The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a VMware Aria Operations vulnerability tracked as CVE-2026-22719 to its Known Exploited Vulnerabilities catalog, flagging the ...
Microsoft warns that attackers are actively exploiting CVE-2026-73570 to run commands, steal Zimbra authentication data, and ...
A major vulnerability in several Netgear routers allowed remote attackers to commit command injection attacks on these devices. The attacks involved tricking victims using Netgear routers into ...
WatchGuard warns of partly critical security vulnerabilities in its access points. Attackers can bypass authentication and ...
Japan's national vulnerability coordination body published its third consecutive advisory disclosing OS command injection flaws in Elecom's networking hardware today, flagging high-severity command ...
Security leaders must adapt large language model controls such as input validation, output filtering and least-privilege access for artificial intelligence systems to prevent prompt injection attacks.
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. The vulnerability, tracked as ...
A prompt injection attack can trick GitHub’s preview Agentic Workflows into retrieving content from private repositories and publishing it publicly, exposing a broader risk as enterprises deploy AI ...
Security researchers have developed a new image-based prompt injection attack that can manipulate how multimodal AI systems interpret user instructions without modifying the original text prompt, ...
This post is Part 1 of a two-part series on multimodal typographic attacks. This blog was written in collaboration between Ravi Balakrishnan, Amy Chang, Sanket Mendapara, and Ankit Garg. Modern ...