The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000.
The post Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers appeared first on SecurityWeek.
The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000.
The post Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers appeared first on SecurityWeek.
The N‑central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass.
The post N‑able Patches Vulnerability Exploited to Hack N-central Servers appeared first on SecurityWeek.
The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement.
The post Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks appeared first on SecurityWeek.
The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE).
The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.
The internet giant has built an agent harness to find vulnerabilities across Chrome’s codebase.
The post Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace appeared first on SecurityWeek.
Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access.
The post Critical Flaw Led to Azure Cosmos DB Pwnage appeared first on SecurityWeek.
Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol.
The post Critical Code Execution Vulnerability Patched in TeamCity appeared first on SecurityWeek.
Unauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container.
The post Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms appeared first on SecurityWeek.
The major browser update resolves roughly 80 critical- and high-severity security defects.
The post Chrome 151 Patches 370 Vulnerabilities appeared first on SecurityWeek.
The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices.
The post Cisco Secure FMC Zero-Day Exploited in the Wild appeared first on SecurityWeek.