Actively Exploited F5 BIG-IP OAuth Zero-Day Enables Unauthenticated RCE
F5 is warning that attackers are exploiting a critical BIG-IP APM zero-day that can provide unauthenticated remote code execution on certain OAuth authorization-server deployments. Organizations should identify exposed...
Check Point Confirms In-the-Wild Attacks on Critical Management Server Zero-Day
A critical, pre-authentication flaw in Check Point's Management Server software was exploited in the wild weeks before a fix existed, letting attackers upload and run code on systems...
Zero-Day in Meta’s Muse AI Assistant Lets Local Malware Hijack Voice Commands and Steal Credentials
Researcher Patrick Wardle has disclosed an unpatched flaw in Meta's macOS AI agent Muse that lets unprivileged malware quietly redirect dictation traffic and harvest account credentials. The bug...
Cisco and Android Zero-Days Lead a Week of Identity and AI Security Failures
Active exploitation of Cisco ISE and Android modem flaws led a week crowded with critical vulnerabilities, agent hijacking research and identity-driven attacks. Defenders should prioritize exposed control planes,...
Steam Windows Zero-Day Turns Local Access Into Full SYSTEM Control
A newly disclosed weakness in the Steam Client Service reportedly lets a standard Windows user execute code with SYSTEM privileges. With no confirmed vendor fix at publication time,...
Cisco Email Gateway Zero-Day Gives Remote Attackers Root Control
Cisco is warning that attackers are exploiting a critical Secure Email Gateway zero-day to execute commands as root without authentication. Organizations should isolate management interfaces, apply Cisco’s remediation...
Exploited Zero-Days and Perimeter Flaws Put Patch Triage Under Pressure
This week’s security picture is dominated by exploited Windows and Chrome zero-days, dangerous flaws in perimeter products and increasingly automated attack operations. Defenders need risk-based patch sequencing, exposure...
Claude Misuse Report Shows AI Agents Automating Exploits, Malware Changes and Intrusions
Anthropic says state-backed groups, cybercriminals and hacktivists misused Claude to automate attack chains, develop exploits and adapt malware. The cases show that AI agents can compress specialist work...