Aggregator
CVE-2026-65947 | Balbooa Gridbox Extension up to 2.20.1 Admin Interface cross-site request forgery
Critical Ruflo MCP Bridge Flaw Lets Attackers Execute Commands and Hijack AI Agents
A critical security flaw in the open-source AI orchestration platform Ruflo has been disclosed, allowing unauthenticated attackers to execute arbitrary commands and fully compromise AI agent environments. Assigned a maximum CVSS base score of 10.0, the vulnerability (tracked as CVE-2026-59726) was discovered by Noma Labs and affects Ruflo’s Model Context Protocol (MCP) Bridge, a core […]
The post Critical Ruflo MCP Bridge Flaw Lets Attackers Execute Commands and Hijack AI Agents appeared first on Cyber Security News.
CVE-2026-65888 | Balbooa Gridbox Extension up to 2.20.1 socialLogin improper authentication
CVE-2026-66724 | CERT.PL MWDB Core up to 2.18.x Config/Blob Upload Endpoints improper authorization
Google 研究未发现有证据显示 AI 将导致大规模自动化以及能取代白领
听键盘声就能还原你打的字?无需标注的自监督窃听,正在变成真实隐私威胁
Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack
9,8 CVSS и обход аутентификации. Уязвимость серверов TeamCity позволяет подменить код перед самым релизом
Человек в контуре — только на бумаге: ИИ управляет уже четырьмя из шести этапов военного удара
OpenAI 开源 Codex Security CLI:用于发现、验证和修复安全漏洞
Russian Intelligence Hackers Phish Signal Backup Keys to Hijack Accounts and Messages
Russian intelligence-linked hackers are trying to seize Signal accounts by posing as support staff and asking targets for backup recovery keys. The campaign targets people with access to sensitive conversations, including officials, military personnel, political figures, journalists, and Ukrainian leaders. It relies on deception, not a break in Signal’s end-to-end encryption, but the possible loss […]
The post Russian Intelligence Hackers Phish Signal Backup Keys to Hijack Accounts and Messages appeared first on Cyber Security News.
CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In
Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack
Laundry Bear’s webmail hackers had more in store after February, report says
Hijacked Joyfill npm Packages Deploy Worm-Like RAT and Steal Developer Credentials
A fresh supply chain scare hit software teams after attackers slipped malware into trusted open source libraries. On July 28, 2026, malicious beta builds of two Joyfill packages appeared on the npm registry. The libraries, @joyfill/components and @joyfill/layouts, are used for forms and layout work in many web apps. Anyone who imported those beta builds […]
The post Hijacked Joyfill npm Packages Deploy Worm-Like RAT and Steal Developer Credentials appeared first on Cyber Security News.