Critical vulnerabilities have been disclosed in Paperclip, an AI agent orchestration platform, that could allow attackers to gain administrative access and execute commands on affected servers. The most severe flaw, …
One Fake Movie Download Can Expose Passwords, Payments and Crypto Assets
August 6, 2026 Cybercriminals are weaponizing pirated downloads of the blockbuster theatrical release “The Odyssey (2026)” to deliver Lumma Stealer. This prolific information-stealing malware quietly strips compromised systems of saved …
Hackers Hid a Remote-Control Toolkit Inside Oracle to Take Over a Windows Server
August 6, 2026 A routine web application weakness has been tied to a serious Windows Server compromise after attackers used SQL injection to plant a remote-control toolkit inside an Oracle …
Public PoC Released for Linux Kernel Bridge Use-After-Free Vulnerability
August 6, 2026 A public proof-of-concept has been released for a use-after-free flaw affecting the Linux kernel’s bridge subsystem, specifically its Spanning Tree Protocol implementation in net/bridge. The issue can …
Critical Jenkins Vulnerability Allows Attackers to Execute Malicious Code on Controller
August 6, 2026 Jenkins has disclosed a critical security vulnerability that could allow attackers to execute malicious code on a Jenkins controller by bypassing a security filter used in agent-to-controller …
OWASP Releases GenAI LLM Top 10 2026 for Building and Securing Modern AI Apps
August 6, 2026 The Open Web Application Security Project (OWASP) has officially released the Top 10 for LLM Applications 2026, a foundational security guide targeting the most critical vulnerabilities across …
OpenAI Agents Discover Zero-Day and Leave the Door Open for Other Models
August 6, 2026 OpenAI has revealed at the Black Hat security conference that AI agents involved in a cybersecurity evaluation found previously unknown vulnerabilities and used them to escape a …
Meta Says AI Model Gained Internet Access and Hacked Another Organization’s System
Meta has disclosed that one of its AI models gained unintended access to the internet during a cybersecurity evaluation and then exploited a vulnerability in another organization’s system. The incident …
CISA Warns of TeamCity RCE Vulnerability Actively Exploited in Attacks
August 6, 2026 The U.S. Cybersecurity and Infrastructure Security Agency has warned that a critical JetBrains TeamCity flaw is being actively exploited. The vulnerability, tracked as CVE-2026-63077, can let an …
250+ macOS ClickFix Domains Use Browser Fingerprinting to Hide Atomic Stealer Attacks
Atomic Stealer is being pushed at Mac users through websites that look harmless. A large ClickFix operation uses more than 250 look-alike domains to steer selected visitors toward a fake …
