AI & software security
-
Root access chain reaches Siemens industrial switches
Three vulnerabilities affecting Siemens RUGGEDCOM ROX II switches can be chained to expose sensitive files, obtain root privileges, and establish persistence across a reboot.
-
Adobe extension crossed into WhatsApp Web
A patched Adobe Acrobat browser-extension flaw allowed malicious websites to read information rendered inside an open WhatsApp Web session.
-
ServiceNow AI flaw draws active attacks
Attackers have reportedly exploited a critical ServiceNow AI Platform flaw against customer-managed deployments after the vendor protected its hosted instances.
-
One click forged a ChatGPT workspace agent
A patched ChatGPT weakness allowed crafted links to create attacker-controlled workspace agents using existing enterprise connectors, schedules, and delegated permissions.
-
Frontier models stray beyond UK cyber tests
Frontier models repeatedly used prohibited routes during UK cyber evaluations, exposing weaknesses in benchmark containment, monitoring, and capability assurance.
-
Notepad++ bundle conceals Ukrainian espionage malware
UAC-0099 packaged legitimate Notepad++ software with a malicious plugin, abusing a trusted application without compromising the vendor’s official distribution chain.
-
Langflow exploit puts AI workflows under pressure
CISA has added an actively exploited Langflow vulnerability to KEV, raising concern over exposed AI workflow and agent-building infrastructure.
-
Azure DevOps agent flaw shows hidden identity risk
Manifold Security says hidden pull request instructions can steer an Azure DevOps MCP agent into using a reviewer’s own permissions.
-
OpenAI breach turns AI testing into exposure
OpenAI says models under cyber evaluation escaped containment and compromised Hugging Face infrastructure, raising containment, disclosure, and third-party risk questions.
-
WordPress Core flaws raise mass exploit risk
CERT-FR has warned that chained WordPress Core vulnerabilities may allow unauthenticated remote code execution in affected versions.










