Patch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent Swarms
The vulnerability in the AI hosting platform Ruflo allows an unauthenticated attacker to take over the system and corrupt memory, so bad behavior can persist after patching.
The vulnerability in the AI hosting platform Ruflo allows an unauthenticated attacker to take over the system and corrupt memory, so bad behavior can persist after patching.
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications f…
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the …
AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along. The conversation happening in security circles right now goes something like this: Mythos is he…
Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it Hig…
Cibercriminosos estão escondendo malware em um falso comando de instalação do Claude Code para infectar computadores macOS. A campanha usa anúncios patrocinados e páginas aparentemente legítimas para alcançar desenvolvedores interessados na ferramenta de inteligência artificial. …
Uma nova botnet chamada Tengu está infectando dispositivos de Internet das Coisas e sistemas Linux embarcados para executar ataques de negação de serviço, redirecionar tráfego e manter acesso persistente. A ameaça é uma versão modernizada do malware Mirai. A infecção observada co…
A Arista Networks publicou ontem (27 de julho) um aviso de segurança sobre uma vulnerabilidade de injeção de comandos no VeloCloud Orchestrator (VCO) on-prem, classificada com a pontuação máxima de gravidade CVSS 10.0. A falha, rastreada como CVE-2026-16812, pode permitir que um …
Researchers found 24,650 public BMC interfaces leaking IPMI password hashes, exposing servers to offline password cracking through a decades-old protocol flaw.
Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild. The vulnerab…
Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-…
Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked the framework to a f…
OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's production environment, and also hacked multiple third-party accounts and services as part of the attack. The latest disclosure sh…
Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/layouts@0.1.2-2773.beta.0 @joyfill/compon…
A Apple publicou ontem atualizações de segurança para iOS, iPadOS e macOS que corrigem vulnerabilidades permitindo a execução de código arbitrário em iPhones, iPads e Macs por meio de imagens maliciosas. As falhas afetam os componentes AppleDouble, ImageIO e SceneKit. Vulnerabili…
10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch.
Security researcher Aleksandr Krasnov reveals dormant non-human identities can create security blind spots and releases NHI Hound, an open source tool to sniff out trust paths.
CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. [...]
Lots of Internet-exposed server management controllers are subject to offline password-cracking attacks — and adversaries have taken note.
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. [...]