Six Flowise RCE Flaws Let Attackers Execute Code on AI Workflow Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 4, 2026 Flowise servers used to build AI agents and automated workflows are facing six newly disclosed remote code execution flaws. The weaknesses could allow authenticated attackers to run …

DarkSword iOS Exploit Kit Spreads Across 180 Web Properties and 27 Hosts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 4, 2026 DarkSword has expanded from a leaked iOS exploit chain into a broad and fast-changing network of malicious web infrastructure. The campaign targets iPhones running iOS 18.4 through …

CISA Warns of N-able N-central Authentication Bypass Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 4, 2026 CISA has warned that attackers are actively exploiting a critical authentication bypass vulnerability in N-able N-central. Tracked as CVE-2026-18577, the flaw affects N-central servers running versions earlier …

Public PoC Released for CUPS Vulnerability Allows Attackers to Gain Root Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 4, 2026 A public proof-of-concept (PoC) has been released for CVE-2026-39875, a macOS vulnerability in the Common UNIX Printing System (CUPS) that allows an unprivileged local user to perform …

Roblox Malware Streams Victims’ Desktops and Captures Webcam Footage

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 4, 2026 A malicious Roblox cheat campaign is turning a familiar gaming shortcut into a serious privacy threat. Players seeking an “undetected” Xeno script executor are being lured through …

Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 4, 2026 A Russian-speaking hacker has been linked to a broad operation that breached organizations worldwide, collected credentials, and prepared access for sale to ransomware groups. The activity affected …

Keyv npm Package with 127M Weekly Downloads Compromised in Shai-Hulud Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers have compromised the GitHub account of the maintainer behind keyv, a popular key-value storage library that pulls in roughly 127 million weekly downloads on npm, and used that access …

Critical Gitea Arbitrary File Read Vulnerability Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 4, 2026 A critical security flaw in Gitea, tracked as CVE-2026-59774, allows unauthenticated remote attackers to read arbitrary files from vulnerable servers and potentially escalate the attack to remote …

Critical Adobe Campaign Classic Vulnerabilities Enables Arbitrary Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 4, 2026 Adobe has issued a critical security update for Adobe Campaign Classic, addressing multiple flaws that could enable arbitrary code execution on vulnerable systems. The update, tracked as …

A Malicious GitHub Issue Could Turn Google’s AI Agent Against Its Own CI/CD Pipeline

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 4, 2026 A first practical, real-world case of agent-to-agent exploitation inside a production multi-agent system, a novel attack class that turns one AI agent against another to compromise a …