Aggregator
CVE-2026-7315 | eiceblue spire-pdf-mcp-server 0.1.1 PDF File server.py get_pdf_path filepath path traversal (EUVD-2026-26152)
CVE-2026-7316 | eiliyaabedini aider-mcp up to 667b914301aada695aab0e46d1fb3a7d5e32c8af code_with_ai aider_mcp.py working_dir/editable_files command injection (EUVD-2026-26153)
CVE-2026-7317 | Grav CMS up to 1.7.49.5/2.0.0-beta.1 Cache Value FileCache.php FileCache::doGet deserialization (GHSA-gwfr-jfjf-92vv / c66dfeb5f)
CVE-2026-7318 | elie mcp-project 0.1.0 research_server.py search_papers topic path traversal (EUVD-2026-26155)
CVE-2026-7319 | elinsky execution-system-mcp 0.1.0 add_action Tool server.py _get_context_file_path context path traversal (EUVD-2026-26156)
CVE-2026-42428 | OpenClaw up to 2026.4.7 integrity check (GHSA-3vvq-q2qc-7rmp / EUVD-2026-26130)
Everest
You must login to view this content
FIDO Alliance wants to keep AI agents from going rogue on online payments
AI agents are beginning to shop, log in, and complete tasks with little direct input. That shift is pushing the security industry to rethink how trust works when actions are carried out on a user’s behalf. The FIDO Alliance has announced a set of initiatives to build shared standards for these interactions, covering how AI agents authenticate, follow instructions, and carry out transactions. “AI agents are quickly becoming part of how people get things done … More →
The post FIDO Alliance wants to keep AI agents from going rogue on online payments appeared first on Help Net Security.
M3RX
You must login to view this content
M3RX
You must login to view this content
Spy agency officials say job loss anxiety, moving fast ‘safely’ among top challenges in AI workforce overhaul
While tech leaders think about how to strategically deploy AI tools to support human intelligence needs, rank and filers express concerns about their livelihoods.
The post Spy agency officials say job loss anxiety, moving fast ‘safely’ among top challenges in AI workforce overhaul appeared first on CyberScoop.
BlueNoroff Uses Fake Zoom Calls to Turn Victims Into Attack Lures
New DHL Phishing Scam Uses 11-Step Attack Chain to Steal Passwords
Broken VECT 2.0 ransomware acts as a data wiper for large files
Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw
Webinar | The Next Wave of Identity Risk: Securing Non Human Identities in an AI Driven World
Good Riddance to Passwords: Officials Urge Passkeys Instead
Forget passwords: British cybersecurity officials now recommend using digital passkeys whenever they're available, finding that passkeys offer better and faster security, with lower costs for services that provide them, compared to widely despised passwords.
How AI Drives Shift to Continuous Pen Testing at Evinova
Continuous pen testing has replaced static annual tests and is reshaping how Evinova, a technology company of AstraZeneca, is managing cyber risk in its fast-moving cloud environment, said Adeeb Mahmood of Evinova and Shahar Peled of Terra Security, who describe the transition.
Germany Caught Up in Likely Russian Signal Phishing
Signal is defending the security of its systems following a series of phishing attacks that took place on the encrypted messaging platform, and that reportedly compromised members of the German government including the president of the country's parliament.