Latest stories — Page 6

Illustration: a laptop screen showing abstract, unreadable code fragments and a partially rendered vector-graphic thumbnail
Vulnerabilities

Next.js Social Preview Feature Has a Remote Code Execution Bug

A flaw in the ImageResponse feature of Next.js lets attackers inject malicious content into SVG image generation and run arbitrary code on the server.

3 min read
A glowing cluster of interconnected nodes arranged in a voting pattern against a deep navy background, each node pulsing with faint electric-blue light, thin da
Threat Intelligence

CLOSEDQUORUM Runs Its Own Attack Without Asking Anyone

Cisco Talos has identified what it calls the first fully autonomous command-and-control implant: malware that polls a panel of AI models to decide its next move and never checks back with its operator.

4 min read
Illustration: a dark server room rack with a single glowing amber ethernet port emitting soft light
Vulnerabilities

One HTTP Request Turns Bifrost AI Gateway Into a Shell

A default-off auth setting in the popular open-source AI gateway lets anyone who can reach it run programs as the server user. The fix ships in 2.1.0.

4 min read
Illustration: a dimly lit modern conference room with a large wall-mounted video conferencing screen displaying an abstract
Identity & Access

EvilTokens: the phishing kit that turned a smart-TV login trick into a mass account raid

Microsoft says a subscription phishing service broke into more than 12,000 mailboxes by abusing the sign-in flow built for printers and conference room screens.

4 min read
Illustration: a developer's desk at night
AI Security

AI Coding Tool Was Quietly Uploading Your Entire Codebase to China

Z.ai's ZCode assistant packaged developers' full project histories by default and sent them to Alibaba Cloud servers. The company has disabled the feature, deleted the stored data, and opened its source code for review.

4 min read
Illustration: a dimly lit enterprise server rack with a single network orchestrator appliance glowing amber
Vulnerabilities

Arista Says a VeloCloud Orchestrator Bug Is Already Being Exploited

A remote attacker with no login can reach privileged functions on the server that runs an entire SD-WAN network. On-prem customers using certificate authentication need to act now.

3 min read
Illustration: an Arm-based server motherboard under cool blue rack
Vulnerabilities

Arm64 KVM flaw lets a guest VM reach into the host's memory

CVE-2026-89775 is a critical Linux kernel bug in the Arm64 virtualization path. A researcher says a guest can read and write host memory when nested virtualization is on.

3 min read
Illustration: a dimly lit server room with rows of dark network racks and cool blue status lights
Vulnerabilities

Microsoft Called This SharePoint Bug a Spoofing Issue. It Runs Code.

A vulnerability first rated medium turned out to let logged-in users execute code on the server. The researcher who found it just published the details.

3 min read
Illustration: a rack-mounted network switch in a dim server room, front panel activity LEDs glowing amber and green
Vulnerabilities

CISA gives federal agencies three days to patch a Zyxel switch bug already being used in attacks

CVE-2026-7273 lets anyone on the local network hijack GS1900 switches with a single crafted web request. Federal deadline: 24 September 2026.

3 min read
Illustration: a dimly lit server rack in a data centre, one blade server pulled halfway out
Ransomware

ShinyHunters defaces Cl0p's leak site and claims it grabbed the gang's Tor keys

The extortion crew says it walked out with source code, server logs, and the private keys that identify Cl0p's dark-web address. The fight traces back to a stolen Oracle exploit.

4 min read
Illustration: a modern silver laptop on a dark desk
Threat Intelligence

The macOS ClickFix Scam Learned to Hide From Researchers

Microsoft says the fake-fix lure now checks your browser before showing itself, and a related campaign is pushing a new remote-control tool called ChainScript.

4 min read
Illustration: a dimly lit corporate server room, rows of dark rack-mounted network firewall appliances with glowing amber
Vulnerabilities

Check Point patches critical login flaw that hands attackers root on firewall management servers

CVE-2026-91843 is the third critical bug in a fortnight for Check Point, and two earlier authentication bypasses are already being exploited in the wild.

4 min read
Illustration: a darkened corporate open-plan office at night
Identity & Access

Fake IT Support on Microsoft Teams Is Now a Full Corporate Break-In

Microsoft says attackers are cold-calling staff on Teams, talking them into a screen share, then walking straight through the network to domain controllers.

4 min read
Illustration: A dimly lit medical office reception desk at night, empty waiting room chairs visible in the background
Ransomware

Ransomware Group Emperador Claims Attack on Alabama Women's Health Clinic

A fast-moving criminal group listed an Alabama reproductive-health practice on its dark-web site, claiming thousands of employee and patient documents. The practice has not confirmed anything.

3 min read
Illustration: a small industrial server rack installed inside a working factory floor
AI Security

When the AI Runs on Your Hardware, You Own the Security Problem

Microsoft says customers running AI on their own kit inherit a security job cloud providers used to handle. Here is what that actually means.

4 min read
Illustration: a smartphone lying face-up on a dark office desk
Identity & Access

Fake IT helpdesk calls are opening the door to Microsoft 365 accounts

Microsoft says attackers are ringing staff on personal phones, walking them through passkey 'updates', then pulling SharePoint and OneDrive files.

4 min read
Illustration: a cluttered corporate mail sorting facility at dusk
Threat Intelligence

Microsoft says Defender missed 221 high-severity emails per thousand users and still won its own benchmark

The vendor's fifth quarterly scorecard shows missed-threat rates climbing across the industry as AI-written phishing gets harder to catch.

4 min read
Illustration: a modern data centre cold aisle at night, blue LED indicator lights reflecting on polished floor
Cloud Security

Microsoft Publishes a Cloud Web App Attack Playbook and Names the Weak Spots Nobody Wants to Own

Microsoft's new threat matrix organises how attackers actually break into cloud-hosted web apps, from forgotten DNS records to Kudu consoles left facing the internet.

4 min read
Illustration: a dimly lit server rack in a modern data center, blue and amber indicator lights reflecting on glass panels
Vulnerabilities

Attackers Are Breaking Into Orkes Conductor Servers Through a Critical Pre-Login Flaw

Fortinet says opportunistic scanning has begun against Orkes Conductor installations vulnerable to CVE-2026-58138, a pre-authentication remote code execution bug patched in version 3.30.2.

3 min read
Illustration: A darkened developer workspace at night: an open laptop showing a blurred terminal with green package-install
Breaches

How a poisoned coding library led to 170 private repos being copied at CrowdSec

A French security firm says a departing employee's laptop was infected through the TanStack npm supply-chain attack in May. The fallout reached its GitHub.

3 min read
Illustration: a dimly lit server rack in a data centre, blue and amber status LEDs reflecting off polished floor tiles
Vulnerabilities

CISA tells federal agencies: patch three Linux kernel bugs within days, attackers already using them

Three Linux kernel flaws are being exploited in the wild. Federal agencies have until 21 September to patch, and the most serious carries a 9.8 severity score.

4 min read
© 2026 Threat Vectr