Latest stories — Page 6

Next.js Social Preview Feature Has a Remote Code Execution Bug
A flaw in the ImageResponse feature of Next.js lets attackers inject malicious content into SVG image generation and run arbitrary code on the server.

CLOSEDQUORUM Runs Its Own Attack Without Asking Anyone
Cisco Talos has identified what it calls the first fully autonomous command-and-control implant: malware that polls a panel of AI models to decide its next move and never checks back with its operator.

One HTTP Request Turns Bifrost AI Gateway Into a Shell
A default-off auth setting in the popular open-source AI gateway lets anyone who can reach it run programs as the server user. The fix ships in 2.1.0.

EvilTokens: the phishing kit that turned a smart-TV login trick into a mass account raid
Microsoft says a subscription phishing service broke into more than 12,000 mailboxes by abusing the sign-in flow built for printers and conference room screens.

AI Coding Tool Was Quietly Uploading Your Entire Codebase to China
Z.ai's ZCode assistant packaged developers' full project histories by default and sent them to Alibaba Cloud servers. The company has disabled the feature, deleted the stored data, and opened its source code for review.

Arista Says a VeloCloud Orchestrator Bug Is Already Being Exploited
A remote attacker with no login can reach privileged functions on the server that runs an entire SD-WAN network. On-prem customers using certificate authentication need to act now.

Arm64 KVM flaw lets a guest VM reach into the host's memory
CVE-2026-89775 is a critical Linux kernel bug in the Arm64 virtualization path. A researcher says a guest can read and write host memory when nested virtualization is on.

Microsoft Called This SharePoint Bug a Spoofing Issue. It Runs Code.
A vulnerability first rated medium turned out to let logged-in users execute code on the server. The researcher who found it just published the details.

CISA gives federal agencies three days to patch a Zyxel switch bug already being used in attacks
CVE-2026-7273 lets anyone on the local network hijack GS1900 switches with a single crafted web request. Federal deadline: 24 September 2026.

ShinyHunters defaces Cl0p's leak site and claims it grabbed the gang's Tor keys
The extortion crew says it walked out with source code, server logs, and the private keys that identify Cl0p's dark-web address. The fight traces back to a stolen Oracle exploit.

The macOS ClickFix Scam Learned to Hide From Researchers
Microsoft says the fake-fix lure now checks your browser before showing itself, and a related campaign is pushing a new remote-control tool called ChainScript.

Check Point patches critical login flaw that hands attackers root on firewall management servers
CVE-2026-91843 is the third critical bug in a fortnight for Check Point, and two earlier authentication bypasses are already being exploited in the wild.

Fake IT Support on Microsoft Teams Is Now a Full Corporate Break-In
Microsoft says attackers are cold-calling staff on Teams, talking them into a screen share, then walking straight through the network to domain controllers.

Ransomware Group Emperador Claims Attack on Alabama Women's Health Clinic
A fast-moving criminal group listed an Alabama reproductive-health practice on its dark-web site, claiming thousands of employee and patient documents. The practice has not confirmed anything.

When the AI Runs on Your Hardware, You Own the Security Problem
Microsoft says customers running AI on their own kit inherit a security job cloud providers used to handle. Here is what that actually means.

Fake IT helpdesk calls are opening the door to Microsoft 365 accounts
Microsoft says attackers are ringing staff on personal phones, walking them through passkey 'updates', then pulling SharePoint and OneDrive files.

Microsoft says Defender missed 221 high-severity emails per thousand users and still won its own benchmark
The vendor's fifth quarterly scorecard shows missed-threat rates climbing across the industry as AI-written phishing gets harder to catch.

Microsoft Publishes a Cloud Web App Attack Playbook and Names the Weak Spots Nobody Wants to Own
Microsoft's new threat matrix organises how attackers actually break into cloud-hosted web apps, from forgotten DNS records to Kudu consoles left facing the internet.

Attackers Are Breaking Into Orkes Conductor Servers Through a Critical Pre-Login Flaw
Fortinet says opportunistic scanning has begun against Orkes Conductor installations vulnerable to CVE-2026-58138, a pre-authentication remote code execution bug patched in version 3.30.2.

How a poisoned coding library led to 170 private repos being copied at CrowdSec
A French security firm says a departing employee's laptop was infected through the TanStack npm supply-chain attack in May. The fallout reached its GitHub.

CISA tells federal agencies: patch three Linux kernel bugs within days, attackers already using them
Three Linux kernel flaws are being exploited in the wild. Federal agencies have until 21 September to patch, and the most serious carries a 9.8 severity score.