(Image credit: Shutterstock/David MG) WordPress patches two flaws: CVE‑2026‑60137 (SQL injection, medium severity) and CVE‑2026‑63030 (REST API batch‑route confusion, critical […]
Category: Security
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI […]
N-day is Becoming N-Hour. Patching Faster Won’t Save You.
Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and […]
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
A cloud tenant using nothing but ordinary GPU access can push a data center’s power draw up and down fast […]
Top AI coding agents can be easy victims to sandbox escapes, showing they aren’t as secure as they claim to be
(Image credit: Blue Planet Studio/Shutterstock) Pillar researchers demonstrated sandbox escapes in AI coding agents Exploits let attacker‑written configs run with […]
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) […]
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first […]
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Ravie LakshmananJul 21, 2026Vulnerability / Artificial Intelligence Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow […]
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) […]
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure […]
