CISA sets urgent deadline to fix Cisco flaw exploited in attacks

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies to patch two recently discovered vulnerabilities within a tight deadline. The flaws, one of which is already being actively exploited by attackers, put sensitive systems at risk of compromise. A server-side request forgery (SSRF) vulnerability in Cisco’s Unified Communications … Read more

FBI: Russian hackers now target Signal backup recovery keys

Russian Hackers Evolve Tactics to Steal Signal Backup Recovery Keys, Exposing Users’ Historical Messages A phishing campaign targeting Signal users tied to Russian intelligence services has taken a concerning turn. The FBI and CISA have issued an updated public service announcement warning that hackers are now attempting to steal Signal Backup Recovery Keys, granting them … Read more

Clean GitHub repo tricks AI coding agents into running malware

A newly discovered vulnerability in AI-powered coding tools has left security experts sounding the alarm. Researchers at Mozilla’s Zero Day Investigative Network (0DIN) have demonstrated a method by which an attacker can plant malware on a developer’s device without leaving any suspicious code or exploit in the repository. The attack relies on a seemingly innocuous-looking … Read more

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

A Critical Flaw in Amazon Q Developer Platform Exposes Users to Malicious Repositories Amazon Web Services (AWS) has acknowledged a significant vulnerability in its Q developer platform, which could allow malicious users to run code on affected accounts via configuration files. The flaw, discovered by security researchers, affects users who have enabled the Model Customization … Read more

New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries

A Critical Linux Exploit Has Been Uncovered, Granting Root Access to Attackers A devastating security vulnerability has been discovered in various Linux distributions, allowing attackers to gain root access by manipulating cached binaries. Dubbed a “COW” (Copy-On-Write) exploit, this flaw can be exploited remotely, making it a pressing concern for system administrators and users alike. … Read more