-
A malicious pull request has the potential to turn Claude Code’s project-scoped Model Context Protocol (MCP) configuration into a trigger for code execution, which could expose developer secrets before a reviewer has a chance to evaluate the code. Anth…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security research presented at Black Hat 2026 has identified 12 vulnerabilities across four enterprise Java platforms, including two critical pre-authentication remote code execution (RCE) chains affecting Bonita BPM and Apache OFBiz. Researchers Lidor…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have demonstrated an indirect prompt-injection chain affecting Claude in Chrome that can transform a standard request, such as summarizing recent emails, into a cross-account takeover scenario. The research reveals how untrusted co…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have shown how attackers could exploit Microsoft Windows Server Update Services (WSUS) infrastructure to distribute malicious software updates across enterprise networks. This technique relies on NTLM authentication coercion and re…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have disclosed a vulnerability affecting AI coding-agent workflows from Anthropic, Google, and OpenAI. Their research highlights how an attacker-controlled issue or zero-privilege input can breach trust boundaries in an agent “harn…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A coordinated cyber campaign targeting internet-facing programmable logic controllers (PLCs) has disrupted water and wastewater operations across the United States, raising concerns about the vulnerabilities in exposed operational technology (OT). Thes…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Critical vulnerabilities in the open-source Paperclip AI-agent orchestration platform could allow attackers to execute commands remotely on exposed servers or on a developer’s local machine. These flaws arise from broken authorization boundaries across…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The fake “undetected” Xeno Roblox executor currently circulating on gaming forums and Discord is a weaponized loader for the Powercat Java stealer, a multi‑stage RAT and infostealer that targets Discord, Roblox, Minecraft, crypto wallets and payment to…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Vanta Stealer is a Python‑based, cross‑platform information stealer that uses layered PyArmor obfuscation on top of a PyInstaller‑packed executable to harvest browser passwords, crypto wallet data, Discord tokens, gaming accounts, VPN configs, and sens…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
KHunt shows how a “routine” SQL injection against an Oracle‑backed web app can be weaponized into SYSTEM‑level remote code execution and credential theft by compiling a full post‑exploitation toolkit directly inside the database engine. This incident m…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


