CARBONATO Botnet Embeds an AI Agent in Compromised Docker Hosts
The CARBONATO botnet abuses unauthenticated Docker services, escapes privileged containers and installs an AI agent controlled through Telegram. Separate automated scripts spread across nearby networks while the agent...
Samsung MagicINFO Exploit Leads to Persistent Access and On-Host Cryptominer Build
Attackers exploited a known Samsung MagicINFO file-write flaw, installed AnyDesk, created an administrator account and disabled Microsoft Defender before building a Monero miner on the victim. The case...
Actively Exploited Linux Kernel Race Condition Enables Root and Container Escape
A race condition in Linux’s AF_ALG cryptographic interface can give an unprivileged local attacker root access and may support Docker container escape. CISA lists CVE-2025-39964 as exploited in...
Unsigned JWT Flaw Opened Microsoft Analytics Service to Administrator Access
A missing signature check in Microsoft’s internal Titan analytics service allowed a forged token to obtain administrator privileges and query connected databases. Microsoft closed the public endpoint after...
TWEAKOS Doesn’t Just Steal Your Discord and Telegram Accounts — It Puts Them Up for Sale
A newly uncovered malware operation called TWEAKOS pairs a lightweight Windows stealer with a Telegram-based storefront, letting operators harvest Discord tokens and hijack Telegram sessions, then sell the...
No Permissions Needed: OxygenOS Bugs Could Hand Root Access to Any App on a OnePlus 15
Two unpatched flaws in OnePlus's latest OxygenOS build could let an app that requests zero permissions still seize root-level control of the device, by abusing privileged system services...
ServiceNow Rushes Fixes for Five AI Platform Bugs After Two Are Rated Critical
ServiceNow has patched five vulnerabilities in its AI Platform, including a SQL injection flaw and a missing-authorization bug that together could let an unauthenticated attacker read, alter, or...
When AI Agents Go Off-Script: OpenAI Systems Quietly Probed Four Public Websites
Newly disclosed incidents show OpenAI's autonomous agents escalating to SQL injection, path traversal, and access-control bypass attempts against government and university systems on their own, without ever being...