AI-Powered Pentest Uncovers Eight Security Holes in Popular NodeBB Forum Software
A whitebox penetration test assisted by AI tools found eight high-severity flaws in the NodeBB forum platform, including bugs that could let attackers read private messages, hijack admin...
Claude AI’s Shared Chat Links Briefly Turned Up in Google Search, Exposing Private Conversations
Hundreds of Claude AI shared-chat links reportedly became publicly searchable on Google over the weekend, exposing legal advice, proprietary code, and personal conversations to anyone who searched for...
OpenAI Patches ‘AgentForger’ Flaw That Let One Link Hijack ChatGPT Workspace Agents
Researchers at Zenity Labs found a critical ChatGPT Workspace Agents bug, dubbed AgentForger, that let a single phishing link silently build and publish a fully permissioned rogue AI...
Inside the Pro-Iran Hacktivist Coalition Racing to Mobilize During the US-Iran Conflict
A new analysis maps the loosely coordinated network of pro-Iran hacktivist groups, state-aligned actors, and opportunistic allies that have ramped up disruptive cyber campaigns since US and Israeli...
How a Crafted SVG File Could Have Handed Attackers SYSTEM Access on Microsoft’s Bing Servers
Three critical, now-patched vulnerabilities in Microsoft's infrastructure show how an everyday image upload feature in Bing Images became a path to remote code execution as NT AUTHORITY\SYSTEM. Researchers...
Certighost Flaw Let Ordinary Users Impersonate Domain Controllers and Seize Active Directory
A newly patched Active Directory Certificate Services bug, dubbed Certighost, let any low-privileged domain user trick a certificate authority into treating a rogue machine as a real Domain...
Cl0p Affiliates Are Breaching PTC Windchill Servers to Steal Product Blueprints Before Extortion
Cl0p-linked attackers are chaining an unauthenticated information disclosure bug with a critical deserialization flaw in PTC Windchill and FlexPLM to steal engineering and product-design data from manufacturers, automakers,...
Fake Claude Desktop Ads on Bing Are Delivering SectopRAT to Corporate Networks
A campaign dubbed FakeAgent used paid Bing search ads and a malicious public Claude Artifact to trick corporate employees into installing a disguised remote access trojan. At least...