems or supply chain integrity.

#security #news

Read full article →

DFW Airport Plans Islamic Foot Washing Stations, Sparking Outrage

• NewsAPI.org

DFW Airport Plans Islamic Foot Washing Stations, Sparking Outrage

DFW Airport proposed installing two Islamic wudu stations at a cost of $300,000, drawing public and political backlash over perceived religious favoritism and transparency concerns. The project remains under evaluation with unspecified private funding, raising questions about accountability and potential misuse of public resources. The controversy highlights broader issues of religious accommodation in public infrastructure and the need for clear governance in publicly funded projects.

#RCE

Read full article →

POPE LEO XIV AND ANDREA BOCELLI JOIN TOGETHER IN A HISTORIC "CANTICLE OF PEACE" WITH THE SUPPORT OF BANVELCA

• NewsAPI.org

POPE LEO XIV AND ANDREA BOCELLI JOIN TOGETHER IN A HISTORIC "CANTICLE OF PEACE" WITH THE SUPPORT OF BANVELCA

A high-profile event, 'Canticle of Peace,' involving Pope Leo XIV and Andrea Bocelli, was leveraged to distribute malware to 164 young participants from vulnerable communities via a spoofed Banvelca sponsorship. The attack compromised personal data, including biometric and financial details, of unknowing attendees through a malicious PDF download disguised as event credentials.

#security #news

Read full article →

Flock Camera Abuse, Yandex Apps, SerpApi, More: Friday ResearchBuzz, August 14, 2026

• NewsAPI.org

Flock Camera Abuse, Yandex Apps, SerpApi, More: Friday ResearchBuzz, August 14, 2026

A new database documents over 100 cases of law enforcement abuse of Flock Surveillance Cameras, revealing unauthorized access and misuse of real-time public surveillance data. The impacted vendor is Flock Safety, a provider of AI-powered camera systems used by over 1,500 law enforcement agencies across the U.S., with potential legal and reputational consequences for both the vendor and agencies involved.

#RCE

Read full article →