🦜 BugsToday – Zero-Days, Exploits & Vulnerabilities
@bugstoday.com@rss-parrot.net
I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline!
Brought to you by the RSS Parrot.
---
Today's Bugs. Tomorrow's Breaches.
Your feed and you don't want it here? Just
e-mail the birb.
Attackers Are Hitting GitLab’s Critical GraphQL Bug Without Logging In
https://bugstoday.com/attackers-are-hitting-gitlabs-critical-graphql-bug-without-logging-in/
Published: September 3, 2026 13:21
GitLab’s GraphQL API just became a very bad place to leave unpatched. CVE-2026-19478 is a critical code injection vulnerability affecting self-managed GitLab Community Edition and...
The post Attackers Are Hitting GitLab’s Critical GraphQL Bug Without…
A WhatsApp Video Call Can Open Your Photo Gallery Without Unlocking Your Phone
https://bugstoday.com/a-whatsapp-video-call-can-open-your-photo-gallery-without-unlocking-your-phone/
Published: September 3, 2026 12:58
Your phone is locked. Your photos should be locked too. Apparently, that assumption does not always survive a WhatsApp video call. Security researcher Jose Rodriguez...
The post A WhatsApp Video Call Can Open Your Photo Gallery Without Unlocking Your Phone…
A Critical VMware Bug Can Let Code Escape the VM and Reach the Host
https://bugstoday.com/a-critical-vmware-bug-can-let-code-escape-the-vm-and-reach-the-host/
Published: September 3, 2026 12:55
Virtual machines exist for a reason. Run something dangerous inside the guest. Keep the host safe. Broadcom has now disclosed vulnerabilities that can attack exactly...
The post A Critical VMware Bug Can Let Code Escape the VM and Reach the Host appeared…
Pegasus Just Infected an iPhone Without the User Touching It
https://bugstoday.com/pegasus-just-infected-an-iphone-without-the-user-touching-it/
Published: September 3, 2026 10:13
You don’t need to click anything. You don’t need to open a suspicious attachment. You don’t even need to know an attack is happening. That’s...
The post Pegasus Just Infected an iPhone Without the User Touching It appeared first on BugsToday – Zero-Days,…
Thomson Reuters Court Data Breach Exposed Files From 11 U.S. States and Canada
https://bugstoday.com/thomson-reuters-court-data-breach-exposed-files-from-11-u-s-states-and-canada/
Published: September 3, 2026 10:11
Court data just became someone else’s problem. Then everyone else’s problem. Thomson Reuters has confirmed a cybersecurity incident involving its C-Track case management platform, which...
The post Thomson Reuters Court Data Breach Exposed Files From 11…
AI Infrastructure Is Being Hacked for Keys, Shells and Crypto Mining
https://bugstoday.com/ai-infrastructure-is-being-hacked-for-keys-shells-and-crypto-mining/
Published: September 3, 2026 10:09
AI infrastructure has officially become an attack surface worth stealing. Not because attackers suddenly care about chatbots. They care about everything sitting behind them. Microsoft...
The post AI Infrastructure Is Being Hacked for Keys, Shells and…
SonicWall SMA 1000 Is Under Attack: Two Zero-Days Can Open the Door to RCE
https://bugstoday.com/sonicwall-sma-1000-is-under-attack-two-zero-days-can-open-the-door-to-rce/
Published: September 3, 2026 10:08
SonicWall has another problem at the edge. And this time it is not theoretical. The company confirmed active exploitation of two previously undisclosed vulnerabilities affecting...
The post SonicWall SMA 1000 Is Under Attack: Two Zero-Days Can Open the…
CrowdStrike Falcon Has a New 0-Day Problem. The PoC Is Already Public
https://bugstoday.com/crowdstrike-falcon-has-a-new-0-day-problem-the-poc-is-already-public/
Published: September 3, 2026 10:06
The irony is almost too clean. CrowdStrike Falcon exists to stop attackers from doing exactly this. FalconFlank allegedly abuses one of the platform’s defensive mechanisms...
The post CrowdStrike Falcon Has a New 0-Day Problem. The PoC Is Already Public…
A Critical WordPress Bug Can Hand Attackers Elevated Access Without a Login
https://bugstoday.com/a-critical-wordpress-bug-can-hand-attackers-elevated-access-without-a-login/
Published: September 3, 2026 06:22
A WordPress site does not always need a stolen password to be compromised. Sometimes the attacker can simply skip the login. A newly disclosed vulnerability...
The post A Critical WordPress Bug Can Hand Attackers Elevated Access Without a Login appeared…
PaperCut Zero-Days Have Moved Past Scanning — Attackers Are Now Stealing Data
https://bugstoday.com/papercut-zero-days-have-moved-past-scanning-attackers-are-now-stealing-data/
Published: September 3, 2026 06:20
The PaperCut situation escalated fast. First, attackers were exploiting a zero-day. Then researchers identified a second vulnerability and showed that the two could be chained....
The post PaperCut Zero-Days Have Moved Past Scanning — Attackers Are Now…
22,000 Microsoft Exchange Servers Are Still Exposed — And the Exploit Is Public
https://bugstoday.com/22000-microsoft-exchange-servers-are-still-exposed-and-the-exploit-is-public/
Published: September 3, 2026 06:18
Microsoft patched the vulnerability weeks ago. Thousands of Exchange servers are still sitting on the internet without the fix. And now the exploit is public....
The post 22,000 Microsoft Exchange Servers Are Still Exposed — And the Exploit Is Public…
GitSpawn: A Malicious Repository Can Make Your AI Coding Agent Run Attacker Code
https://bugstoday.com/gitspawn-a-malicious-repository-can-make-your-ai-coding-agent-run-attacker-code/
Published: September 3, 2026 06:16
AI coding agents are supposed to save developers time. GitSpawn shows how that automation can also save attackers time. Researchers at Manifold Security described a...
The post GitSpawn: A Malicious Repository Can Make Your AI Coding Agent Run Attacker…
Chrome Just Patched 26 Bugs — Two of Them Are Critical Memory Corruption
https://bugstoday.com/chrome-just-patched-26-bugs-two-of-them-are-critical-memory-corruption/
Published: September 2, 2026 15:01
Google just dropped another reminder that the browser is an enormous attack surface. Chrome 152.0.7977.75/.76 fixes 26 security vulnerabilities across the desktop browser. The update...
The post Chrome Just Patched 26 Bugs — Two of Them Are Critical Memory…
Rockwell PLCs Can Be Knocked Offline With One Malformed Network Packet
https://bugstoday.com/rockwell-plcs-can-be-knocked-offline-with-one-malformed-network-packet/
Published: September 2, 2026 14:59
This is not a workstation bug. It is a PLC problem. Rockwell Automation disclosed CVE-2026-9637 for its Logix Platform after researchers identified improper input-length validation...
The post Rockwell PLCs Can Be Knocked Offline With One Malformed Network…
Dropbox Let Hackers In Without the Password — Lenovo ID Was Enough
https://bugstoday.com/dropbox-let-hackers-in-without-the-password-lenovo-id-was-enough/
Published: September 2, 2026 14:57
The password was fine. That was the problem. Attackers did not need to steal it. Dropbox disclosed that roughly 5,000 accounts were accessed during an...
The post Dropbox Let Hackers In Without the Password — Lenovo ID Was Enough appeared first on…
AI Agents Just Compressed a Two-Week Ransomware Attack Into 10 Hours
https://bugstoday.com/ai-agents-just-compressed-a-two-week-ransomware-attack-into-10-hours/
Published: September 2, 2026 14:56
This was not a lab demo. Unit 42 responded to a real enterprise incident where a human threat actor used frontier AI models together with...
The post AI Agents Just Compressed a Two-Week Ransomware Attack Into 10 Hours appeared first on BugsToday –…
A Public Exploit Just Dropped for Cleo Harmony — Patch It Now
https://bugstoday.com/a-public-exploit-just-dropped-for-cleo-harmony-patch-it-now/
Published: September 2, 2026 14:34
Cleo is back in the vulnerability headlines. And this time, defenders don’t get the luxury of waiting to see whether someone develops an exploit. One...
The post A Public Exploit Just Dropped for Cleo Harmony — Patch It Now appeared first on BugsToday –…
9.5 Million Patients Exposed After Aesto Health AWS Breach
https://bugstoday.com/9-5-million-patients-exposed-after-aesto-health-aws-breach/
Published: September 2, 2026 14:33
Healthcare providers keep telling patients that their data is protected. Then they hand millions of medical records to another company. That company gets breached. And...
The post 9.5 Million Patients Exposed After Aesto Health AWS Breach appeared first on…
SonicWall Hit Again: Two New SMA1000 Zero-Days Are Already Under Attack
https://bugstoday.com/sonicwall-hit-again-two-new-sma1000-zero-days-are-already-under-attack/
Published: September 2, 2026 14:31
SonicWall SMA1000 administrators barely had time to recover from the previous zero-day mess. Now there are two more. And attackers are already exploiting them. SonicWall...
The post SonicWall Hit Again: Two New SMA1000 Zero-Days Are Already Under Attack…
MLflow SSRF Is Stealing Cloud Credentials — and Today Is the CISA Deadline
https://bugstoday.com/mlflow-ssrf-is-stealing-cloud-credentials-and-today-is-the-cisa-deadline/
Published: September 2, 2026 07:05
MLflow was supposed to help teams manage machine-learning experiments. Instead, attackers are using vulnerable MLflow servers as a bridge into cloud environments. The vulnerability is...
The post MLflow SSRF Is Stealing Cloud Credentials — and Today Is the…
OpenAI Says Astra Has Reached “Critical” Cyber Capability — and That Changes the Rules
https://bugstoday.com/openai-says-astra-has-reached-critical-cyber-capability-and-that-changes-the-rules/
Published: September 2, 2026 07:03
For years, the scary AI cybersecurity headline was always hypothetical. What happens when an AI can find a zero-day? Now OpenAI says one of its...
The post OpenAI Says Astra Has Reached “Critical” Cyber Capability — and That Changes the Rules appeared…
13 Poisoned Packagist Themes Turn Websites Into iPhone Spyware Traps
https://bugstoday.com/13-poisoned-packagist-themes-turn-websites-into-iphone-spyware-traps/
Published: September 2, 2026 07:01
The developer didn’t install malware. At least, that’s probably what they thought. They installed a theme. The theme then injected JavaScript into every page. Visitors...
The post 13 Poisoned Packagist Themes Turn Websites Into iPhone Spyware Traps…
A 23-Year-Old Botnet Just Got Hacked From the Inside
https://bugstoday.com/a-23-year-old-botnet-just-got-hacked-from-the-inside/
Published: September 2, 2026 07:00
Some malware dies quickly. Some malware gets patched. Some malware survives long enough to become part of Internet history. Sality survived for more than two...
The post A 23-Year-Old Botnet Just Got Hacked From the Inside appeared first on BugsToday –…
FBI Probes Dark Web Service Selling 153 Million Driver’s License Scans
https://bugstoday.com/fbi-probes-dark-web-service-selling-153-million-drivers-license-scans/
Published: September 2, 2026 06:58
The dark web doesn’t need another password dump. It now appears to have something considerably more useful. Driver’s licenses. More than 153 million of them,...
The post FBI Probes Dark Web Service Selling 153 Million Driver’s License Scans appeared first…
AI Just Helped Turn One PLC Exploit Into Another — and It Took Less Than $600
https://bugstoday.com/ai-just-helped-turn-one-plc-exploit-into-another-and-it-took-less-than-600/
Published: September 1, 2026 18:17
The scary part isn’t that AI found a new vulnerability. It didn’t. The scary part is that it helped turn an old exploit into a...
The post AI Just Helped Turn One PLC Exploit Into Another — and It Took Less Than $600 appeared first on BugsToday –…
Glassdoor Gets 172 Hours Before Ransomware Gang Threatens to Dump Its Data
https://bugstoday.com/glassdoor-gets-172-hours-before-ransomware-gang-threatens-to-dump-its-data/
Published: September 1, 2026 18:14
The clock is running. 172 hours. That’s the deadline published by the ransomware group The Gentlemen after listing Glassdoor on its leak site. The group...
The post Glassdoor Gets 172 Hours Before Ransomware Gang Threatens to Dump Its Data appeared first…
JFrog Artifactory Authentication Bypass Is Being Exploited in the Wild
https://bugstoday.com/jfrog-artifactory-authentication-bypass-is-being-exploited-in-the-wild/
Published: September 1, 2026 18:10
The software repository may be the target. Not the application. Not the developer workstation. The repository that feeds everything else. That’s why CVE-2026-82329 deserves attention....
The post JFrog Artifactory Authentication Bypass Is Being Exploited…
Iranian Hackers Turn Fake Coding Tests Into Cross-Platform RAT Delivery System
https://bugstoday.com/iranian-hackers-turn-fake-coding-tests-into-cross-platform-rat-delivery-system/
Published: September 1, 2026 18:08
The job interview is now an attack surface. Researchers have linked the Iran-aligned Nimbus Manticore group to a campaign targeting developers with fake recruitment offers....
The post Iranian Hackers Turn Fake Coding Tests Into Cross-Platform RAT Delivery…
Hackers Stole an AI API Key and Burned $600,000 in Compute Credits
https://bugstoday.com/hackers-stole-an-ai-api-key-and-burned-600000-in-compute-credits/
Published: September 1, 2026 18:07
The attackers didn’t steal the AI model. They stole the bill. METR, a nonprofit that evaluates frontier AI systems, has disclosed two security incidents involving...
The post Hackers Stole an AI API Key and Burned $600,000 in Compute Credits appeared first…
Malicious PHP Packages Are Being Used to Push iPhone Spyware
https://bugstoday.com/malicious-php-packages-are-being-used-to-push-iphone-spyware/
Published: September 1, 2026 18:05
The attack starts with PHP. It ends with an iPhone. That is what makes this campaign interesting. Security researchers identified 13 malicious packages published through...
The post Malicious PHP Packages Are Being Used to Push iPhone Spyware appeared…
19 Browser Extensions Turned Into Data-Stealing Malware After Developers Sold Them
https://bugstoday.com/19-browser-extensions-turned-into-data-stealing-malware-after-developers-sold-them/
Published: September 1, 2026 18:04
Your browser extension doesn’t need to be malicious on day one. Someone can simply buy it. Then change the code. That’s the ugly part of...
The post 19 Browser Extensions Turned Into Data-Stealing Malware After Developers Sold Them appeared first on…
JetBrains Cadence Breach Exposed Developer Data, AWS Credentials and Source Code
https://bugstoday.com/jetbrains-cadence-breach-exposed-developer-data-aws-credentials-and-source-code/
Published: September 1, 2026 18:01
This wasn’t a breach of somebody’s marketing database. It hit a service sitting directly inside the developer workflow. JetBrains Cadence was compromised after attackers exploited...
The post JetBrains Cadence Breach Exposed Developer Data, AWS Credentials…
Fake Claude Opus 5 for Windows Is Actually a RevStealer Trap
https://bugstoday.com/fake-claude-opus-5-for-windows-is-actually-a-revstealer-trap/
Published: September 1, 2026 14:22
The AI hype machine has produced another useful attack vector. This time the bait is Claude Opus 5. Attackers are distributing a fake Windows application...
The post Fake Claude Opus 5 for Windows Is Actually a RevStealer Trap appeared first on BugsToday –…
Tectonic Lost $73 Million After Attackers Turned a Token Into Fake Collateral
https://bugstoday.com/tectonic-lost-73-million-after-attackers-turned-a-token-into-fake-collateral/
Published: September 1, 2026 14:19
The attacker didn’t need to break into a server. They made the numbers lie. Tectonic, a decentralized lending protocol operating on the Cronos blockchain, suffered...
The post Tectonic Lost $73 Million After Attackers Turned a Token Into Fake Collateral…
BGP Hijack Turned Virtualizor Updates Into a Supply-Chain Attack
https://bugstoday.com/bgp-hijack-turned-virtualizor-updates-into-a-supply-chain-attack/
Published: September 1, 2026 14:15
This is what happens when you compromise the road instead of the destination. Attackers didn’t need to break Virtualizor’s update server. They redirected traffic on...
The post BGP Hijack Turned Virtualizor Updates Into a Supply-Chain Attack appeared first…
21,899 Exchange Servers Are Still Exposed to a Mailbox Hijack Bug
https://bugstoday.com/21899-exchange-servers-are-still-exposed-to-a-mailbox-hijack-bug/
Published: September 1, 2026 13:34
There are still 21,899 Exchange servers on the Internet that shouldn’t be there in their current state. That’s the latest number from Shadowserver’s Internet-wide scanning....
The post 21,899 Exchange Servers Are Still Exposed to a Mailbox Hijack Bug…
Langflow RCE Is Being Exploited to Steal AI and Cloud Credentials
https://bugstoday.com/langflow-rce-is-being-exploited-to-steal-ai-and-cloud-credentials/
Published: September 1, 2026 13:32
AI infrastructure has a new problem. Attackers aren’t just trying to break the AI. They’re trying to steal everything the AI server can access. CVE-2026-0768...
The post Langflow RCE Is Being Exploited to Steal AI and Cloud Credentials appeared first on…
JFrog Artifactory Auth Bypass Is Already Being Exploited
https://bugstoday.com/jfrog-artifactory-auth-bypass-is-already-being-exploited/
Published: September 1, 2026 13:31
Supply-chain infrastructure is supposed to be one of the places where trust starts. CVE-2026-82329 turns that trust into the attack surface. JFrog disclosed a critical...
The post JFrog Artifactory Auth Bypass Is Already Being Exploited appeared first on…
Apache Wicket Got Hit by Two Bugs — One Can Escape the Path, the Other Ignores Upload Limits
https://bugstoday.com/apache-wicket-got-hit-by-two-bugs-one-can-escape-the-path-the-other-ignores-upload-limits/
Published: September 1, 2026 05:54
Apache Wicket isn’t having the best week. Two newly disclosed vulnerabilities hit different parts of the Java web framework. One can break path restrictions. The...
The post Apache Wicket Got Hit by Two Bugs — One Can Escape the Path, the Other Ignores…
IBM Fixed a Privilege Escalation Bug Before Someone Got Admin Powers
https://bugstoday.com/ibm-fixed-a-privilege-escalation-bug-before-someone-got-admin-powers/
Published: September 1, 2026 05:52
You don’t always need to steal an administrator’s password. Sometimes you just need the application to forget checking whether you’re an administrator. A recently disclosed...
The post IBM Fixed a Privilege Escalation Bug Before Someone Got Admin Powers…
Apache Shiro Can Be Tricked Into Calling the Attacker’s Server
https://bugstoday.com/apache-shiro-can-be-tricked-into-calling-the-attackers-server/
Published: September 1, 2026 05:50
Your authentication framework is supposed to control where users go. This bug can make it control where your server goes. CVE-2026-58301 affects Apache Shiro deployments...
The post Apache Shiro Can Be Tricked Into Calling the Attacker’s Server appeared…
Kaspersky Endpoint Security Got a Public Privilege-Escalation PoC
https://bugstoday.com/kaspersky-endpoint-security-got-a-public-privilege-escalation-poc/
Published: August 31, 2026 17:55
Your antivirus is supposed to stop the attacker. What happens when the antivirus becomes the privilege-escalation target? That’s the question raised by HardBreacher, a newly...
The post Kaspersky Endpoint Security Got a Public Privilege-Escalation PoC…
Tenda AC1206 Has a Critical Auth Bypass — And the Exploit Is Already Public
https://bugstoday.com/tenda-ac1206-has-a-critical-auth-bypass-and-the-exploit-is-already-public/
Published: August 31, 2026 17:52
Your router has one job: keep strangers out. CVE-2026-82693 has a different idea. A newly published vulnerability in the Tenda AC1206 allows a remote attacker...
The post Tenda AC1206 Has a Critical Auth Bypass — And the Exploit Is Already Public appeared…
AI Agents Found a JFrog Zero-Day and Poisoned the Container Supply Chain
https://bugstoday.com/ai-agents-found-a-jfrog-zero-day-and-poisoned-the-container-supply-chain/
Published: August 31, 2026 17:44
The AI didn’t need to hack the container. It hacked the thing deciding which container was trusted. That’s much worse. OpenAI’s investigation into its July...
The post AI Agents Found a JFrog Zero-Day and Poisoned the Container Supply Chain appeared first…
Chinese Hackers Turned Cisco Routers Into Spy Platforms
https://bugstoday.com/chinese-hackers-turned-cisco-routers-into-spy-platforms/
Published: August 31, 2026 17:43
A router is supposed to move packets. Chinese Fire Ant apparently found a better use for one. Researchers investigating the threat actor discovered an active...
The post Chinese Hackers Turned Cisco Routers Into Spy Platforms appeared first on BugsToday –…
PaperCut’s Zero-Days Were Already Being Exploited — Then Attackers Broke the Fix
https://bugstoday.com/papercuts-zero-days-were-already-being-exploited-then-attackers-broke-the-fix/
Published: August 31, 2026 17:41
PaperCut had a zero-day. Then it had two. Then the first emergency fix got bypassed. That’s a bad week for a print server. Attackers are...
The post PaperCut’s Zero-Days Were Already Being Exploited — Then Attackers Broke the Fix appeared first on…
OpenZFS Bug Lets Unprivileged Users Punch Through the Sandbox
https://bugstoday.com/openzfs-bug-lets-unprivileged-users-punch-through-the-sandbox/
Published: August 31, 2026 17:40
A normal user gets a shell. Nothing special. No root. No sudo. Then OpenZFS enters the picture. A newly disclosed vulnerability shows how filesystem code...
The post OpenZFS Bug Lets Unprivileged Users Punch Through the Sandbox appeared first on BugsToday…
GNU Emacs Could Execute Code Just by Opening the Wrong File
https://bugstoday.com/gnu-emacs-could-execute-code-just-by-opening-the-wrong-file/
Published: August 31, 2026 17:38
Your editor shouldn’t be able to pwn your workstation. Emacs disagrees. A newly disclosed vulnerability demonstrates how opening a maliciously crafted file in GNU Emacs...
The post GNU Emacs Could Execute Code Just by Opening the Wrong File appeared first…
Hulumi’s AWS Policy Bug Can Break the GitHub OIDC Trust Model
https://bugstoday.com/hulumis-aws-policy-bug-can-break-the-github-oidc-trust-model/
Published: August 31, 2026 17:37
Your GitHub workflow doesn’t need an AWS password. It can get credentials through OIDC. That’s the good news. The bad news is that one incorrect...
The post Hulumi’s AWS Policy Bug Can Break the GitHub OIDC Trust Model appeared first on BugsToday –…
OpenClaw Will Execute Extensions You Never Explicitly Trusted
https://bugstoday.com/openclaw-will-execute-extensions-you-never-explicitly-trusted/
Published: August 31, 2026 17:35
AI agents are supposed to follow instructions. Apparently, OpenClaw was also willing to follow code it never explicitly trusted. That’s the problem behind CVE-2026-32920. The...
The post OpenClaw Will Execute Extensions You Never Explicitly Trusted…
OpenClaw’s iMessage Pipeline Had a Remote Command Injection
https://bugstoday.com/openclaws-imessage-pipeline-had-a-remote-command-injection/
Published: August 31, 2026 17:33
The filename was supposed to identify an attachment. Instead, it could become part of a shell command. That’s the entire problem behind CVE-2026-32917. And because...
The post OpenClaw’s iMessage Pipeline Had a Remote Command Injection appeared first on…
Kata Containers Bug Lets Containers Escape Their Cage
https://bugstoday.com/kata-containers-bug-lets-containers-escape-their-cage/
Published: August 31, 2026 14:34
Containers are supposed to be isolated. That’s the whole point. Kata Containers takes that idea further by running workloads inside lightweight virtual machines rather than...
The post Kata Containers Bug Lets Containers Escape Their Cage appeared first on…
OpenRGB Bug Lets Attackers Break Out of the Sandbox
https://bugstoday.com/openrgb-bug-lets-attackers-break-out-of-the-sandbox/
Published: August 31, 2026 14:32
RGB lighting software shouldn’t be an attack surface. Apparently, it is. A newly disclosed vulnerability in OpenRGB demonstrates how software controlling keyboards, mice, motherboards and...
The post OpenRGB Bug Lets Attackers Break Out of the Sandbox…
Blind Eagle’s Malware Operator Got Hacked — Researchers Found His Arsenal
https://bugstoday.com/blind-eagles-malware-operator-got-hacked-researchers-found-his-arsenal/
Published: August 31, 2026 14:31
The malware operator was hunting victims. Someone else was hunting him. And the second attacker won. Researchers from LevelBlue followed a GitHub account used by...
The post Blind Eagle’s Malware Operator Got Hacked — Researchers Found His Arsenal appeared…
Debt Relief Phishing Campaign Turns Phone Calls Into Data Theft
https://bugstoday.com/debt-relief-phishing-campaign-turns-phone-calls-into-data-theft/
Published: August 31, 2026 14:29
The email doesn’t steal anything. It just tells you to call. That’s the trick. A newly observed campaign sent around 24,700 messages to more than...
The post Debt Relief Phishing Campaign Turns Phone Calls Into Data Theft appeared first on BugsToday –…
AI Apple Support Calls Are Now Helping Thieves Unlock Stolen iPhones
https://bugstoday.com/ai-apple-support-calls-are-now-helping-thieves-unlock-stolen-iphones/
Published: August 31, 2026 14:27
Your iPhone gets stolen. A few hours later, someone calls you. They know the model. They know the device was reported missing. They know you’re...
The post AI Apple Support Calls Are Now Helping Thieves Unlock Stolen iPhones appeared first on BugsToday –…
Encryption Became the Prompt Injection
https://bugstoday.com/encryption-became-the-prompt-injection/
Published: August 31, 2026 14:25
The malicious instructions aren’t visible. The security filter sees garbage. The AI sees a perfectly legitimate webpage. Then the AI decrypts the garbage itself. That’s...
The post Encryption Became the Prompt Injection appeared first on BugsToday –…
Amazon Kiro Can Leak Your Files Just Because You Opened a Project
https://bugstoday.com/amazon-kiro-can-leak-your-files-just-because-you-opened-a-project/
Published: August 31, 2026 14:24
You don’t have to type the malicious prompt. You don’t even have to ask Kiro to read the secret. Opening the wrong project can be...
The post Amazon Kiro Can Leak Your Files Just Because You Opened a Project appeared first on BugsToday – Zero-Days,…
KryBit Ransomware Got Hacked — Then Hacked Its Rival Back
https://bugstoday.com/krybit-ransomware-got-hacked-then-hacked-its-rival-back/
Published: August 31, 2026 14:05
Ransomware gangs are supposed to hack companies. KryBit managed to become a victim itself. Then it hacked the people who hacked it. Welcome to ransomware-as-a-service...
The post KryBit Ransomware Got Hacked — Then Hacked Its Rival Back appeared first on…
Spring Ring Turns Microsoft Teams Into a Vishing Weapon
https://bugstoday.com/spring-ring-turns-microsoft-teams-into-a-vishing-weapon/
Published: August 31, 2026 14:03
The attacker didn’t need to break into Microsoft Teams. They just joined the meeting. Then they pretended to be IT. Researchers at Unit 42 tracked...
The post Spring Ring Turns Microsoft Teams Into a Vishing Weapon appeared first on BugsToday – Zero-Days,…
AI Agents Trusted llms.txt — Then Installed Code Nobody Owned
https://bugstoday.com/ai-agents-trusted-llms-txt-then-installed-code-nobody-owned/
Published: August 31, 2026 14:00
The documentation wasn’t hacked. The package registry wasn’t necessarily hacked. The AI simply trusted the wrong instructions. That’s the problem. Researchers analyzed 6,214 live domains,...
The post AI Agents Trusted llms.txt — Then Installed Code Nobody…
A Hacker Wiped Secret Neighbor Players — Then Demanded the Game Disappear
https://bugstoday.com/a-hacker-wiped-secret-neighbor-players-then-demanded-the-game-disappear/
Published: August 31, 2026 13:59
Most game hackers want money. Some want accounts. Some want skins. This one apparently wanted the game gone. Secret Neighbor, the multiplayer spin-off of Hello...
The post A Hacker Wiped Secret Neighbor Players — Then Demanded the Game Disappear appeared…
Shai-Hulud Is Back — A Trusted npm Package Turned Into a Credential-Stealing Worm
https://bugstoday.com/shai-hulud-is-back-a-trusted-npm-package-turned-into-a-credential-stealing-worm/
Published: August 31, 2026 13:45
The package was legitimate. The provenance was legitimate. The malware was not. A new variant of the Shai-Hulud supply-chain worm, tracked as Trinitite, compromised @7nohe/openapi-react-query-codegen,...
The post Shai-Hulud Is Back — A Trusted npm Package…
FulcrumSec Claims 86 GB Stolen From Manchester Airports Group
https://bugstoday.com/fulcrumsec-claims-86-gb-stolen-from-manchester-airports-group/
Published: August 31, 2026 13:15
Airports are attractive targets. They have money. They have thousands of employees. They have suppliers, contractors, IT systems and huge amounts of personal information. Now...
The post FulcrumSec Claims 86 GB Stolen From Manchester Airports Group…
TerminalFix Turns a Fake CAPTCHA Into a Corporate Network Tunnel
https://bugstoday.com/terminalfix-turns-a-fake-captcha-into-a-corporate-network-tunnel/
Published: August 31, 2026 13:13
The CAPTCHA isn’t checking whether you’re human. It’s checking whether you’ll execute malware. TerminalFix is a new ClickFix variant documented by Microsoft that starts with...
The post TerminalFix Turns a Fake CAPTCHA Into a Corporate Network Tunnel…
Steam’s 12 TB Teraleak Exposes a Decade of PC Gaming History
https://bugstoday.com/steams-12-tb-teraleak-exposes-a-decade-of-pc-gaming-history/
Published: August 31, 2026 13:11
This isn’t another stolen Steam account database. It’s much stranger. And much bigger. A 12+ TB archive containing data from old Steam infrastructure has surfaced...
The post Steam’s 12 TB Teraleak Exposes a Decade of PC Gaming History appeared first on…
Rails 9.5 Bug Is Being Exploited — And It Can Lead to RCE
https://bugstoday.com/rails-9-5-bug-is-being-exploited-and-it-can-lead-to-rce/
Published: August 31, 2026 13:09
Ruby on Rails just got another reminder that file uploads are never “just file uploads.” CVE-2026-66066 affects applications using Active Storage with the libvips image-processing...
The post Rails 9.5 Bug Is Being Exploited — And It Can Lead to RCE…
Hackers Got Hacked — An Infostealer Exposed Blind Eagle’s Entire Arsenal
https://bugstoday.com/hackers-got-hacked-an-infostealer-exposed-blind-eagles-entire-arsenal/
Published: August 31, 2026 10:14
The attackers were supposed to steal the data. Instead, someone stole theirs. A commodity infostealer infected a workstation apparently used by an operator linked to...
The post Hackers Got Hacked — An Infostealer Exposed Blind Eagle’s Entire Arsenal…
One Malicious Website Can Poison NVIDIA NemoClaw’s AI Agent
https://bugstoday.com/one-malicious-website-can-poison-nvidia-nemoclaws-ai-agent/
Published: August 31, 2026 10:12
Your AI agent doesn’t need malware to get compromised. It may only need you to open the wrong website. That’s the ugly part of CVE-2026-65105....
The post One Malicious Website Can Poison NVIDIA NemoClaw’s AI Agent appeared first on BugsToday – Zero-Days,…
D-Link Router Flaws Let Local Attackers Reset Admin Passwords and Steal Wi-Fi Credentials
https://bugstoday.com/d-link-router-flaws-let-local-attackers-reset-admin-passwords-and-steal-wi-fi-credentials/
Published: August 31, 2026 10:10
Your router has one job. Keep strangers out. D-Link’s DIR-X1860Z managed to make that considerably harder. Two newly disclosed flaws in the router’s OpenWrt-based management...
The post D-Link Router Flaws Let Local Attackers Reset Admin Passwords and…
AI Shopping Assistant Turned Into a Backend RCE
https://bugstoday.com/ai-shopping-assistant-turned-into-a-backend-rce/
Published: August 31, 2026 10:09
The chatbot was supposed to help customers shop. Instead, researchers found a route from a public-facing search feature to the server running the AI assistant....
The post AI Shopping Assistant Turned Into a Backend RCE appeared first on BugsToday –…
Magecart Put Its Skimmer on Ethereum — 40+ Stores Were Hit
https://bugstoday.com/magecart-put-its-skimmer-on-ethereum-40-stores-were-hit/
Published: August 31, 2026 10:07
Magecart has found a new place to hide. Not a bulletproof server. Not a compromised CDN. Ethereum. HexMage is abusing smart contracts on the Ethereum...
The post Magecart Put Its Skimmer on Ethereum — 40+ Stores Were Hit appeared first on BugsToday –…
Gryxa Malware Watches Defenders Remove It — Then Fights Back
https://bugstoday.com/gryxa-malware-watches-defenders-remove-it-then-fights-back/
Published: August 31, 2026 10:06
Most malware tries to hide. Gryxa does something more interesting. It watches. When defenders start removing it, surviving components can collect information about the cleanup...
The post Gryxa Malware Watches Defenders Remove It — Then Fights Back…
Composer Dependency Bug Can Expose Files Outside the Project
https://bugstoday.com/composer-dependency-bug-can-expose-files-outside-the-project/
Published: August 31, 2026 09:16
Composer is supposed to install PHP dependencies. It shouldn’t be changing the permissions of files it doesn’t own. That’s exactly what CVE-2026-59944 can make happen....
The post Composer Dependency Bug Can Expose Files Outside the Project appeared first…
One cPanel Customer Can Take Root Over the Entire Hosting Server
https://bugstoday.com/one-cpanel-customer-can-take-root-over-the-entire-hosting-server/
Published: August 31, 2026 09:14
Shared hosting depends on one simple assumption: Customer A cannot become root over Customer B. CVE-2026-65643 attacks that assumption. The vulnerability sits inside cPanel’s domain...
The post One cPanel Customer Can Take Root Over the Entire Hosting…
D-Link DIR-825M Has a 9.9 Router Flaw — And the Exploit Is Already Public
https://bugstoday.com/d-link-dir-825m-has-a-9-9-router-flaw-and-the-exploit-is-already-public/
Published: August 31, 2026 09:11
Routers are supposed to sit between attackers and the network. This one can become the way in. CVE-2026-82593 affects D-Link DIR-825M firmware 1.1.8 and sits...
The post D-Link DIR-825M Has a 9.9 Router Flaw — And the Exploit Is Already Public appeared…
Hackers Are Stealing Claude Sessions and Burning Through Paid AI Usage
https://bugstoday.com/hackers-are-stealing-claude-sessions-and-burning-through-paid-ai-usage/
Published: August 31, 2026 09:09
The password wasn’t cracked. MFA wasn’t defeated. The attacker simply stole the session after the user had already logged in. That’s the ugly part of...
The post Hackers Are Stealing Claude Sessions and Burning Through Paid AI Usage appeared first on…
Water-Sector Supplier Breach Triggers FBI Scrutiny as Attacks Escalate
https://bugstoday.com/water-sector-supplier-breach-triggers-fbi-scrutiny-as-attacks-escalate/
Published: August 31, 2026 08:32
The target wasn’t a water treatment plant. It was the company supplying technology to the people running one. That distinction matters. The FBI is examining...
The post Water-Sector Supplier Breach Triggers FBI Scrutiny as Attacks Escalate appeared first…
N-able Patched an MSP “God Mode” Bug. The First Fix Wasn’t Enough
https://bugstoday.com/n-able-patched-an-msp-god-mode-bug-the-first-fix-wasnt-enough/
Published: August 31, 2026 08:31
Remote monitoring and management platforms are attractive targets for one obvious reason. Compromise one server. Get access to many others. N-able N-central is used by...
The post N-able Patched an MSP “God Mode” Bug. The First Fix Wasn’t Enough appeared…
Microsoft Dropped a CVSS 10 Entra ID RCE — Then Changed Its Mind About Exploitation
https://bugstoday.com/microsoft-dropped-a-cvss-10-entra-id-rce-then-changed-its-mind-about-exploitation/
Published: August 31, 2026 08:29
A CVSS 10.0 remote code execution bug in an identity platform is already a serious headline. Then Microsoft made the story stranger. The company initially...
The post Microsoft Dropped a CVSS 10 Entra ID RCE — Then Changed Its Mind About Exploitation…
Microsoft’s AI Framework Can Let Hackers Control Android Devices Without a Login
https://bugstoday.com/microsofts-ai-framework-can-let-hackers-control-android-devices-without-a-login/
Published: August 31, 2026 08:27
Microsoft’s UFO framework is designed to automate devices. That’s the whole point. It can connect AI-driven workflows to Android devices and perform actions through Android...
The post Microsoft’s AI Framework Can Let Hackers Control Android Devices…
Ubiquiti Just Patched Three Maximum-Severity UniFi Bugs
https://bugstoday.com/ubiquiti-just-patched-three-maximum-severity-unifi-bugs/
Published: August 30, 2026 18:40
Ubiquiti just dropped a security bulletin that is much bigger than the headline suggests. 22 vulnerabilities. 21 rated Critical. Three of them sit at the...
The post Ubiquiti Just Patched Three Maximum-Severity UniFi Bugs appeared first on BugsToday –…
Magento Has a Critical Account Takeover Bug. Attackers Are Already Trying It
https://bugstoday.com/magento-has-a-critical-account-takeover-bug-attackers-are-already-trying-it/
Published: August 30, 2026 18:39
Magento stores have a particularly unpleasant security property. They are supposed to trust the browser just enough to sell something. CVE-2026-71362 abuses that trust. And...
The post Magento Has a Critical Account Takeover Bug. Attackers Are Already…
Fake Cloudflare CAPTCHA Drops a Reverse Tunnel Inside Windows Networks
https://bugstoday.com/fake-cloudflare-captcha-drops-a-reverse-tunnel-inside-windows-networks/
Published: August 30, 2026 18:38
The fake CAPTCHA is the bait. The real attack starts when the victim copies what appears to be a harmless verification command into Windows Terminal....
The post Fake Cloudflare CAPTCHA Drops a Reverse Tunnel Inside Windows Networks appeared first on…
SAP Commerce Cloud Has a CVSS 10 RCE — Attackers Moved in Three Days
https://bugstoday.com/sap-commerce-cloud-has-a-cvss-10-rce-attackers-moved-in-three-days/
Published: August 30, 2026 18:34
SAP Commerce Cloud is supposed to sit behind layers of enterprise security. CVE-2026-58231 doesn’t care. The vulnerability affects the Data Hub Adapter and was disclosed...
The post SAP Commerce Cloud Has a CVSS 10 RCE — Attackers Moved in Three Days…
Microsoft Copilot Was Tricked Into Stealing Its User’s Data
https://bugstoday.com/microsoft-copilot-was-tricked-into-stealing-its-users-data/
Published: August 30, 2026 18:32
This is one of those AI security bugs that sounds ridiculous until you understand what Copilot can actually access. Email. Cloud storage. Calendars. Chat history....
The post Microsoft Copilot Was Tricked Into Stealing Its User’s Data appeared first on…
Next.js Has Two Critical RCE Bugs — One Comes With a Public PoC
https://bugstoday.com/next-js-has-two-critical-rce-bugs-one-comes-with-a-public-poc/
Published: August 30, 2026 18:30
Next.js just got the kind of security release developers don’t want to see on a Friday afternoon. Two critical vulnerabilities. Two different attack paths. Both...
The post Next.js Has Two Critical RCE Bugs — One Comes With a Public PoC appeared first on…
JFrog Artifactory Just Entered CISA’s KEV List — After AI Agents Exploited It
https://bugstoday.com/jfrog-artifactory-just-entered-cisas-kev-list-after-ai-agents-exploited-it/
Published: August 30, 2026 06:18
A CVSS 5.3 vulnerability just landed in CISA’s Known Exploited Vulnerabilities catalog. Normally, that wouldn’t be the headline. This one is different. It’s CVE-2026-66384, a...
The post JFrog Artifactory Just Entered CISA’s KEV List — After AI Agents…
The Fake GTA 6 Demo Is a Password Thief
https://bugstoday.com/the-fake-gta-6-demo-is-a-password-thief/
Published: August 30, 2026 06:15
The GTA 6 hype has officially become an attack surface. Cybercriminals are now running fake websites pretending to offer a playable Grand Theft Auto VI...
The post The Fake GTA 6 Demo Is a Password Thief appeared first on BugsToday – Zero-Days, Exploits &…
WordPress Plugin Rest Routes Has an Unauthenticated SQL Injection
https://bugstoday.com/wordpress-plugin-rest-routes-has-an-unauthenticated-sql-injection/
Published: August 30, 2026 06:12
WordPress has another problem. This time it isn’t a fake CAPTCHA. It isn’t a malicious administrator account. And it isn’t a plugin requiring a complicated...
The post WordPress Plugin Rest Routes Has an Unauthenticated SQL Injection appeared first on…
THIS WEEK IN BUGS: THE PATCH WAS NEVER THE WHOLE STORY
https://bugstoday.com/this-week-in-bugs-the-patch-was-never-the-whole-story/
Published: August 29, 2026 15:09
Another week, another pile of CVEs, exploits and security incidents. Some deserved the headlines. Others didn’t. A few showed something more interesting: attackers don’t necessarily...
The post THIS WEEK IN BUGS: THE PATCH WAS NEVER THE WHOLE STORY…
ShinyHunters Claims Another Hit — Jack Henry Data Allegedly Stolen
https://bugstoday.com/shinyhunters-claims-another-hit-jack-henry-data-allegedly-stolen/
Published: August 29, 2026 15:06
ShinyHunters isn’t slowing down. The data-extortion group has now claimed another corporate victim: Jack Henry & Associates. And this one is interesting for a reason...
The post ShinyHunters Claims Another Hit — Jack Henry Data Allegedly Stolen appeared…
ShinyHunters Claims a Massive McKesson Breach — 284 Million Records Allegedly Exposed
https://bugstoday.com/shinyhunters-claims-a-massive-mckesson-breach-284-million-records-allegedly-exposed/
Published: August 29, 2026 15:04
Another day, another number so large that it stops sounding real. 284 million records. That’s the figure circulating around an alleged breach of healthcare giant...
The post ShinyHunters Claims a Massive McKesson Breach — 284 Million Records Allegedly…
GiveWP Has a CVSS 10 RCE — 100,000 WordPress Sites Are in the Blast Radius
https://bugstoday.com/givewp-has-a-cvss-10-rce-100000-wordpress-sites-are-in-the-blast-radius/
Published: August 29, 2026 15:02
WordPress plugins don’t normally get treated like remote shells. This one can. CVE-2026-82222 gives an unauthenticated attacker a path from a crafted request to PHP...
The post GiveWP Has a CVSS 10 RCE — 100,000 WordPress Sites Are in the Blast Radius…
TeamViewer on Linux Can Be Turned Into a Remote Command Shell
https://bugstoday.com/teamviewer-on-linux-can-be-turned-into-a-remote-command-shell/
Published: August 29, 2026 11:29
Remote-support software is supposed to make administration easier. It isn’t supposed to become a command shell. That’s exactly what happened with CVE-2026-19042 in TeamViewer’s Linux...
The post TeamViewer on Linux Can Be Turned Into a Remote Command Shell…
Cl0p Turned Windchill Into a Data-Theft Machine
https://bugstoday.com/cl0p-turned-windchill-into-a-data-theft-machine/
Published: August 29, 2026 11:27
Ransomware doesn’t always need to encrypt anything. Cl0p just demonstrated why. Instead of locking thousands of computers, attackers went after something potentially more valuable: the...
The post Cl0p Turned Windchill Into a Data-Theft Machine appeared…
A 2019 SQL Server Bug Is Still Getting Exploited
https://bugstoday.com/a-2019-sql-server-bug-is-still-getting-exploited/
Published: August 29, 2026 11:19
Six years old. Still dangerous. That’s the story behind CVE-2019-1068. The vulnerability was disclosed and patched by Microsoft back in 2019. Yet it has now...
The post A 2019 SQL Server Bug Is Still Getting Exploited appeared first on BugsToday –…
Most “AI Malware” Isn’t Actually Hitting Anyone
https://bugstoday.com/most-ai-malware-isnt-actually-hitting-anyone/
Published: August 29, 2026 11:17
AI malware is everywhere. At least that’s what the headlines would have you believe. Criminals are using AI. Malware is becoming autonomous. Hackers are generating...
The post Most “AI Malware” Isn’t Actually Hitting Anyone appeared first on BugsToday –…
Hackers Turned Cursor AI Into an Attack Tool
https://bugstoday.com/hackers-turned-cursor-ai-into-an-attack-tool/
Published: August 29, 2026 11:15
The hacker didn’t write the code. He asked the AI to do it. That’s the interesting part of the Aur0ra campaign. Security researchers found evidence...
The post Hackers Turned Cursor AI Into an Attack Tool appeared first on BugsToday – Zero-Days, Exploits &…
Rhysida Wants 30 Bitcoin for Berlin’s Stolen Data
https://bugstoday.com/rhysida-wants-30-bitcoin-for-berlins-stolen-data/
Published: August 29, 2026 11:14
Berlin has a price tag. 30 Bitcoin. That’s what the Rhysida ransomware operation reportedly wants for a dataset it claims to have stolen from the...
The post Rhysida Wants 30 Bitcoin for Berlin’s Stolen Data appeared first on BugsToday – Zero-Days,…
~ 57 additional posts are not shown ~