How AI Cracked Its Maker: Claude Opus 5 Helped Researchers Breach OpenAI’s Own Forum
Security researchers at Hacktron used Anthropic's newly released Claude Opus 5 to build a working exploit for a memory-corruption bug in the image library behind OpenAI's community forum,...
Chrome 153 Patches 42 Security Flaws, Including Three Critical Memory Bugs
Google’s Chrome 153 stable update closes 42 vulnerabilities, including three critical memory-safety issues in Internals, Workers and WebGL. Users and administrators should ensure the browser has restarted on...
MapLibre Sanitizer Bug Puts 2.7 Million Sites at Risk of Zero-Click Code Execution
A critical flaw in the widely used MapLibre GL JS mapping library lets attackers slip malicious event handlers past its HTML sanitizer, triggering code execution with no clicks...
Critical ServiceNow AI Flaws Expose Enterprise Data and Code Execution Paths
ServiceNow has patched three critical AI-platform vulnerabilities and a high-severity Now Platform sandbox escape. Self-hosted customers should urgently verify fixed releases and investigate signs of unauthorized code execution...
Arista VeloCloud SD-WAN Orchestrators Under Active Attack via Maximum-Severity Command Injection Flaw
A perfect-10 command injection vulnerability in on-premises Arista VeloCloud Orchestrator deployments is being actively exploited, letting unauthenticated attackers reach privileged internal functions over the exposed web interface. Patches...
Five-Year-Old Bugs in a JSON Parser Open a Code Execution Hole in Self-Managed GitLab
Researchers chained two long-dormant memory-safety bugs in Ruby's Oj JSON parser to achieve remote code execution on self-managed GitLab instances, using nothing more than an ordinary commit and...
JetBrains Patches a Wave of Critical Flaws Across IntelliJ IDEA and TeamCity
JetBrains has released fixes for a critical remote-code-execution flaw in IntelliJ IDEA and four high-severity vulnerabilities in TeamCity, including a critical RCE reachable through malicious Git repository configuration....
RefluXFS: A Nine-Year-Old Race Condition in Linux’s XFS Filesystem Opens a Silent Road to Root
Qualys researchers have disclosed RefluXFS (CVE-2026-64600), a race condition in the Linux kernel's XFS copy-on-write path that lets a local, unprivileged user seize root access while leaving no...