Tuesday , July 28 2026
WebKit

Apple Patches Two Critical WebKit Zero-Days Under Active Exploitation

Apple has urgently patched two critical zero-day vulnerabilities in the WebKit browser engine affecting iPhone and iPad users. The company revealed these flaws are actively exploited, enabling advanced attacks on high-risk targets. Vulnerabilities CVE-2025-43529 and CVE-2025-14174 let attackers run malicious code if a victim visits a specific web page.

WebKit powers Safari and displays web content on iOS devices, making it vulnerable to attacks due to its extensive role. An attacker does not need physical access to the device; processing “maliciously crafted web content”—such as a compromised website or a malicious ad—is enough to trigger the exploit.

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
Shinyhunters claimed and set deadline to publish E&Y data

Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Google Search Results Reportedly Show Claude AI Shared Chats

Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
Google Search Results Reportedly Show Claude AI Shared Chats

“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

PentesterFlow is a new open-source AI tool for command lines. It is made for penetration testers and bug bounty hunters....
Read More
“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

A famous AI red team expert claimed developing a universal jailbreak that can work against top large language models, like...
Read More
Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

Researchers found security flaws in every script generated by ChatGPT, Copilot, and Gemini

A new study from Beacom College shows that all automation scripts produced by top AI models like ChatGPT, Microsoft Copilot,...
Read More
Researchers found security flaws in every script generated by ChatGPT, Copilot, and Gemini

Australian Energy Giant Origin confirms unauthorized access and disclosure of customer data

Origin Energy Limited, a major energy provider in Australia, has said there was a cybersecurity issue with unauthorized access to...
Read More
Australian Energy Giant Origin confirms unauthorized access and disclosure of customer data

Anthropic Unveils Claude Security Plugin for Code Flaw Scanning

Anthropic launched the Claude Security plugin in beta. This tool uses AI to find serious security flaws in Claude Code....
Read More
Anthropic Unveils Claude Security Plugin for Code Flaw Scanning

Apple, ASUS Router, Meta, Windmill & Ubuntu Patch Critical Security Flaws

ASUS has put out important security updates for a serious router flaw. This issue could let remote hackers run any...
Read More
Apple, ASUS Router, Meta, Windmill & Ubuntu Patch Critical Security Flaws

Apple’s advisory for both bugs uses identical, alarming language regarding their active exploitation:

“Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26.”

This phrasing usually indicates targeted attacks by sophisticated groups against important individuals.

CVE-2025-43529 (Use-After-Free): The Google Threat Analysis Group (TAG) found a “use-after-free” vulnerability. This occurs when a program tries to use memory that has already been cleared, allowing hackers to run code. Apple fixed this by enhancing memory management (WebKit Bugzilla: 302502).

CVE-2025-14174 (Memory Corruption): This issue, affecting both Apple and Google TAG, can lead to memory corruption, which might crash systems or allow attackers access. It was fixed through better input validation (WebKit Bugzilla: 303614).

The vulnerability impacts various modern Apple mobile devices. If you have one of the following, your device is at risk until updated:

iPhone: iPhone 11 and later
iPad Pro: 12.9-inch (3rd gen+), 11-inch (1st gen+)
iPad Air: 3rd gen and later
iPad: 8th gen and later
iPad mini: 5th gen and later

Now that the patches are available, other hackers may try to analyze the fixes to create their own attacks. Users should update to iOS 26 (or the latest version available in Settings) right away.

Check Also

Oracle

Oracle fixes 1,400+ vulnerabilities; critical flaws threaten enterprise servers

Oracle has fixed over 1,400 security holes in its July 2026 Critical Patch Update (CPU). …