18 posts were published in the last hour 13:4 : Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks 12:32 : Apple Fixes WebKit Flaws in iOS and macOS, With Help From AI Tools 12:31 : The Realities…
Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks
Decades-old Bash shell tricks can bypass safeguards in most open source AI coding agents, potentially turning malicious repositories into supply chain attack vectors. The post Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks appeared first on SecurityWeek.…
Apple Fixes WebKit Flaws in iOS and macOS, With Help From AI Tools
Apple released updates for iOS, iPadOS, macOS, and Safari, fixing WebKit flaws, four of which were found using AI tools like Claude and Codex Apple pushed out security updates for iOS, iPadOS, macOS, and Safari on Monday, and this round…
The Realities of AI Video Surveillance
The Financial Times has a good article on how AI is changing the capabilities of video surveillance, with information from both Israel/Iran and Russia. I wrote about this sort of thing a few years ago, how AI enables mass spying…
PoC Released for NTLM reflection bypass Vulnerability that Emanbles SYSTEM Access on Windows Server
A proof-of-concept has been published that bypasses Microsoft’s mitigation for the NTLM reflection vulnerability tracked as CVE-2025-33073 and allows escalation to NT AUTHORITY\SYSTEM on Windows Server. The exploit leverages two conceptual weaknesses left unaddressed by the original patch: the mitigation…
Multiple AirDrop and Quick Share Vulnerabilities Allow Attackers to Crash Devices
A new technical analysis has exposed six proximity-transfer flaws across Apple AirDrop, Samsung Quick Share on Android, and Google Quick Share for Windows, showing that device-sharing stacks still contain fragile pre-authentication attack surfaces that can be abused from wireless range.…
TONResolver Malware Uses TON Smart Contracts as Dead Drop Resolver for C2 Switching
A new wave of cyberattacks targeting Japan’s hospitality sector has put the global threat landscape on high alert. In late May 2026, attackers began sending phishing emails to Japanese partner companies of Booking.com, disguised as urgent guest complaints and review…
SimpleHelp Authentication Bypass Vulnerability Exploited in the Wild to Deploy TaskWeaver Loader
A critical authentication bypass vulnerability in SimpleHelp Remote Monitoring and Management (RMM) software is being actively exploited in the wild. This enables attackers to deploy advanced malware, including a newly identified loader, TaskWeaver, and an information-stealing tool, Djinn Stealer. Security…
Multiple WolfSSL Vulnerabilities Expose Billions of Servers and IoT Devices to Cyberattacks
Multiple newly disclosed vulnerabilities in the wolfSSL embedded TLS library expose billions of servers and Internet of Things (IoT) devices to potential certificate forgery, remote code execution, and denial-of-service attacks if left unpatched. These flaws undermine core trust mechanisms in…
PoC Released for NTLM Reflection Bypass Flaw that Enables SYSTEM Access on Windows Server
A working proof-of-concept (PoC) exploit has been released for a new NTLM reflection bypass flaw that enables SYSTEM-level access on Windows Server 2025, raising fresh concerns about the resilience of Microsoft’s authentication hardening. The vulnerability, tracked as CVE-2026-24294, shows that…
GitHub Advisory Database Hits Record Volume as Vulnerability Reports Surpass Review Capacity
GitHub’s Advisory Database reached an all-time high in May 2026, publishing 1,560 reviewed security advisories, more than five times its typical monthly output. Despite this milestone, the platform still struggled to keep pace with a rapidly expanding volume of vulnerability…
Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History
The ruling was made in the case of a bank robber whose identity was discovered through a geofence warrant. The post Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History appeared first on SecurityWeek. This article has…
Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat
Chris Thompson’s journey took him from hacking game controls as a teenager to founding IBM’s X-Force Red team. The post Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat appeared first on SecurityWeek. This article has…
ClickFix Now Cybercriminals’ Favorite Malware Delivery Technique
ReliaQuest report warns of a surge in ClickFix social engineering attacks against Windows and macOS users This article has been indexed from www.infosecurity-magazine.com Read the original article: ClickFix Now Cybercriminals’ Favorite Malware Delivery Technique
AirDrop and Quick Share Flaws Enable Crashes
Security researchers have identified six vulnerabilities affecting AirDrop and Quick Share, the wireless file-transfer protocols used by Apple and Android devices respectively. This article has been indexed from CyberMaterial Read the original article: AirDrop and Quick Share Flaws Enable Crashes
China-linked malware on USB drives infected Japanese military
Japan’s Ground Self-Defense Force (JGSDF) used malware-infected counterfeit USB drives on sensitive military networks for nearly a year before detection in February 2025. This article has been indexed from CyberMaterial Read the original article: China-linked malware on USB drives infected…
Sophos AI Threat Taxonomy Framework
Sophos X-Ops has published a working taxonomy framework to help security professionals track and categorize the growing landscape of AI-related cybersecurity threats. This article has been indexed from CyberMaterial Read the original article: Sophos AI Threat Taxonomy Framework
CMA proposes app store payment reforms
The UK’s Competition and Markets Authority has proposed new conduct requirements that would compel Apple and Google to permit app developers to steer customers toward payment options outside the tech giants’ proprietary systems. This article has been indexed from CyberMaterial…
Kali Linux 2026.2 improves VM boot times
Offensive Security has released Kali Linux 2026.2 with faster boot times for penetration testers running the distribution in virtual machines. This article has been indexed from CyberMaterial Read the original article: Kali Linux 2026.2 improves VM boot times
SystemBC Malware Turns Windows Machines Into SOCKS5 Proxies for Ransomware Attacks
SystemBC (also tracked as Coroxy) remains a versatile and persistent Windows malware family that operators routinely deploy to convert compromised hosts into SOCKS5 proxy gateways and to maintain remote access for follow-on operations. First observed as a payload in exploit…
Exploitation of Recent Oracle E-Business Suite Vulnerability Begins
The critical-severity defect allows unauthenticated attackers to take over the E-Business Suite’s Payments product. The post Exploitation of Recent Oracle E-Business Suite Vulnerability Begins appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: Exploitation…
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unreported malware families, TaskWeaver and Djinn Stealer. The intrusion involves the exploitation of CVE-2026-48558 (CVSS score: 10.0), a critical authentication…
US Offers $10 Million Bounty for Information on Russian Hackers Targeting Signal and WhatsApp Users
The U. Thank you for being a Ghacks reader. The post US Offers $10 Million Bounty for Information on Russian Hackers Targeting Signal and WhatsApp Users appeared first on gHacks. This article has been indexed from Cybersecurity News: Threats, Vulnerabilities…
WhatsApp Usernames Will Let You Chat Without Sharing Your Phone Number
WhatsApp is letting users reserve usernames before its 2026 launch, giving people a way to chat without sharing phone numbers. Here is how it works, why it matters, and the security limits to know This article has been indexed from…
