News
-
Zoom Windows clients face account takeover
A critical input-validation vulnerability could allow an unauthenticated attacker to take over accounts through affected Zoom Workplace and VDI clients for Windows.
-
Critical Tenable flaw reaches privileged endpoints
A path-traversal and signature-verification weakness in Tenable Agent could lead to code execution through software deployed with extensive privileges across enterprise endpoints.
-
Claude deep links exposed prompt controls
A crafted link could open Claude Desktop and submit hidden attacker instructions automatically, exposing the boundary between browsers, AI agents, and locally authorised tools.
-
A repository can trigger code in Cursor
Mindgard says Cursor automatically runs a malicious Git binary placed inside an opened Windows repository, without displaying a warning or requiring further user action.
-
Public exploit code brings attacks to LoadMaster
Attempts to exploit a critical Progress LoadMaster command-injection vulnerability began within hours of functional proof-of-concept code becoming publicly available.
-
Old UEFI signatures reopen Secure Boot
Eleven old but validly signed bootloaders could be introduced onto modern systems to bypass Secure Boot, extending software supply chain risk beneath the operating system.
-
AsyncAPI release breach poisons npm packages
Attackers compromised AsyncAPI release processes and published malicious npm packages capable of installing a persistent remote shell on developer workstations and build systems.
-
No patch yet for Siemens PLC simulator
Every version of SIMATIC S7-PLCSIM Advanced is affected by a denial-of-service weakness, leaving industrial operators dependent on network restrictions while Siemens prepares corrected releases.
-
Credential flaw reaches EcoStruxure security console
Schneider Electric has patched a high-severity weakness that could allow a privileged local attacker to alter credentials used to administer cybersecurity policies across electrical operational technology.
-
Europe’s fraud machine ran like a multinational
Dutch police say an alleged investment-fraud network employed more than 700 people, operated approximately 20 call centres, and generated over €100 million a month.










