How a Rogue Prompt Could Turn Microsoft Copilot Into a $250,000 Wire Fraud Accomplice
A proof-of-concept from Barracuda researchers shows how attackers could weaponize Microsoft Copilot itself to escalate a single compromised inbox into full CEO account takeover and a quarter-million-dollar wire...
One Click, Total Takeover: The RCE Bug That Hid Inside Cursor, VS Code, and Google Antigravity
Security researchers at AISLE uncovered a one-click remote code execution flaw shared by Cursor, Microsoft VS Code, and Google Antigravity, all three built on the same underlying codebase....
Six Ways to Break Flowise: New RCE Chain Puts AI Workflow Servers at Risk
Security researchers at Elttam disclosed six separate remote code execution flaws in the Flowise AI workflow platform, spanning CSV processing, sandboxed JavaScript, and database configuration. Several of the...
DarkSword Exploit Kit Quietly Expands to 180 Sites, Turning iPhones Into Data-Theft Targets
A leaked iOS exploit chain known as DarkSword has grown into a sprawling, fast-changing network of malicious infrastructure, with researchers at Censys tracking 27 hosts and 180 web...
Arch Linux Freezes AUR Package Adoptions After Attackers Exploit Abandoned Projects
Arch Linux has temporarily disabled the ability to adopt orphaned AUR packages after security teams spotted a wave of hostile takeovers followed by malicious code injected through routine-looking...
How One Poisoned Tracking Script Turned a Major Ad Platform Into a Crypto-Theft Pipeline
Researchers say attackers hijacked a widely deployed JavaScript file from ad-tech company Adform, turning routine website analytics into a silent clipboard hijacker that swaps copied crypto wallet addresses...
ShinyHunters Strikes Again: Brinks Home Confirms Breach Tied to Salesforce Systems
Brinks Home has confirmed attackers broke into systems connected to its Salesforce environment after the ShinyHunters extortion crew claimed to have stolen nearly five million records. The company...
865,000 ‘No-Logs’ VPN Users Exposed After SplitVPN Breach Reveals Hidden Connection Records
A breach at Russian VPN provider SplitVPN, formerly NotVPN, has exposed the records of roughly 865,000 users despite the service's long-standing 'no logs' promise. The leaked database reportedly...