Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause the application to crash if a maliciously crafted DICOM file is opened. The following versions of Medixant RadiAnt DICOM are affected: RadiAnt DICOM <=2025.2 CVSS Vendor Equipment Vulnerabilities v3 4.3 Medixant Medixant RadiAnt DICOM Out-of-bounds Write Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: Poland Vulnerabilities Expand All + CVE-2026-17264 Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.
Tenable spent over 500 hours testing Anthropic's Claude Mythos Preview, finding that frontier AI enhances but does not replace human-led code security. They discovered that while AI generates many findings, only a fraction are actionable after expert analysis.
Tenable spent over 500 hours and 40 billion tokens testing Anthropic's Claude Mythos Preview for Project Glasswing. The assessment shows frontier AI can significantly strengthen a code security program when paired with human oversight)Skip.
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data. The following versions of ABB Ability Zenon are affected: IIoT services with MongoDB (4.2) installed on ABB Ability Zenon vers:all/* CVSS Vendor Equipment Vulnerabilities v3 7.8 ABB ABB Ability Zenon Improper Handling of Length Parameter Inconsistency, Improper Neutralization of Null Byte or NUL Character, Collapse of Data into Unsafe Value, Undefined Behavior for Input to API, Incorrect Regular Expression, Uncaught Exception, Reachable Assertion, Allocation of Resources Without Limits or Throttling, Out-of-bounds Write, Improper Output Neutralization for Logs, Improper Certificate Validation, Execution with Unnecessary Privileges Background Critical Infrastructure Sectors: Chemical, Communications, Critical Manufacturing, Dams, Energy, Healthcare and Public Health, Information Technology, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2025-14847 Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client.
Coinspect identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains, causing approximately $5.7 million in theft. Five wallet apps used this generator for recovery phrases, with some fixed and others discontinued.
Coinspect identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains, causing approximately $5.7 million in theft. Five wallet apps used this generator for recovery phrases, with some fixed and others discontinued.