Cybersecurity

Three OpenClaw AI flaws allow host takeover via WhatsApp

Three high-severity flaws in the OpenClaw AI assistant (CVSS 8.8, 8.8, 8.4) could enable credential theft, privilege escalation, and arbitrary code execution.Researcher Chinmohan Nayak...

XRING bug lets attackers crash XQUIC servers with legal traffic

A remote crash vulnerability dubbed XRING affects all versions of Alibaba's XQUIC library, disclosed July 8.The flaw requires only 260 bytes of legitimate QPACK...

npm 12 disables install scripts, phases out 2FA bypass tokens

GitHub released npm version 12 with install scripts disabled by default, making previously automatic behaviors like dependency lifecycle scripts opt-in.Granular Access Tokens (GATs) designed...

New Webinar: Outpace AI Attacks with Zero Trust

AI-powered attacks, like the Mythos model, now execute in minutes what previously took attackers days.Traditional network-based defenses lag behind because they were built for...

RoguePlanet Microsoft Defender Flaw Patched After Month Delay

Microsoft patched a Defender privilege escalation flaw called RoguePlanet, tracked as CVE-2026-50656, nearly a month after public disclosure.The vulnerability, rated 7.8 on the CVSS...

Lurking Lizard uses fake 7-Zip installer to build proxy botnet

Threat actor Lurking Lizard has operated a residential proxy business since August 2022, using over 230 lookalike domains.The group lures victims with trojanized installers...

AI coding agents trigger security alarms by mimicking hackers

AI coding agents like Claude Code, Cursor, and OpenAI Codex are triggering endpoint detection rules designed for human attackers, according to a seven-day Sophos...

Ubiquiti patches critical flaws in UniFi products

Ubiquiti released emergency patches for seven critical vulnerabilities across its UniFi product line, with CVSS scores ranging from 9.0 to 10.0.The flaws affect UniFi...

Latest news

Allbridge Core pauses protocol after $1.65M security exploit

Allbridge paused its Allbridge Core protocol after a security incident drained $1.65 million from its Solana deployment.The attacker used...

Critical Nginx Flat Allows Unauthenticated Remote Code Execution

F5 patched a critical nginx heap buffer overflow (CVE-2026-42533) rated 9.2 on CVSS v4, affecting versions since 2011.The flaw...

Saylor lists 110 reasons against Bitcoin BIP-110 fork

Strategy executive chairman Michael Saylor published a 3,700-word post with 110 reasons against Bitcoin Improvement Proposal-110 (BIP-110), which aims...