Security news

Latest security news

Wed, 19 Aug 2026

  1. CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway

    Overview On August 19, 2026, a security advisory was published for CVE-2026-19490 , a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges. NetScaler ADC and NetScaler Gateway are widely deployed enterprise networking products commonly positioned at or near the network perimeter. NetScaler ADC provides application delivery, traffic management, load balancing, SSL/TLS offloading, and application security capabilities, while NetScaler Gateway provides secure remote access and VPN functionality. Because these systems are frequently deployed in enterprise DMZs and exposed to the public internet, authentication bypass vulnerabilities affecting Citrix products are nearly always exploited by threat actors. CVE-2026-19490 affects the following systems: NetScaler ADC and NetScaler Gateway 14.1: Versions prior to 14.1-73.32 NetScaler ADC and NetScaler Gateway 13.1: Versions prior to 13.1-63.21 NetScaler ADC FIPS: Versions prior to 14.1-73.32 FIPS NetScaler ADC FIPS an

    Rapid7 BlogCitrix
  2. Exclusive: Linux Foundation's Akrites to Go Live in September

    The Linux Foundation's Akrites initiative will become operational in September, when it will begin accepting AI-powered vulnerability reports for open-source projects

    Infosecurity MagazineLinux

Tue, 18 Aug 2026

  1. Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed

    The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher

    Infosecurity MagazineGitHub
  2. Enterprise Applications Carry 4.31x More Critical and High Vulnerabilities

    Enterprise software creation has accelerated as vulnerability levels rise, Sonatype finds

    Infosecurity Magazine
  3. NASA Ground Control Software Flaw Enables Unauthenticated Commands

    Critical AIT-GUI flaws expose spacecraft commands and scripts to unauthenticated attackers

    Infosecurity Magazine
  4. New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

    You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers. The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive programs. Success going forward can’t be about patching as much as possible - it has to be about understanding what matters most and reducing the exposures attackers can actually reach. Here are the four trends that defined Q2 2026, and what they mean for your security program as you define priorities for Q3 and beyond: The volume of disclosures hit another milestone There were 8,539 new high- and critical-severity CVEs (CVSS 7.0–10.0) this quarter- double the number reported in the same quarter last year (4,268). Meanwhile, the number of newly exploited vulnerabilities held roughly steady (40). The takeaway isn’t that exploitation exploded - it’s that disclosure volume is far outstripping what any

    Rapid7 Blog

Mon, 17 Aug 2026

  1. UNISOC Modem Flaw Enables Remote Code Execution via Video Calls

    UNISOC modem flaw enabled kernel-level code execution through video calls

    Infosecurity Magazine
  2. WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

    Critical User Profile Builder flaw let unauthenticated attackers access administrator accounts

    Infosecurity MagazineWordPress
  3. Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

    Operation ASTERIX overview Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the campaign's development; recovered prompts, shell history, and project files show AI being used to package Electron applications, obfuscate code, troubleshoot builds, modify phishing infrastructure, and prepare malware for distribution. When one model began resisting parts of that workflow, the operator switched providers and attempted to bypass the next model's safety controls with a custom jailbreak prompt. Together, these artifacts provide an unusual view into how AI was integrated into the development of an active phishing operation rather than simply being used to generate isolated snippets of code. We track this activity as Operation ASTERIX, named after the Asterisk open-source telephony platform recovered on the serve

    Rapid7 Blog

About this news

1,264
Stories
36
Added in the last 24 hours
16
Critical in the last 7 days
4
Reported by several outlets