Code

New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution

Ravie LakshmananMay 12, 2026Vulnerability / Email Security Exim has released security updates to address a severe security issue affecting certain…

5 jours ago

‘TrustFall’ Exposes Claude Code Execution Risk

Developers using the latest version of Claude Code could inadvertently execute malicious code on their systems with a single keypress,…

2 semaines ago

vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution

Ravie LakshmananMay 07, 2026Vulnerability / Software Security A dozen critical security vulnerabilities have been disclosed in the vm2 Node.js library…

2 semaines ago

Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution

Ravie LakshmananMay 06, 2026Vulnerability / Network Security Palo Alto Networks has released an advisory warning that a critical buffer overflow…

2 semaines ago

Trellix Source Code Breach Highlights Supply Chain Threats

Cybersecurity vendor Trellix published a terse statement last Friday, disclosing that a threat actor recently gained unauthorized access to "a…

2 semaines ago

Trellix Confirms Source Code Breach With Unauthorized Repository Access

Ravie LakshmananMay 02, 2026Data Breach / Enterprise Security Cybersecurity company Trellix has announced that it suffered a breach that enabled…

2 semaines ago

Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution

Google has addressed a maximum severity security flaw in Gemini CLI -- the "@google/gemini-cli" npm package and the "google-github-actions/run-gemini-cli" GitHub…

3 semaines ago

Glasswing Secured the Code. The Rest is on You

OPINIONWhen Anthropic announced Project Glasswing this month, most coverage landed on the headline numbers: a 27-year-old OpenBSD vulnerability, a 16-year-old…

3 semaines ago

Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain

Ravie LakshmananApr 22, 2026Cloud Security / Software Security Cybersecurity researchers have warned of malicious images pushed to the official "checkmarx/kics"…

4 semaines ago