News
-
Zbtlink suspends sales after router backdoor report
Zbtlink has suspended sales and withdrawn affected software after researchers found a remotely controllable function across at least 20 router models, while the manufacturer disputes that it was intended for unauthorised access.
-
macOS Screen Sharing flaw bypasses authentication
Apple has patched a Screen Sharing authentication flaw as independent research describes a deeper pre-authentication route capable of reaching remote code execution on exposed, unpatched Macs.
-
CSS research crosses email and AI boundaries
PortSwigger research shows how weaknesses in webmail HTML and CSS handling can escape message boundaries, manipulate trusted interfaces, expose information, and influence AI browsers consuming email content.
-
RovoBlast exposes AI agent permission risks
A fixed flaw in Atlassian Rovo showed how a crafted link could place attacker instructions inside a trusted AI session and use the agent’s legitimate access across connected enterprise services.
-
OpenAI tightens Astra controls over cyber risk
OpenAI has paused Astra-related internal work that does not meet stronger security requirements after preliminary evaluations left it unable to rule out its highest cybersecurity capability threshold.
-
‘No reply’ domains become accidental data sinks
Researchers controlling plausible placeholder domains are receiving large volumes of misdirected corporate and personal information, exposing persistent weaknesses in automated email and account-deprovisioning processes.
-
Kimi K3 exploits gap in UK benchmark
Kimi K3 retrieved a benchmark solution through an allowed GitHub connection during a UK AI evaluation, exposing how containment design can distort measurements of autonomous cyber capability.
-
TrueConf compromise turns updates into attack route
Kaspersky says attackers compromised unpatched TrueConf servers and replaced legitimate client installers with backdoored versions, extending exposure from server operators to organisations connecting through affected counterparties.
-
Stade Français contains attack on internal systems
Stade Français says a cyberattack affected part of its information system while ticketing and merchandise remained available, as separate claims about leaked player documents remain unconfirmed by the club.
-
Metabase zero-day reaches n8n user data
A zero-day attack on Metabase Cloud reached data available through German automation company n8n’s analytics environment, exposing how an internal reporting dependency can become a route into user and credential information.


