Crafted HEIC Uploads Can Turn WordPress Image Processing Into Server Code Execution
A newly demonstrated exploit chain turns a malicious HEIC upload into code execution through WordPress's server-side image pipeline. Administrators should update libheif, restrict unnecessary modern image formats, and...
Police Impersonation Call Center Dismantled in Timor-Leste, 16 Detained in Japan-Targeted Fraud Scheme
Authorities in Timor-Leste raided a Dili building allegedly used to run a scripted phone-fraud operation impersonating Japanese police, detaining 16 suspects and recovering fake uniforms and a prefectural...
Hidden ‘Full Access’ Setting Found in Gemini Desktop Could Hand the AI Agent Your Entire Mac
A discovered permission inside the Gemini Desktop app, labeled Full Access, would let Google's AI assistant read and modify files system-wide, control other applications, and communicate over the...
Apple to Overhaul macOS Full Disk Access Controls as AI Agents Gain More System Power
Apple says it will require a far more deliberate approval step before granting apps Full Disk Access on macOS, warning that the permission's sweeping reach becomes more dangerous...
Fake CAPTCHA Prompts Are Hiding Malware in Your Browser Cache, Microsoft Warns
Microsoft Threat Intelligence has uncovered a ClickFix variant that pre-stages a disguised VBScript payload inside the browser cache before a victim ever pastes a command into the Windows...
Undercover Blockchain Probe Maps Lazarus-Linked Laundering After $1.5B Bybit Theft
Blockchain investigator ZachXBT says an undercover operation exposed a Chinese laundering network handling funds linked to North Korea's $1.5 billion Bybit theft. Private chats were correlated with public...
GlassWorm Hides Malware Inside VS Code Themes to Target Developer Workstations
GlassWorm operators used convincing VS Code theme extensions to conceal downloaders, encrypted JavaScript and blockchain-based payload routing. Developer teams should remove confirmed malicious packages and investigate hosts because...
AI-Driven Zammad Attack Chained Two Zero-Days to Reach Root in Seconds
An AI-assisted intruder compromised the Dutch Institute for Vulnerability Disclosure by chaining two previously unknown Zammad flaws. The incident moved from session hijacking to root access in seconds...