General High 6 May

Zero-Auth Flaw Exposes DoD Contractor to Cross-Tenant Data Access

A severe zero-authorization vulnerability in Schemata’s API, an AI-powered virtual training platform holding active Department of Defense (DoD) contracts, recently exposed highly sensitive military training materials and U.S. service member records. Discovered by the open-source AI hacking agent Str

General High 6 May

Oracle Debuts Monthly Critical Security Patch Updates

Containing fixes for critical-severity vulnerabilities, the monthly rollouts will focus on addressing priority issues faster. The post Oracle Debuts Monthly Critical Security Patch Updates appeared first on SecurityWeek. Source: Security Week

General Medium 6 May

Critical Weaver E-cology RCE Vulnerability Actively Exploited in Attacks

A critical unauthenticated remote code execution vulnerability in the Weaver E-cology platform is currently being actively exploited in the wild. CVE-2026-22679 carries a maximum CVSS score of 9.8 and affects Weaver E-cology 10.0 builds released before 20260312. The security flaw exists in an expose Source: Cybersecurity News

General Medium 6 May

Critical Qualcomm Chipset Vulnerabilities Enables Remote Code Execution

Qualcomm Technologies has released a critical security bulletin addressing multiple severe vulnerabilities in its proprietary and open-source software. These security updates are essential for protecting devices from severe flaws that threaten a vast ecosystem of hardware powered by Snapdragon proce Source: Cybersecurity News

General Medium 6 May

Instructure Confirms Canvas Cybersecurity Incident, User Data Accessed

A Canvas cybersecurity incident has disrupted services at Instructure, the company behind the widely used Canvas platform, raising concerns among educational institutions over potential data exposure and service interruptions. The Canvas cybersecurity incident first came to light late Friday, when I Source: The Cyber Express

General Medium 6 May

Trellix Confirms Source Code Repository Breach

It is always a bit jarring when the "digital locksmiths" are the ones getting their locks picked. Cybersecurity firm Trellix on Saturday confirmed it suffered a breach involving its internal source code repositories, proving that even the defenders aren't immune to the threats they fight. The Incide Source: The Cyber Express