Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

A Critical Flaw in Claude Cowork Exposes Mac Users to Unwanted Access A worrying vulnerability has been discovered in Claude Cowork, an artificial intelligence (AI) platform designed for collaborative workspaces. The flaw, which affects Mac users, allows AI agents running within virtual machines (VMs) to potentially escape their digital confines and access sensitive files on … Read more

New RefluXFS Linux flaw lets attackers gain root privileges

A critical vulnerability has been discovered in Linux systems that allows attackers to gain root privileges. Dubbed RefluXFS by Qualys’ Threat Research Unit (TRU), this flaw affects millions of systems running major enterprise Linux distributions, including Red Hat Enterprise Linux, Oracle Linux, and Amazon Linux. RefluXFS is a nine-year-old race condition vulnerability in the Linux … Read more

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

A Critical Linux Flaw Exposed: Nine-Year-Old RefluXFS Bug Gives Unprivileged Users Root Access on Default RHEL Installs For nearly a decade, a critical vulnerability has been lurking in the depths of Red Hat Enterprise Linux (RHEL), waiting to be exploited. The RefluXFS bug, discovered back in 2017, has finally come under scrutiny after researchers revealed … Read more

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

A wave of attacks is sweeping through cPanel and WHM servers, thanks to an ingenious tactic employed by threat actors: exploiting GitHub Actions Runners to gain unauthorized access. The vulnerability, detected in recent days, has caught security professionals off guard, highlighting the ever-evolving nature of cyber threats. The attack vector hinges on a clever manipulation … Read more

How Synthetic Identity Fraud is Coming for Machine Identities

A New Threat Emerges: Synthetic Identity Fraud Targets Machine Identities The latest evolution of identity theft, synthetic identity fraud, is spreading its tentacles into the realm of machine identities, putting organizations and their digital assets at risk. This insidious form of cybercrime has been quietly gaining momentum, with devastating consequences for businesses that fail to … Read more

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

Cybersecurity firm Check Point is scrambling to patch a critical vulnerability in its SmartConsole management platform, allowing attackers with knowledge of the flaw to gain full administrative access to affected systems. The issue, which has been described as “extremely severe,” affects various versions of Check Point’s SmartConsole software used by organizations worldwide. According to the … Read more

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

A nine-year-old Linux flaw, dubbed RefluXFS, has been exposed, allowing local users on default Red Hat Enterprise Linux (RHEL) installs to gain root access without needing a password. The vulnerability, discovered by researchers at CyberNews.work, affects numerous systems worldwide, underscoring the importance of regular security audits and patch management. The flaw resides in the XFS … Read more

Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

Google has introduced a new feature that allows users locked out of their accounts to recover access through facial recognition technology. This move comes after years of criticism over password-related lockouts, which often leave users unable to regain control over their Google services. The introduction of selfie video recovery is part of Google’s ongoing efforts … Read more

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Cybersecurity experts are sounding the alarm after discovering that attackers have exploited GitHub Actions Runners, a popular automation tool, to compromise cPanel and WHM servers on a massive scale. The attack vector leverages a critical vulnerability in the way these tools interact with each other, highlighting the need for increased vigilance in protecting server infrastructure. … Read more