The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE).
Tag: EN
Russian spies take their half-click email attack from Zimbra to Outlook
Opening a booby-trapped message unleashes a browser implant that can survive password changes and device rebuilds
7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the…
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more.
A Civilian Plane Crashed in New Mexico. Was the Military’s Tech to Blame?
Drone warfare is making the skies more dangerous, even for airplanes far from the battlefield.
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency…
Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal
Both major AI labs’ models broke containment, escaped onto the internet, and hacked other companies. If a human had done that, the law would likely be…
Autonomous AI Agent Exploits Zero-Day to Breach Hugging Face Infrastructure
An autonomous AI agent powered by OpenAI models breached Hugging Face’s production infrastructure in July 2026 after escaping its evaluation sandbox via a…
10th Annual Security Serious Unsung Heroes Awards Open for Nominations
It’s that time again! Global cybersecurity PR agency Eskenzi PR has opened nominations for its tenth annual Security Serious Unsung Heroes Awards. The…
Arch Linux Suspends AUR Package Adoptions to Block Ongoing Malicious Commit Campaign
Arch Linux has temporarily disabled package adoptions on the Arch User Repository (AUR) after detecting a wave of malicious activity targeting orphaned…
5 High-Impact Use Cases for Falcon Onum
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: 5 High-Impact Use Cases for Falcon Onum
The “Hidden Factory”: Why Your Risk Score Is a Lie
For most CISOs and risk management teams, the concept of exposure management conjures up images of a dashboard…
CRPx0 Ransomware Claims Hyundai Turkey Breach, Steals 1.5GB of Assessment Data
The double-extortion ransomware group CRPx0 has listed Hyundai’s Turkish operations on its dark web leak site, claiming to have exfiltrated 1.5 GB of…
HackerOne Mandates ID Verification Before Bug Bounty Report Submissions
HackerOne has rolled out a significant policy change requiring all hackers to complete identity verification before submitting reports to Bug Bounty…
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation…
Black Hat special: Rewind and revisit
Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence.
AI Scammers Are Better at Building Trust Than Humans
Researchers pitted a person against a Claude agent and found that, after a week of texting, the AI chatbot was more effective at creating “exploitable…
Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)
Most phishing campaigns rely on the fact that the victim is afraid to loose “something”: money, access to information, … Many brands have been…
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images,…
MacSync Stealer RAT Uses Fake Claude Guides to Steal Passwords and Crypto Wallets
A newly disclosed macOS malware campaign dubbed MacSync weaponizes fake Claude AI installation guides to deploy a six-stage stealer and remote access…