Focus: rogue AI models and OT threats this week
This week again showed how quickly trust and access rights can go wrong. From rogue AI models to OT attacks in the water sector, and captcha-free DNS hijacks.
This week again showed how quickly trust and access rights can go wrong. From rogue AI models to OT attacks in the water sector, and captcha-free DNS hijacks.
Broadcom released emergency updates for VMware products to fix multiple VMware critical flaws. Patches address authentication bypass, directory traversal, code execution, and a virtual machine escape scenario.
A new Rails critical vulnerability (CVE-2026-66066) was patched after reports that unauthenticated attackers could read arbitrary server files. In some setups, that exposure could lead to remote code execution.
Google has fixed 1,442 security bugs in recent Chrome releases, far exceeding the total of earlier updates combined. The company is also testing faster delivery, automation, and dynamic patching to reduce exposure time.
A NCSC advisory reports a high-severity authentication bypass affecting SolarWinds Web Help Desk when SAML 2.0 is enabled. The vendor has released updates to remediate the issue—here’s what it means for your environment.
The NCSC reports that vulnerabilities in Adobe Campaign Classic have been patched. The issues can enable unauthorized code execution and high-impact SQL injection.
The NCSC reports critical vulnerabilities patched in VMware vCenter, ESX, Workstation, and Fusion. Key issues include an authentication bypass, directory traversal, and out-of-bounds memory flaws.
NCSC-2026-0268 originally pointed to a critical SQLite issue tied to CVE-2026-51302. The CVE has since been withdrawn, so the reported vulnerability is likely a hallucination.