Tag
Qualys and Anthropic disclose CVE-2026-64600, a race condition in the Linux kernel's XFS filesystem that allows local privilege escalation to root, affecting over 16 million systems, with no kernel log output and survival across reboots.
A blog post detailing a local privilege escalation vulnerability (CVE-2026-50343) in the Windows Install Service on Windows 11, allowing a standard user to execute code as SYSTEM by exploiting a writable plugin map and a user-plantable COM server.
First documented case of an AI agent being prompt-injected via an NFT to execute unauthorized on-chain transactions, resulting in a $175K transfer. The attacker returned the funds, demonstrating the vulnerability of autonomous agents to instruction spoofing.
This paper explores using fine-tuned LLMs to identify indicators of vulnerability (mental ill health, substance misuse, alcohol dependence, homelessness) in UK police incident logs, finding that while LLMs can produce meaningful prevalence estimates, they require careful methodological support and are not reliable for individual-level decisions.
Security researchers found that XCharge C6 EV chargers expose SSH and Telnet services with default root:root credentials over the CCS2 charging interface, enabling attackers to gain full control by connecting a malicious EV.
Apple fixed a vulnerability in its Hide My Email feature that could reveal users' real email addresses after 404 Media reported on the issue, despite Apple knowing about it for over a year.
A tweet and blog post highlight that the tool list itself is an attack surface: by controlling a tool's description, an attacker can hijack an AI agent's behavior without exploit code. This is part 2 of a series on MCP bug bounties.
Researchers at UC San Diego discovered a severe Bluetooth vulnerability in the KARR aftermarket car alarm, installed in over 2 million US vehicles, allowing attackers to unlock, track, or disable cars. A firmware patch has been released, but many owners are unaware the device is installed.
This article details the discovery and exploitation of a Linux kernel 0-day vulnerability in the network scheduler subsystem (red scheduler), turning a limited slab use-after-free into full physical memory read/write, ultimately achieving privilege escalation to root. The vulnerability existed for 2.5 years and was fixed in June 2026.
A heap buffer overflow vulnerability in Dnsmasq (CVE-2026-2291) allows remote code execution via a malicious upstream DNS server. The issue was introduced in version 2.73 and fixed in 2.92rel2 and 2.93.
Pillar Research found sandbox escape vulnerabilities in AI coding agents from Cursor, Codex, Gemini CLI, and Antigravity, revealing that these agents can write files that host components later trust, bypassing sandbox boundaries. The findings highlight the need for a new threat model for agentic security.
This article describes using fuzzing to discover an unauthenticated denial-of-service vulnerability in snac2's JSON parser, allowing remote crashes via crafted inputs.
Fortinet FortiSandbox contains a critical unauthenticated OS command injection vulnerability (CVE-2026-25089) actively exploited in the wild, added to CISA's Known Exploited Vulnerabilities catalog on July 16, 2026.
A security report reveals that over 10% of MCP servers leak credentials or personally identifiable information through tool responses, bypassing traditional SAST/DAST scanning.
A Windows 0-day vulnerability called LegacyHive allows non-admin users to escalate privileges by abusing how Windows loads user class hives, with Microsoft investigating and detection scripts available.
NAT Slipstreaming v2.0 is a browser-based attack that exploits ALG connection tracking to remotely access any TCP/UDP service behind a victim's NAT, bypassing firewall restrictions.
A 64GB CMP 170HX NVIDIA GPU with A100 tensor cores has appeared on China's secondhand market for $1,170, and a software-level vulnerability has successfully removed its computing power limit.
A security researcher discovered a vulnerability in Claude's web_fetch tool that allowed data exfiltration by chaining through nested links, compromising user privacy. Anthropic has since fixed the issue.
A security researcher demonstrates a method to trick Claude AI into exfiltrating user personal data from its memory system by encoding data in web fetch URLs, exploiting the combination of memory retrieval and web browsing capabilities.
A vulnerability in Tailscale SSH allowed users to gain root access by using a crafted username with a leading dash. The issue is fixed in version 1.98.9.