Researcher Chains a Guardrail Bypass With a Path Traversal Flaw to Access System Files in ChatGPT
A proof-of-concept disclosed by researcher zer0dac combined social engineering against ChatGPT's own safety logic with a path traversal bug to retrieve restricted system files through the platform's file...
Ousaban Banking Trojan Resurfaces With Steganographic PDF Lures Targeting Spain and Portugal
Fortinet's FortiGuard Labs has documented a fresh wave of the Ousaban banking trojan hitting Windows users in Spain and Portugal through fake corrupted PDFs and a spoofed tax...
New ARToken Phishing Kit Abuses Microsoft’s OAuth Device Code Flow to Hijack Microsoft 365 Accounts
Cisco Talos has uncovered ARToken, a phishing panel that abuses Microsoft's device code sign-in flow to steal Microsoft 365 session tokens without a password or MFA prompt. The...
Researchers Chain DLL Sideloading and an RPC Flaw to Gain Root Access Inside Claude Cowork’s Sandbox
Security researchers at Armadin found a way to chain DLL sideloading with a flaw in an internal RPC protocol to escalate privileges and execute commands as root inside...
Google Dismantles NetNut-Linked “Popa” Residential Proxy Botnet That Hijacked 2 Million Home Devices
Google, working with the FBI, Lumen Technologies, and other partners, has taken action against the NetNut residential proxy network - also tracked as "Popa" - estimated to have...
AsyncRAT Trojan Hidden in 90+ Fake Software Download Sites via DLL Sideloading and ScreenConnect
A stealthy campaign is hiding the AsyncRAT trojan inside fake installers for popular free software, using DLL sideloading and the legitimate ScreenConnect remote-access tool to slip past security...
New CitrixBleed-Class Vulnerability in Citrix NetScaler Exploited Within 24 Hours of Disclosure
CVE-2026-8451, the latest entry in the CitrixBleed family of NetScaler memory-disclosure flaws, came under active exploitation less than a day after public disclosure. Decoy infrastructure operator Lupovis tracked...
DHS Confirms Hackers Breached HSIN, the Government’s Emergency Information-Sharing Platform
The Department of Homeland Security has confirmed a breach of the Homeland Security Information Network (HSIN), the unclassified platform used by federal, state, local, and international partners to...