August 10, 2026 RovoBlast is a one-click prompt-injection vulnerability in Atlassian Rovo that could allow attackers to exfiltrate sensitive enterprise data from Jira, Confluence, SharePoint, and other connected services. Atlassian …
Claude Code Sessions Spawn Reverse Tunnels and LaunchAgent Persistence on macOS
August 10, 2026 Claude Code activity on a macOS developer machine has raised a difficult security question: when does convenient automation become a serious exposure? A new Elastic investigation found …
New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response
August 10, 2026 A supply chain attack targeting BdThemes WordPress plugins has exposed site administrators to account takeover, webshell deployment, and persistent backdoors. Wordfence Threat Intelligence was notified of the …
Claude Opus 5 Cuts Indirect Prompt Injection Attack Success to 2% in New Benchmark Analysis
August 10, 2026 Anthropic’s Claude Opus 5 has recorded the lowest indirect prompt injection attack success rate in Gray Swan’s latest benchmark, according to results provided in its system card. …
Windows 11’s Built-In Weather App Reportedly Consumes 1.2GB of RAM for Showing Forecasts
August 10, 2026 Windows 11’s default Weather app, a fixture on the taskbar for millions of users, is under fire after independent testing revealed it consumes more than 1.2GB of …
Claude-Powered OpenClaw AI Agent Exploits Gym API to Steal a Workout Slot
August 10, 2026 An Australian man’s AI assistant has become the center of what is being described as the country’s first known autonomous AI cyberattack, after it exploited a security …
Weekly Cyber Security Newsletter — OWASP Top 10 for LLM, Cisco IOS XE Flaw, and 1-Click Cursor RCE +20 Stories
This week’s roundup covers active exploitation of Apache Tomcat and SonicWall SMA, a nearly two-decade-old Linux kernel flaw, critical bugs in N-able N-Central, Veeam ONE, Jenkins, and Cisco IOS XE, …
Metabase 0-Day Vulnerability Exploited in the Wild to Gain Admin Access
August 9, 2026 Metabase, the widely used open-source business intelligence and data visualization platform, has confirmed that a critical zero-day vulnerability tracked as GHSA-vwf4-m7j8-wcjf was actively exploited in the wild, …
Microsoft to Launch New Security Detection Report in Teams
August 9, 2026 Microsoft is preparing to roll out a new Security Detection Report inside the Teams admin center, giving administrators a long-awaited, unified way to monitor messaging-based threats across …
CSS Bomb Attacks Turn Malicious Emails Into Password-Stealing Keyloggers
August 9, 2026 A new class of email-based attacks that exploit ordinary CSS styling code to hijack webmail interfaces, spy on user activity, and even steal passwords in real time, …
