AI & software security
-
SharePoint secrets move into the breach zone
CERT-FR has warned that exploited SharePoint flaws require urgent patching and secret rotation where compromise is suspected.
-
Gold Eagle seeks faster vulnerability response
The White House has launched an AI-supported vulnerability clearinghouse intended to coordinate exploit detection and remediation across federal agencies, critical infrastructure, industry, and open-source partners.
-
Shadow AI grows alongside basic security failures
WatchGuard research suggests unauthorised AI use is rising alongside password reuse, weak application visibility, and inconsistent remote-working controls across smaller and mid-market organisations.
-
Oracle Payments flaw enters active exploitation
An unauthenticated Oracle E-Business Suite vulnerability capable of compromising the Payments component has been added to the US government’s exploited-vulnerability catalogue.
-
Starland RAT hides inside familiar software
A Russian-speaking criminal operation is disguising malware as familiar administration, database, conferencing, and gaming software, with potential exposure identified in Germany and Romania.
-
Gemini CLI ran a live botnet migration
Trend Micro says a Russian-speaking operator used Gemini CLI to migrate, debug, and control a small botnet through natural-language instructions rather than direct technical commands.
-
Claude deep links exposed prompt controls
A crafted link could open Claude Desktop and submit hidden attacker instructions automatically, exposing the boundary between browsers, AI agents, and locally authorised tools.
-
A repository can trigger code in Cursor
Mindgard says Cursor automatically runs a malicious Git binary placed inside an opened Windows repository, without displaying a warning or requiring further user action.
-
Old UEFI signatures reopen Secure Boot
Eleven old but validly signed bootloaders could be introduced onto modern systems to bypass Secure Boot, extending software supply chain risk beneath the operating system.
-
AsyncAPI release breach poisons npm packages
Attackers compromised AsyncAPI release processes and published malicious npm packages capable of installing a persistent remote shell on developer workstations and build systems.







