Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'patch'

View all threats tagged with 'patch'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: patch

Threats Tagged 'patch'

Click on any threat for detailed analysis and mitigation recommendations

an AI agent has been getting security patches merged into major open source repos for months and I only just noticed
0

An autonomous AI agent named Aeon has been actively scanning major open source repositories for security vulnerabilities and submitting patches that have been merged by maintainers. The agent operates transparently via GitHub actions, auditing code, submitting fixes, and tracking merges across over 70 repositories with a combined 2.1 million stars. The patches include fixes for critical issues such as DNS rebinding, SSRF bypasses, microVM escapes, and stored XSS. This represents a novel defensive use of AI agents in open source security maintenance, raising questions about trust in autonomous code contributions.

Join the discussion
New WordPress Pre-Auth XSS (CVE-2026-64638) Could Lead to RCE: Have you patched your instances yet?CVE-2026-64638
0

CVE-2026-64638 is a high-severity pre-authentication reflected cross-site scripting (XSS) vulnerability in WordPress login pages that can lead to remote code execution (RCE) under specific conditions. The flaw allows attacker-controlled JavaScript to execute in the browser of a visitor after a failed login attempt. Exploitation requires a logged-in administrator to interact with an attacker-controlled page, potentially enabling PHP code execution on the server. The vulnerability affects default WordPress installations and was patched in WordPress 7.0.3 and backported to versions back through 4.7. Versions older than 4.7 remain vulnerable. WordPress recommends immediate updating, and automatic background updates should apply the patch automatically. No in-the-wild exploitation has been reported as of the advisory date.

Join the discussion
tl;dv (AI meeting assistant) left 181,874 meetings exposed via misconfigured Firestore, including live calls you could join. Researcher disclosed in January, still unpatched 6 months later.
0

The AI meeting assistant tl;dv exposed 181,874 meetings due to a misconfigured Firestore database. This exposure included live calls that unauthorized users could join. The vulnerability was disclosed by a researcher in January but remains unpatched six months later.

Join the discussion
Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates
0

Oracle released its July 2026 Critical Patch Update addressing 1,434 unique vulnerabilities across 334 products with 1,449 security patches. Many vulnerabilities were likely discovered using AI technologies. The update includes fixes for critical severity flaws, including roughly 600 that can be exploited remotely without authentication. Key affected products include E-Business Suite, Fusion Middleware, Communications, and PeopleSoft. Organizations are urged to apply these patches promptly to mitigate risks from known vulnerabilities.

Join the discussion
Critical Google Chrome Zero-Day Vulnerability Enables Sandbox Escape – Immediate Update Required
0

A critical zero-day vulnerability in Google Chrome's V8 JavaScript engine allows attackers to escape the browser sandbox and execute malicious code with user-level privileges, risking theft of passwords and sensitive data. The exploit is actively used in the wild by APT groups, prompting urgent patching directives from federal agencies including CISA. Immediate manual updating of Chrome and Chromium-based browsers is essential to mitigate this threat.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: patch
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses