Critical Ruby on Rails Flaw Lets Attackers Steal Server Secrets Through Image Uploads
A critical vulnerability in Rails' Active Storage component, tracked as CVE-2026-66066, allows unauthenticated attackers to read arbitrary files — and potentially achieve remote code execution — on applications...
Researchers Show How a Hidden Prompt Can Turn Word Copilot Into a Self-Spreading AI Worm
A newly disclosed weakness in Microsoft Copilot for Word shows how invisible text buried in a document can hijack the AI assistant, quietly alter content, and copy itself...
Fake CAPTCHA Pages Are Now Tricking Mac Users Into Installing Password-Stealing Malware
Kaspersky has documented a ClickFix campaign now targeting macOS users, luring them into pasting a Terminal command that quietly installs Atomic Stealer (AMOS). The malware harvests browser passwords,...
FBI Warns Russian State Hackers Are Tricking Signal Users Into Handing Over Backup Keys
The FBI says Russian intelligence-linked hacking clusters are impersonating Signal support to trick high-value targets — officials, military personnel, journalists, and Ukrainian leadership — into revealing their backup...
Foxit’s Own Update Service Can Be Turned Into a SYSTEM-Level Backdoor on Windows
A privilege-escalation flaw in Foxit PDF Reader's updater, tracked as CVE-2026-57239, lets an attacker who already has a foothold on a Windows machine ride the update service all...
Five-Year-Old Bugs in a JSON Parser Open a Code Execution Hole in Self-Managed GitLab
Researchers chained two long-dormant memory-safety bugs in Ruby's Oj JSON parser to achieve remote code execution on self-managed GitLab instances, using nothing more than an ordinary commit and...
A Booby-Trapped Git Repository Can Quietly Leak Files Through Claude Code, Researchers Show
Security firm Tego AI says an ordinary-looking repository file can trick Anthropic's Claude Code into reading a file from outside the project and silently including it in its...
JetBrains Patches a Wave of Critical Flaws Across IntelliJ IDEA and TeamCity
JetBrains has released fixes for a critical remote-code-execution flaw in IntelliJ IDEA and four high-severity vulnerabilities in TeamCity, including a critical RCE reachable through malicious Git repository configuration....