Cybersecurity

n8n patches high-severity sandbox escape allowing OS command execution

n8n fixed a high-severity sandbox escape (CVSS 8.7) in versions 2.31.5 and 2.32.1 that could allow authenticated workflow editors to execute OS commands on...

East Asia hackers target Middle East govts with new Telegram malware

A previously undocumented East Asian threat actor is targeting Middle East government agencies with three new malware families: TELESHIM, MIXEDKEY, and BINDCLOAK.The TELESHIM backdoor...

SourTrade Malware Built in Browser Using Bun Runtime

SourTrade malvertising campaign targets cryptocurrency investors by assembling malware inside the victim's browser using a legitimate Bun runtime.It operates since late 2024, impersonating TradingView,...

Critical Fastjson flaw lets attackers hijack Spring Boot apps

A critical remote code execution vulnerability (CVE-2026-16723, CVSS 9.0) affects Alibaba's Fastjson library versions 1.2.68 through 1.2.83 when used in Spring Boot applications.Security firms...

BlueNoroff uses typosquatted Zoom domains in phishing

North Korean threat actor BlueNoroff is running ClickFix-style campaigns using typosquatted Zoom and Microsoft Teams domains.The group operates an active phishing kit designed to...

Claude Cowork bug lets AI break sandbox, access Mac files

Researchers at Accomplish AI discovered a sandbox escape vulnerability in Anthropic's Claude Cowork, affecting approximately 500,000 macOS users.The flaw, named SharedRoot, allowed an agent...

New Linux bug grants root access via snap-confine flaw

Security researchers at Qualys disclosed a high-severity local privilege escalation flaw (CVE-2026-8933) in snap-confine, affecting default Ubuntu Desktop installations.An unprivileged attacker can exploit two...

CISOs Earn Strategic Influence by Enabling Fast, Visible AI Adoption

76% of employees now use AI at work, up from 55% the previous year, according to McKinsey's State of AI report Security teams that build...

Latest news

Binance.US seeks CFTC license for prediction markets

Binance.US will apply for a Designated Contract Market (DCM) license from the CFTC in August.The license would allow the...

Rails critical Active Storage bug lets attackers read files remotely

Ruby on Rails patched a critical Active Storage vulnerability, CVE-2026-66066 (CVSS 9.5), allowing unauthenticated file read on servers using...

AI Credit Default Swaps Surge, Nvidia Protection Cost Doubles

Demand for credit default swaps (CDS) on mega-cap AI stocks has surged, with NVIDIA's annual insurance premium doubling since...