command-injection

Tag

Cards List
#command-injection

CVE-2026-25089: FortiSandbox unauthenticated command injection added to CISA KEV

Hacker News Top · 2026-07-16 Cached

Fortinet FortiSandbox contains a critical unauthenticated OS command injection vulnerability (CVE-2026-25089) actively exploited in the wild, added to CISA's Known Exploited Vulnerabilities catalog on July 16, 2026.

0 favorites 0 likes
#command-injection

Command Execution via Drag-and-Drop in Terminal Emulators

Lobsters Hottest · 2026-04-21

Security researchers have identified a technique where terminal emulators can execute arbitrary commands when users drag and drop text containing shell commands, creating a potential social engineering attack vector.

0 favorites 0 likes
#command-injection

Anthropic Claude Code Leak Reveals Critical Command Injection Vulnerabilities

Lobsters Hottest · 2026-04-19 Cached

Critical command injection vulnerabilities (CVE-2026-35022, CVSS 9.8) discovered in Anthropic's Claude Code CLI and SDK allow attackers to execute arbitrary commands and steal credentials through environment variables, file paths, and authentication helpers. The flaws enable poisoned pipeline execution attacks in CI/CD environments, requiring immediate patching and configuration changes.

0 favorites 0 likes
#command-injection

Cybersecurity AI: Humanoid Robots as Attack Vectors

Papers with Code Trending · 2025-09-17 Cached

This paper presents a systematic security assessment of the Unitree G1 humanoid robot, revealing critical vulnerabilities including BLE provisioning protocol exploits, hardcoded AES keys, and a resident Cybersecurity AI agent capable of exfiltration and offensive operations, arguing for adaptive CAI-powered defenses as humanoids enter critical infrastructure.

0 favorites 0 likes
← Back to home

Submit Feedback