GitLab has released security updates to fix a high-severity vulnerability in its Duo Claude AI agent that could allow authenticated developers to execute arbitrary commands within CI pipeline contexts. The …
TP-Link Kasa Smart Home Devices Vulnerability Allows Attackers to Disrupt Device Functionality
TP-Link has disclosed a high-severity vulnerability affecting multiple Kasa smart home devices that could allow attackers on the same local network to intercept, replay, or forge device-control commands. Tracked as …
CISA Warns of Microsoft SQL Server RCE Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a Microsoft SQL Server remote code execution vulnerability, tracked as CVE-2019-1068, to its Known Exploited Vulnerabilities catalog after confirming exploitation in …
Two Australians Charged Over TeamPCP Supply-Chain Attacks That Hit 1,000+ Organizations
Two Western Australian men have been charged over alleged TeamPCP supply-chain attacks that police say planted malicious open-source code and reached more than 1,000 organizations worldwide. The Australian Federal Police …
AWS Shows How Hackers Can Turn Stolen Cloud Credentials Into Full-Scale Attacks
Stolen cloud credentials can turn an incident into a wider breach. An attacker who gets a valid AWS key or session can enter as an approved user and move toward …
Multiple TeamViewer Vulnerabilities Enable Remote Code Execution Attacks
TeamViewer patched high-severity CVE-2026-16444, allowing authenticated remote-session attackers to write files to unintended locations and potentially execute code with user privileges. The issue is detailed in TeamViewer security bulletin TV-2026-1008, …
Hackers Exploit ownCloud and WordPress Flaws to Steal Philippine Nuclear and Naval Data
A suspected Chinese-speaking operator exploited known ownCloud and WordPress weaknesses to collect sensitive information from a Philippine nuclear research body and a marine engineering company that serves the Philippine Navy. …
Hackers Exploit AI Infrastructure to Steal API Keys, Gain Persistence and Mine Cryptocurrency
Hackers are increasingly turning AI platforms into a doorway to valuable corporate systems. New Microsoft research shows that exposed AI gateways, retrieval tools, and workflow services can give intruders a …
Ransomware Hacker Uses AI to Plan Cyberattacks Against More Than 20 Organizations
Aurora ransomware has been tied to a Russian-speaking affiliate that used an AI coding assistant while targeting more than 20 organisations. A wrongly exposed server gave investigators a detailed view …
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply …

