-
A malicious pull request has the potential to turn Claude Code’s project-scoped Model Context Protocol (MCP) configuration into a trigger for code execution, which could expose developer secrets before a reviewer has a chance to evaluate the code. Anth…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security research presented at Black Hat 2026 has identified 12 vulnerabilities across four enterprise Java platforms, including two critical pre-authentication remote code execution (RCE) chains affecting Bonita BPM and Apache OFBiz. Researchers Lidor…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Forescout disclosed 15 TP-Link flaws at Black Hat USA 2026 that could expose Omada credentials and VPN keys, allow internal access and affect VIGI camera feeds.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Critical vulnerabilities in the open-source Paperclip AI-agent orchestration platform could allow attackers to execute commands remotely on exposed servers or on a developer’s local machine. These flaws arise from broken authorization boundaries across…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability in Jenkins, tracked as CVE-2026-70426, may allow attackers to execute arbitrary code on Jenkins controllers by bypassing deserialization protections within the platform’s Remoting library. This flaw, identified as SECURITY-3911…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A proof-of-concept (PoC) has been released for a use-after-free vulnerability affecting the Linux kernel’s software bridge implementation found in `net/bridge`. This vulnerability occurs within the Spanning Tree Protocol (STP) timer lifecycle. It…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
At Black Hat USA 2026, Novee found GitHub workflow flaws in Claude Code, Gemini CLI and Codex that enabled RCE, credential theft and agent control in pipelines.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
OpenAI has revealed new details about an incident involving AI agents, in which multiple autonomous agents reportedly worked together to identify vulnerabilities, bypass containment measures, and gain access to external systems during a cybersecurity e…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Connor Riley Moucka, a 26-year-old Canadian national from Kitchener, Ontario, has pleaded guilty to charges related to a large-scale cloud data theft and extortion operation that affected at least 165 organizations. This campaign resulted in the theft …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cisco has released security-hardening updates for IOS XE Software that address seven classes of vulnerabilities, including a critical command, operating system, and argument injection category identified as CVE-2026-20272. The advisory, released on Aug…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


