RSS Parrot

BETA

🦜 BugsToday – Zero-Days, Exploits & Vulnerabilities

@bugstoday.com@rss-parrot.net

I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline! Brought to you by the RSS Parrot.

---

Today's Bugs. Tomorrow's Breaches.

Your feed and you don't want it here? Just e-mail the birb.

Site URL: bugstoday.com/

Feed URL: bugstoday.com/feed

Posts: 157

Followers: 1

Attackers Are Hitting GitLab’s Critical GraphQL Bug Without Logging In

Published: September 3, 2026 13:21

GitLab’s GraphQL API just became a very bad place to leave unpatched. CVE-2026-19478 is a critical code injection vulnerability affecting self-managed GitLab Community Edition and... The post Attackers Are Hitting GitLab’s Critical GraphQL Bug Without…

A Critical VMware Bug Can Let Code Escape the VM and Reach the Host

Published: September 3, 2026 12:55

Virtual machines exist for a reason. Run something dangerous inside the guest. Keep the host safe. Broadcom has now disclosed vulnerabilities that can attack exactly... The post A Critical VMware Bug Can Let Code Escape the VM and Reach the Host appeared…

Pegasus Just Infected an iPhone Without the User Touching It

Published: September 3, 2026 10:13

You don’t need to click anything. You don’t need to open a suspicious attachment. You don’t even need to know an attack is happening. That’s... The post Pegasus Just Infected an iPhone Without the User Touching It appeared first on BugsToday – Zero-Days,…

AI Infrastructure Is Being Hacked for Keys, Shells and Crypto Mining

Published: September 3, 2026 10:09

AI infrastructure has officially become an attack surface worth stealing. Not because attackers suddenly care about chatbots. They care about everything sitting behind them. Microsoft... The post AI Infrastructure Is Being Hacked for Keys, Shells and…

CrowdStrike Falcon Has a New 0-Day Problem. The PoC Is Already Public

Published: September 3, 2026 10:06

The irony is almost too clean. CrowdStrike Falcon exists to stop attackers from doing exactly this. FalconFlank allegedly abuses one of the platform’s defensive mechanisms... The post CrowdStrike Falcon Has a New 0-Day Problem. The PoC Is Already Public…

Chrome Just Patched 26 Bugs — Two of Them Are Critical Memory Corruption

Published: September 2, 2026 15:01

Google just dropped another reminder that the browser is an enormous attack surface. Chrome 152.0.7977.75/.76 fixes 26 security vulnerabilities across the desktop browser. The update... The post Chrome Just Patched 26 Bugs — Two of Them Are Critical Memory…

Rockwell PLCs Can Be Knocked Offline With One Malformed Network Packet

Published: September 2, 2026 14:59

This is not a workstation bug. It is a PLC problem. Rockwell Automation disclosed CVE-2026-9637 for its Logix Platform after researchers identified improper input-length validation... The post Rockwell PLCs Can Be Knocked Offline With One Malformed Network…

Dropbox Let Hackers In Without the Password — Lenovo ID Was Enough

Published: September 2, 2026 14:57

The password was fine. That was the problem. Attackers did not need to steal it. Dropbox disclosed that roughly 5,000 accounts were accessed during an... The post Dropbox Let Hackers In Without the Password — Lenovo ID Was Enough appeared first on…

AI Agents Just Compressed a Two-Week Ransomware Attack Into 10 Hours

Published: September 2, 2026 14:56

This was not a lab demo. Unit 42 responded to a real enterprise incident where a human threat actor used frontier AI models together with... The post AI Agents Just Compressed a Two-Week Ransomware Attack Into 10 Hours appeared first on BugsToday –…

A Public Exploit Just Dropped for Cleo Harmony — Patch It Now

Published: September 2, 2026 14:34

Cleo is back in the vulnerability headlines. And this time, defenders don’t get the luxury of waiting to see whether someone develops an exploit. One... The post A Public Exploit Just Dropped for Cleo Harmony — Patch It Now appeared first on BugsToday –…

9.5 Million Patients Exposed After Aesto Health AWS Breach

Published: September 2, 2026 14:33

Healthcare providers keep telling patients that their data is protected. Then they hand millions of medical records to another company. That company gets breached. And... The post 9.5 Million Patients Exposed After Aesto Health AWS Breach appeared first on…

MLflow SSRF Is Stealing Cloud Credentials — and Today Is the CISA Deadline

Published: September 2, 2026 07:05

MLflow was supposed to help teams manage machine-learning experiments. Instead, attackers are using vulnerable MLflow servers as a bridge into cloud environments. The vulnerability is... The post MLflow SSRF Is Stealing Cloud Credentials — and Today Is the…

OpenAI Says Astra Has Reached “Critical” Cyber Capability — and That Changes the Rules

Published: September 2, 2026 07:03

For years, the scary AI cybersecurity headline was always hypothetical. What happens when an AI can find a zero-day? Now OpenAI says one of its... The post OpenAI Says Astra Has Reached “Critical” Cyber Capability — and That Changes the Rules appeared…

13 Poisoned Packagist Themes Turn Websites Into iPhone Spyware Traps

Published: September 2, 2026 07:01

The developer didn’t install malware. At least, that’s probably what they thought. They installed a theme. The theme then injected JavaScript into every page. Visitors... The post 13 Poisoned Packagist Themes Turn Websites Into iPhone Spyware Traps…

A 23-Year-Old Botnet Just Got Hacked From the Inside

Published: September 2, 2026 07:00

Some malware dies quickly. Some malware gets patched. Some malware survives long enough to become part of Internet history. Sality survived for more than two... The post A 23-Year-Old Botnet Just Got Hacked From the Inside appeared first on BugsToday –…

FBI Probes Dark Web Service Selling 153 Million Driver’s License Scans

Published: September 2, 2026 06:58

The dark web doesn’t need another password dump. It now appears to have something considerably more useful. Driver’s licenses. More than 153 million of them,... The post FBI Probes Dark Web Service Selling 153 Million Driver’s License Scans appeared first…

AI Just Helped Turn One PLC Exploit Into Another — and It Took Less Than $600

Published: September 1, 2026 18:17

The scary part isn’t that AI found a new vulnerability. It didn’t. The scary part is that it helped turn an old exploit into a... The post AI Just Helped Turn One PLC Exploit Into Another — and It Took Less Than $600 appeared first on BugsToday –…

JFrog Artifactory Authentication Bypass Is Being Exploited in the Wild

Published: September 1, 2026 18:10

The software repository may be the target. Not the application. Not the developer workstation. The repository that feeds everything else. That’s why CVE-2026-82329 deserves attention.... The post JFrog Artifactory Authentication Bypass Is Being Exploited…

Hackers Stole an AI API Key and Burned $600,000 in Compute Credits

Published: September 1, 2026 18:07

The attackers didn’t steal the AI model. They stole the bill. METR, a nonprofit that evaluates frontier AI systems, has disclosed two security incidents involving... The post Hackers Stole an AI API Key and Burned $600,000 in Compute Credits appeared first…

Malicious PHP Packages Are Being Used to Push iPhone Spyware

Published: September 1, 2026 18:05

The attack starts with PHP. It ends with an iPhone. That is what makes this campaign interesting. Security researchers identified 13 malicious packages published through... The post Malicious PHP Packages Are Being Used to Push iPhone Spyware appeared…

Fake Claude Opus 5 for Windows Is Actually a RevStealer Trap

Published: September 1, 2026 14:22

The AI hype machine has produced another useful attack vector. This time the bait is Claude Opus 5. Attackers are distributing a fake Windows application... The post Fake Claude Opus 5 for Windows Is Actually a RevStealer Trap appeared first on BugsToday –…

BGP Hijack Turned Virtualizor Updates Into a Supply-Chain Attack

Published: September 1, 2026 14:15

This is what happens when you compromise the road instead of the destination. Attackers didn’t need to break Virtualizor’s update server. They redirected traffic on... The post BGP Hijack Turned Virtualizor Updates Into a Supply-Chain Attack appeared first…

21,899 Exchange Servers Are Still Exposed to a Mailbox Hijack Bug

Published: September 1, 2026 13:34

There are still 21,899 Exchange servers on the Internet that shouldn’t be there in their current state. That’s the latest number from Shadowserver’s Internet-wide scanning.... The post 21,899 Exchange Servers Are Still Exposed to a Mailbox Hijack Bug…

Langflow RCE Is Being Exploited to Steal AI and Cloud Credentials

Published: September 1, 2026 13:32

AI infrastructure has a new problem. Attackers aren’t just trying to break the AI. They’re trying to steal everything the AI server can access. CVE-2026-0768... The post Langflow RCE Is Being Exploited to Steal AI and Cloud Credentials appeared first on…

JFrog Artifactory Auth Bypass Is Already Being Exploited

Published: September 1, 2026 13:31

Supply-chain infrastructure is supposed to be one of the places where trust starts. CVE-2026-82329 turns that trust into the attack surface. JFrog disclosed a critical... The post JFrog Artifactory Auth Bypass Is Already Being Exploited appeared first on…

Apache Wicket Got Hit by Two Bugs — One Can Escape the Path, the Other Ignores Upload Limits

Published: September 1, 2026 05:54

Apache Wicket isn’t having the best week. Two newly disclosed vulnerabilities hit different parts of the Java web framework. One can break path restrictions. The... The post Apache Wicket Got Hit by Two Bugs — One Can Escape the Path, the Other Ignores…

IBM Fixed a Privilege Escalation Bug Before Someone Got Admin Powers

Published: September 1, 2026 05:52

You don’t always need to steal an administrator’s password. Sometimes you just need the application to forget checking whether you’re an administrator. A recently disclosed... The post IBM Fixed a Privilege Escalation Bug Before Someone Got Admin Powers…

Apache Shiro Can Be Tricked Into Calling the Attacker’s Server

Published: September 1, 2026 05:50

Your authentication framework is supposed to control where users go. This bug can make it control where your server goes. CVE-2026-58301 affects Apache Shiro deployments... The post Apache Shiro Can Be Tricked Into Calling the Attacker’s Server appeared…

Kaspersky Endpoint Security Got a Public Privilege-Escalation PoC

Published: August 31, 2026 17:55

Your antivirus is supposed to stop the attacker. What happens when the antivirus becomes the privilege-escalation target? That’s the question raised by HardBreacher, a newly... The post Kaspersky Endpoint Security Got a Public Privilege-Escalation PoC…

Tenda AC1206 Has a Critical Auth Bypass — And the Exploit Is Already Public

Published: August 31, 2026 17:52

Your router has one job: keep strangers out. CVE-2026-82693 has a different idea. A newly published vulnerability in the Tenda AC1206 allows a remote attacker... The post Tenda AC1206 Has a Critical Auth Bypass — And the Exploit Is Already Public appeared…

AI Agents Found a JFrog Zero-Day and Poisoned the Container Supply Chain

Published: August 31, 2026 17:44

The AI didn’t need to hack the container. It hacked the thing deciding which container was trusted. That’s much worse. OpenAI’s investigation into its July... The post AI Agents Found a JFrog Zero-Day and Poisoned the Container Supply Chain appeared first…

Chinese Hackers Turned Cisco Routers Into Spy Platforms

Published: August 31, 2026 17:43

A router is supposed to move packets. Chinese Fire Ant apparently found a better use for one. Researchers investigating the threat actor discovered an active... The post Chinese Hackers Turned Cisco Routers Into Spy Platforms appeared first on BugsToday –…

PaperCut’s Zero-Days Were Already Being Exploited — Then Attackers Broke the Fix

Published: August 31, 2026 17:41

PaperCut had a zero-day. Then it had two. Then the first emergency fix got bypassed. That’s a bad week for a print server. Attackers are... The post PaperCut’s Zero-Days Were Already Being Exploited — Then Attackers Broke the Fix appeared first on…

OpenZFS Bug Lets Unprivileged Users Punch Through the Sandbox

Published: August 31, 2026 17:40

A normal user gets a shell. Nothing special. No root. No sudo. Then OpenZFS enters the picture. A newly disclosed vulnerability shows how filesystem code... The post OpenZFS Bug Lets Unprivileged Users Punch Through the Sandbox appeared first on BugsToday…

GNU Emacs Could Execute Code Just by Opening the Wrong File

Published: August 31, 2026 17:38

Your editor shouldn’t be able to pwn your workstation. Emacs disagrees. A newly disclosed vulnerability demonstrates how opening a maliciously crafted file in GNU Emacs... The post GNU Emacs Could Execute Code Just by Opening the Wrong File appeared first…

Hulumi’s AWS Policy Bug Can Break the GitHub OIDC Trust Model

Published: August 31, 2026 17:37

Your GitHub workflow doesn’t need an AWS password. It can get credentials through OIDC. That’s the good news. The bad news is that one incorrect... The post Hulumi’s AWS Policy Bug Can Break the GitHub OIDC Trust Model appeared first on BugsToday –…

OpenClaw Will Execute Extensions You Never Explicitly Trusted

Published: August 31, 2026 17:35

AI agents are supposed to follow instructions. Apparently, OpenClaw was also willing to follow code it never explicitly trusted. That’s the problem behind CVE-2026-32920. The... The post OpenClaw Will Execute Extensions You Never Explicitly Trusted…

OpenClaw’s iMessage Pipeline Had a Remote Command Injection

Published: August 31, 2026 17:33

The filename was supposed to identify an attachment. Instead, it could become part of a shell command. That’s the entire problem behind CVE-2026-32917. And because... The post OpenClaw’s iMessage Pipeline Had a Remote Command Injection appeared first on…

Kata Containers Bug Lets Containers Escape Their Cage

Published: August 31, 2026 14:34

Containers are supposed to be isolated. That’s the whole point. Kata Containers takes that idea further by running workloads inside lightweight virtual machines rather than... The post Kata Containers Bug Lets Containers Escape Their Cage appeared first on…

OpenRGB Bug Lets Attackers Break Out of the Sandbox

Published: August 31, 2026 14:32

RGB lighting software shouldn’t be an attack surface. Apparently, it is. A newly disclosed vulnerability in OpenRGB demonstrates how software controlling keyboards, mice, motherboards and... The post OpenRGB Bug Lets Attackers Break Out of the Sandbox…

Blind Eagle’s Malware Operator Got Hacked — Researchers Found His Arsenal

Published: August 31, 2026 14:31

The malware operator was hunting victims. Someone else was hunting him. And the second attacker won. Researchers from LevelBlue followed a GitHub account used by... The post Blind Eagle’s Malware Operator Got Hacked — Researchers Found His Arsenal appeared…

Debt Relief Phishing Campaign Turns Phone Calls Into Data Theft

Published: August 31, 2026 14:29

The email doesn’t steal anything. It just tells you to call. That’s the trick. A newly observed campaign sent around 24,700 messages to more than... The post Debt Relief Phishing Campaign Turns Phone Calls Into Data Theft appeared first on BugsToday –…

AI Apple Support Calls Are Now Helping Thieves Unlock Stolen iPhones

Published: August 31, 2026 14:27

Your iPhone gets stolen. A few hours later, someone calls you. They know the model. They know the device was reported missing. They know you’re... The post AI Apple Support Calls Are Now Helping Thieves Unlock Stolen iPhones appeared first on BugsToday –…

Encryption Became the Prompt Injection

Published: August 31, 2026 14:25

The malicious instructions aren’t visible. The security filter sees garbage. The AI sees a perfectly legitimate webpage. Then the AI decrypts the garbage itself. That’s... The post Encryption Became the Prompt Injection appeared first on BugsToday –…

Amazon Kiro Can Leak Your Files Just Because You Opened a Project

Published: August 31, 2026 14:24

You don’t have to type the malicious prompt. You don’t even have to ask Kiro to read the secret. Opening the wrong project can be... The post Amazon Kiro Can Leak Your Files Just Because You Opened a Project appeared first on BugsToday – Zero-Days,…

KryBit Ransomware Got Hacked — Then Hacked Its Rival Back

Published: August 31, 2026 14:05

Ransomware gangs are supposed to hack companies. KryBit managed to become a victim itself. Then it hacked the people who hacked it. Welcome to ransomware-as-a-service... The post KryBit Ransomware Got Hacked — Then Hacked Its Rival Back appeared first on…

Spring Ring Turns Microsoft Teams Into a Vishing Weapon

Published: August 31, 2026 14:03

The attacker didn’t need to break into Microsoft Teams. They just joined the meeting. Then they pretended to be IT. Researchers at Unit 42 tracked... The post Spring Ring Turns Microsoft Teams Into a Vishing Weapon appeared first on BugsToday – Zero-Days,…

AI Agents Trusted llms.txt — Then Installed Code Nobody Owned

Published: August 31, 2026 14:00

The documentation wasn’t hacked. The package registry wasn’t necessarily hacked. The AI simply trusted the wrong instructions. That’s the problem. Researchers analyzed 6,214 live domains,... The post AI Agents Trusted llms.txt — Then Installed Code Nobody…

A Hacker Wiped Secret Neighbor Players — Then Demanded the Game Disappear

Published: August 31, 2026 13:59

Most game hackers want money. Some want accounts. Some want skins. This one apparently wanted the game gone. Secret Neighbor, the multiplayer spin-off of Hello... The post A Hacker Wiped Secret Neighbor Players — Then Demanded the Game Disappear appeared…

FulcrumSec Claims 86 GB Stolen From Manchester Airports Group

Published: August 31, 2026 13:15

Airports are attractive targets. They have money. They have thousands of employees. They have suppliers, contractors, IT systems and huge amounts of personal information. Now... The post FulcrumSec Claims 86 GB Stolen From Manchester Airports Group…

TerminalFix Turns a Fake CAPTCHA Into a Corporate Network Tunnel

Published: August 31, 2026 13:13

The CAPTCHA isn’t checking whether you’re human. It’s checking whether you’ll execute malware. TerminalFix is a new ClickFix variant documented by Microsoft that starts with... The post TerminalFix Turns a Fake CAPTCHA Into a Corporate Network Tunnel…

Steam’s 12 TB Teraleak Exposes a Decade of PC Gaming History

Published: August 31, 2026 13:11

This isn’t another stolen Steam account database. It’s much stranger. And much bigger. A 12+ TB archive containing data from old Steam infrastructure has surfaced... The post Steam’s 12 TB Teraleak Exposes a Decade of PC Gaming History appeared first on…

Rails 9.5 Bug Is Being Exploited — And It Can Lead to RCE

Published: August 31, 2026 13:09

Ruby on Rails just got another reminder that file uploads are never “just file uploads.” CVE-2026-66066 affects applications using Active Storage with the libvips image-processing... The post Rails 9.5 Bug Is Being Exploited — And It Can Lead to RCE…

Hackers Got Hacked — An Infostealer Exposed Blind Eagle’s Entire Arsenal

Published: August 31, 2026 10:14

The attackers were supposed to steal the data. Instead, someone stole theirs. A commodity infostealer infected a workstation apparently used by an operator linked to... The post Hackers Got Hacked — An Infostealer Exposed Blind Eagle’s Entire Arsenal…

One Malicious Website Can Poison NVIDIA NemoClaw’s AI Agent

Published: August 31, 2026 10:12

Your AI agent doesn’t need malware to get compromised. It may only need you to open the wrong website. That’s the ugly part of CVE-2026-65105.... The post One Malicious Website Can Poison NVIDIA NemoClaw’s AI Agent appeared first on BugsToday – Zero-Days,…

D-Link Router Flaws Let Local Attackers Reset Admin Passwords and Steal Wi-Fi Credentials

Published: August 31, 2026 10:10

Your router has one job. Keep strangers out. D-Link’s DIR-X1860Z managed to make that considerably harder. Two newly disclosed flaws in the router’s OpenWrt-based management... The post D-Link Router Flaws Let Local Attackers Reset Admin Passwords and…

AI Shopping Assistant Turned Into a Backend RCE

Published: August 31, 2026 10:09

The chatbot was supposed to help customers shop. Instead, researchers found a route from a public-facing search feature to the server running the AI assistant.... The post AI Shopping Assistant Turned Into a Backend RCE appeared first on BugsToday –…

Magecart Put Its Skimmer on Ethereum — 40+ Stores Were Hit

Published: August 31, 2026 10:07

Magecart has found a new place to hide. Not a bulletproof server. Not a compromised CDN. Ethereum. HexMage is abusing smart contracts on the Ethereum... The post Magecart Put Its Skimmer on Ethereum — 40+ Stores Were Hit appeared first on BugsToday –…

Gryxa Malware Watches Defenders Remove It — Then Fights Back

Published: August 31, 2026 10:06

Most malware tries to hide. Gryxa does something more interesting. It watches. When defenders start removing it, surviving components can collect information about the cleanup... The post Gryxa Malware Watches Defenders Remove It — Then Fights Back…

Composer Dependency Bug Can Expose Files Outside the Project

Published: August 31, 2026 09:16

Composer is supposed to install PHP dependencies. It shouldn’t be changing the permissions of files it doesn’t own. That’s exactly what CVE-2026-59944 can make happen.... The post Composer Dependency Bug Can Expose Files Outside the Project appeared first…

One cPanel Customer Can Take Root Over the Entire Hosting Server

Published: August 31, 2026 09:14

Shared hosting depends on one simple assumption: Customer A cannot become root over Customer B. CVE-2026-65643 attacks that assumption. The vulnerability sits inside cPanel’s domain... The post One cPanel Customer Can Take Root Over the Entire Hosting…

D-Link DIR-825M Has a 9.9 Router Flaw — And the Exploit Is Already Public

Published: August 31, 2026 09:11

Routers are supposed to sit between attackers and the network. This one can become the way in. CVE-2026-82593 affects D-Link DIR-825M firmware 1.1.8 and sits... The post D-Link DIR-825M Has a 9.9 Router Flaw — And the Exploit Is Already Public appeared…

Hackers Are Stealing Claude Sessions and Burning Through Paid AI Usage

Published: August 31, 2026 09:09

The password wasn’t cracked. MFA wasn’t defeated. The attacker simply stole the session after the user had already logged in. That’s the ugly part of... The post Hackers Are Stealing Claude Sessions and Burning Through Paid AI Usage appeared first on…

Water-Sector Supplier Breach Triggers FBI Scrutiny as Attacks Escalate

Published: August 31, 2026 08:32

The target wasn’t a water treatment plant. It was the company supplying technology to the people running one. That distinction matters. The FBI is examining... The post Water-Sector Supplier Breach Triggers FBI Scrutiny as Attacks Escalate appeared first…

N-able Patched an MSP “God Mode” Bug. The First Fix Wasn’t Enough

Published: August 31, 2026 08:31

Remote monitoring and management platforms are attractive targets for one obvious reason. Compromise one server. Get access to many others. N-able N-central is used by... The post N-able Patched an MSP “God Mode” Bug. The First Fix Wasn’t Enough appeared…

Microsoft’s AI Framework Can Let Hackers Control Android Devices Without a Login

Published: August 31, 2026 08:27

Microsoft’s UFO framework is designed to automate devices. That’s the whole point. It can connect AI-driven workflows to Android devices and perform actions through Android... The post Microsoft’s AI Framework Can Let Hackers Control Android Devices…

Ubiquiti Just Patched Three Maximum-Severity UniFi Bugs

Published: August 30, 2026 18:40

Ubiquiti just dropped a security bulletin that is much bigger than the headline suggests. 22 vulnerabilities. 21 rated Critical. Three of them sit at the... The post Ubiquiti Just Patched Three Maximum-Severity UniFi Bugs appeared first on BugsToday –…

SAP Commerce Cloud Has a CVSS 10 RCE — Attackers Moved in Three Days

Published: August 30, 2026 18:34

SAP Commerce Cloud is supposed to sit behind layers of enterprise security. CVE-2026-58231 doesn’t care. The vulnerability affects the Data Hub Adapter and was disclosed... The post SAP Commerce Cloud Has a CVSS 10 RCE — Attackers Moved in Three Days…

Microsoft Copilot Was Tricked Into Stealing Its User’s Data

Published: August 30, 2026 18:32

This is one of those AI security bugs that sounds ridiculous until you understand what Copilot can actually access. Email. Cloud storage. Calendars. Chat history.... The post Microsoft Copilot Was Tricked Into Stealing Its User’s Data appeared first on…

Next.js Has Two Critical RCE Bugs — One Comes With a Public PoC

Published: August 30, 2026 18:30

Next.js just got the kind of security release developers don’t want to see on a Friday afternoon. Two critical vulnerabilities. Two different attack paths. Both... The post Next.js Has Two Critical RCE Bugs — One Comes With a Public PoC appeared first on…

JFrog Artifactory Just Entered CISA’s KEV List — After AI Agents Exploited It

Published: August 30, 2026 06:18

A CVSS 5.3 vulnerability just landed in CISA’s Known Exploited Vulnerabilities catalog. Normally, that wouldn’t be the headline. This one is different. It’s CVE-2026-66384, a... The post JFrog Artifactory Just Entered CISA’s KEV List — After AI Agents…

The Fake GTA 6 Demo Is a Password Thief

Published: August 30, 2026 06:15

The GTA 6 hype has officially become an attack surface. Cybercriminals are now running fake websites pretending to offer a playable Grand Theft Auto VI... The post The Fake GTA 6 Demo Is a Password Thief appeared first on BugsToday – Zero-Days, Exploits &…

WordPress Plugin Rest Routes Has an Unauthenticated SQL Injection

Published: August 30, 2026 06:12

WordPress has another problem. This time it isn’t a fake CAPTCHA. It isn’t a malicious administrator account. And it isn’t a plugin requiring a complicated... The post WordPress Plugin Rest Routes Has an Unauthenticated SQL Injection appeared first on…

THIS WEEK IN BUGS: THE PATCH WAS NEVER THE WHOLE STORY

Published: August 29, 2026 15:09

Another week, another pile of CVEs, exploits and security incidents. Some deserved the headlines. Others didn’t. A few showed something more interesting: attackers don’t necessarily... The post THIS WEEK IN BUGS: THE PATCH WAS NEVER THE WHOLE STORY…

ShinyHunters Claims Another Hit — Jack Henry Data Allegedly Stolen

Published: August 29, 2026 15:06

ShinyHunters isn’t slowing down. The data-extortion group has now claimed another corporate victim: Jack Henry & Associates. And this one is interesting for a reason... The post ShinyHunters Claims Another Hit — Jack Henry Data Allegedly Stolen appeared…

ShinyHunters Claims a Massive McKesson Breach — 284 Million Records Allegedly Exposed

Published: August 29, 2026 15:04

Another day, another number so large that it stops sounding real. 284 million records. That’s the figure circulating around an alleged breach of healthcare giant... The post ShinyHunters Claims a Massive McKesson Breach — 284 Million Records Allegedly…

GiveWP Has a CVSS 10 RCE — 100,000 WordPress Sites Are in the Blast Radius

Published: August 29, 2026 15:02

WordPress plugins don’t normally get treated like remote shells. This one can. CVE-2026-82222 gives an unauthenticated attacker a path from a crafted request to PHP... The post GiveWP Has a CVSS 10 RCE — 100,000 WordPress Sites Are in the Blast Radius…

TeamViewer on Linux Can Be Turned Into a Remote Command Shell

Published: August 29, 2026 11:29

Remote-support software is supposed to make administration easier. It isn’t supposed to become a command shell. That’s exactly what happened with CVE-2026-19042 in TeamViewer’s Linux... The post TeamViewer on Linux Can Be Turned Into a Remote Command Shell…

Cl0p Turned Windchill Into a Data-Theft Machine

Published: August 29, 2026 11:27

Ransomware doesn’t always need to encrypt anything. Cl0p just demonstrated why. Instead of locking thousands of computers, attackers went after something potentially more valuable: the... The post Cl0p Turned Windchill Into a Data-Theft Machine appeared…

A 2019 SQL Server Bug Is Still Getting Exploited

Published: August 29, 2026 11:19

Six years old. Still dangerous. That’s the story behind CVE-2019-1068. The vulnerability was disclosed and patched by Microsoft back in 2019. Yet it has now... The post A 2019 SQL Server Bug Is Still Getting Exploited appeared first on BugsToday –…

Most “AI Malware” Isn’t Actually Hitting Anyone

Published: August 29, 2026 11:17

AI malware is everywhere. At least that’s what the headlines would have you believe. Criminals are using AI. Malware is becoming autonomous. Hackers are generating... The post Most “AI Malware” Isn’t Actually Hitting Anyone appeared first on BugsToday –…

Hackers Turned Cursor AI Into an Attack Tool

Published: August 29, 2026 11:15

The hacker didn’t write the code. He asked the AI to do it. That’s the interesting part of the Aur0ra campaign. Security researchers found evidence... The post Hackers Turned Cursor AI Into an Attack Tool appeared first on BugsToday – Zero-Days, Exploits &…

Rhysida Wants 30 Bitcoin for Berlin’s Stolen Data

Published: August 29, 2026 11:14

Berlin has a price tag. 30 Bitcoin. That’s what the Rhysida ransomware operation reportedly wants for a dataset it claims to have stolen from the... The post Rhysida Wants 30 Bitcoin for Berlin’s Stolen Data appeared first on BugsToday – Zero-Days,…

~ 57 additional posts are not shown ~