Latest Security News

software security news

“A malicious unauthenticated actor may exploit this issue to execute arbitrary commands, which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress,” the company said in an advisory released late last month. “We found no evidence that OpenAI user data was accessed, that our systems or intellectual property were compromised, or that our software was altered.” The disclosure comes a little over a week after Google Threat Intelligence Group (GTIG) attributed the supply chain compromise of the popular npm package to a North Korean hacking group it tracks as UNC1069 . OpenAI revealed a GitHub Actions workflow used to sign its macOS apps led to the download of the malicious Axios library on March 31, but noted that no user data or internal system was compromised. Once the extensions begin to gather user downloads, a new version with the malicious behavior is published. In a post-mortem published August 28 , Cosmos Labs said the flaw was reported through its bug bounty program on April 25 and was assessed at the time as posing no risk to funds on live networks. The campaign, targeting organizations across multiple sectors, leverages compromised websites as a starting point to serve fake Cloudflare CAPTCHA verifications that prompt unsuspecting site visitors to copy and execute a malicious PowerShell command.

And increasingly, it’s the question leaders are forced to answer after an incident. Cybersecurity researchers have disclosed details of two now-patched security flaws in the n8n workflow automation platform, including two critical bugs that could result in arbitrary command execution. “N8n contains an improper control of dynamically managed code resources vulnerability in its workflow https://www.librarysites.info/learning-the-secrets-of/ expression evaluation system that allows for remote code execution,” CISA said.

Security teams must treat autonomous agents as highly privileged identities.

software security news

ATM Flaws Reveal Key Weaknesses in the Software Supply Chain

The only itemized account in circulation is the attackers’ own, a leak-site post indexed on August 28 that claims 5.79 terabyt… Scope and content are still being examined, and the Senate Chancellery said personal or other non-public data cannot be excluded from what was taken. The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment, with the exfiltration dated between August 7 and August 12, 2026. Berlin’s state government has confirmed that it is the target of an extortion attempt following the August compromise of the city’s state administrative network, and said it will not meet the extortionists’ demands. Controlling the routers gave the actor a vantage point over traffic moving through trusted network paths, Sygnia said. However, activity against those networks was limited to scanning and connection attempts rather than confirmed compromise.

Laflamme published the research on August 27, 2026, describing the two issues as separate root-RCE paths. As of the August 27 disclosure, the current cloud-assisted route requires an account bound to the target G1 or the relevant key material already in hand. Laflamme said Unitree patched the cloud account-to-robot ownership check in July 2026. An exact fixed firmware release has not been verified in any accessible Unitree guidance, leaving G1 EDU owners without a confirmed release target for either vulnerability. Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. “This new privacy standard works in tandem with private DNS to obscure the domain names you visit, hiding metadata that can be used to profile you,” Google’s Bram Bonné and Shuaibo Huang said .

WiFi users didn’t have to travel very far to get caught up in this breach. Veeam has released security updates to address multiple critical vulnerabilities in its Backup & Replication software that, if successfully exploited, could result in remote code execution. “In ShowDoc version before 2.8.7, an unrestricted and unauthenticated file upload issue is found and an attacker is able to upload a web shell and execute arbitrary code on server,” according to an advisory released by Vulhub. “The malware could generate an uncensored scan report, encrypt it, and send it to an external endpoint, creating a serious risk for teams using KICS to scan infrastructure-as-code files that may contain credentials or other sensitive configuration data.” Further analysis of the incident has uncovered that related Ch… “Analysis of the poisoned image indicates that the bundled KICS binary was modified to include data collection and exfiltration capabilities not present in the legitimate version,” Socket said. In an alert published today, software supply chain security company Socket revealed that unknown threat actors managed to have overwritten existing tags, including v2.1.20 and alpine, while also introducing a new v2.1.21 tag that does not correspond to an official release.

software security news

The AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage. Local boy and 4-time F1 champ Max Verstappen has just extended his Red Bull contract through 2030. Splashtop Shield lets tech-savvy users remotely fix family PC issues with ease, but actual virus protection tanked in my hands-on security tests. Real Madrid and its bevy of stars, including Mbappé, Bellingham, Vini Jr, and Valverde, will look to keep their winning streak going as they take on Malaga. From AI-generated images to restricted satellite data, the systems used to verify what’s real online are struggling to keep up. Chrome users were caught off guard by a 4-GB Google AI model baked into Chrome, sparking privacy concerns.

SECURITYWEEK NETWORK:

  • OpenAI has launched Daybreak , a new cybersecurity initiative that brings together frontier artificial intelligence (AI) model capabilities and Codex Security to help organizations identify and patch vulnerabilities before attackers find a way in using the same issues.
  • “We found no evidence that OpenAI user data was accessed, that our systems or intellectual property were compromised, or that our software was altered.” The disclosure comes a little over a week after Google Threat Intelligence Group (GTIG) attributed the supply chain compromise of the popular npm package to a North Korean hacking group it tracks as UNC1069 .
  • The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.
  • However, activity against those networks was limited to scanning and connection attempts rather than confirmed compromise.

The firm assessed that the hacker group used its foothold to explore paths to connected high-value environments, including critical infrastructure. A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal https://skillpoint.info/innovations-in-wood-carving-the-latest-tools-and-gadgets/ Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks. CloudSEK said the exposed open directory leaked “months of activity” that was active against more than 20 organizations across nine countries between April and July 2026. “This case is a clear example of how adware and affiliate networks can turn out to be far more dangerous than they appear. ValleyRAT is a sophisticated backdoor capable of… Kaspersky said the attack’s geography and payload point to Silver Fox as the likely group behind it, and urged users to avoid software of questionable reputation and to keep it away from security-tool exclusions. Once installed, ValleyRAT (also tracked as Winos 4.0) hands the operator full control of the compromised machine.

software security news

How to Watch Liverpool vs. Nottingham Forest Live for Free

Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU , including a Bluetooth Low Energy (BLE) path that can reach root on the robot’s Locomotion PC. “By encrypting the destination website name from the very start, ECH helps ensure that, for supported websites and apps, network providers and network snoopers can no longer easily see which websites or apps you are accessing.” Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users’ home networks. Huntress has explained the flaw as follows – In unpatched versions of PaperCut NG and PaperCut MF, a specifically crafted request can refer to one page that is rendered for the response, and another page that owns the component or action being executed.

“Because the internal header format used a delimiter character that could also appear in user input, an attacker could inject additional metadata fields through crafted push option values.” Google-owned cloud security firm Wiz has been credited with discovering and reporting the issue on March 4, 2026, with GitHub validating and deployi… Cybersecurity researchers have disclosed details of a critical security vulnerability impacting GitHub.com and GitHub Enterprise Server that could allow an authenticated user to obtain remote code execution with a single “git push” command. A new software supply chain attack campaign has been observed using sleeper packages as a conduit to subsequently push malicious payloads that enabled credential theft, GitHub Actions tampering, and SSH persistence. AVB Disc Soft, the developer of the software, has been notified of the breach.

software security news

Berlin Won’t Pay Extortion Group Claiming Data Theft

Sygnia, the incident response firm that investigated the intrusion, said the actor turned the compromised routers into collection platforms, capturing network traffic, harvesting credentials, and suppressing the logging and telemetry that defenders rely on to reconstruct an attack. They account for 68.6% of the AI agents Token Security discovers in customer environments, and they often inherit the employee’s credentials, network position, and permissions. Illinois prosecutors shared defendants’ personal data with federal immigration agents without criminal warrants, public disclosure, or legislative oversight. Alpharetta, Georgia, cops share data with thousands of Flock users, ranging from federal agencies to a fish and wildlife commission.

Mobile networks expose IMEI and other phone data to attackers – report

Checkmarx has confirmed that a modified version of the Jenkins AST plugin was published to the Jenkins Marketplace. RubyGems , the standard package manager for the Ruby programming language, has temporarily paused account sign ups following what has been described as a “major malicious attack.” “We’re dealing with a major malicious attack on RubyGems right now,” Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, said in a post on X. Its purpose is to reconcile what access policy intends with how identities are actually used at runtime. As enterprise access spans more cloud services and automated workloads, identity security depends less on static configuration and more on runtime visibility.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top