Aggregator
CVE-2026-11008 | Google Chrome up to 148.0.7778.216 WebAppInstalls cross-domain policy (ID 495864 / Nessus ID 319287)
CVE-2026-11149 | Google Chrome up to 148.0.7778.216 Extensions input validation (ID 501739 / Nessus ID 319285)
CVE-2026-11171 | Google Chrome up to 148.0.7778.216 Blink external control of assumed-immutable web parameter (ID 502322 / Nessus ID 319286)
CVE-2026-11076 | Google Chrome up to 148.0.7778.216 CSS type confusion (ID 499784 / Nessus ID 319289)
Parasitic Bandwidth: How Free Applications Convert Domestic Smart TVs into Residential Proxies
Free mobile or Smart TV software often serves secondary, hidden purposes. Specifically, games, streaming utilities, or screensavers may secretly harbor the Bright Data SDK. This silent component integrates a domestic internet connection into a...
The post Parasitic Bandwidth: How Free Applications Convert Domestic Smart TVs into Residential Proxies appeared first on Information Security News.
The Automated Vulnerability Surge: AI Diagnostics and the Remediation Bottleneck
Artificial intelligence agents excel at identifying legacy software vulnerabilities rapidly and economically. However, the subsequent remediation lifecycle still demands arduous human intervention. Maintainers must manually validate findings, replicate system failures, and author code patches....
The post The Automated Vulnerability Surge: AI Diagnostics and the Remediation Bottleneck appeared first on Information Security News.
CVE-2022-32940 | Apple watchOS up to 9.0.2 AVEVideoEncoder buffer overflow (HT213491 / EUVD-2022-36006)
CVE-2022-32940 | Apple tvOS up to 16.0 AVEVideoEncoder buffer overflow (HT213492 / EUVD-2022-36006)
CVE-2022-32940 | Apple macOS AVEVideoEncoder memory corruption (HT213488 / EUVD-2022-36006)
CVE-2022-32940 | Apple iOS/iPadOS AVEVideoEncoder buffer overflow (HT213489 / EUVD-2022-36006)
CVE-2022-32939 | Apple iOS/iPadOS Kernel memory corruption (EUVD-2022-36005)
Sovereign Intrusion: Deconstructing the FalkonC2 Commercial Command Framework
Corporate networks rarely fall victim to indiscriminate assaults. Instead, most breaches leverage meticulously calibrated arsenals specifically engineered for precise targets. Recently, threat analysts at Flare identified FalkonC2. This commercial command-and-control framework facilitates remote management...
The post Sovereign Intrusion: Deconstructing the FalkonC2 Commercial Command Framework appeared first on Information Security News.
CVE-2022-32938 | Apple macOS Shortcuts information disclosure (HT213488 / EUVD-2022-36004)
Hackers Can Hijack Claude Code MCP Traffic to Steal OAuth Tokens
A five-step attack chain that silently redirects Claude Code’s Model Context Protocol (MCP) traffic through attacker-controlled infrastructure, intercepting OAuth bearer tokens that grant persistent, broadly scoped access to connected SaaS platforms like Jira, Confluence, and GitHub with no patch incoming from Anthropic. Researchers at Mitiga Labs have demonstrated the attack, with the entry point being […]
The post Hackers Can Hijack Claude Code MCP Traffic to Steal OAuth Tokens appeared first on Cyber Security News.
Persistent Espionage: Covert Campaign Targets Global Stock Exchange Executive
For five months, sophisticated threat actors covertly exfiltrated the correspondence of a prominent global stock exchange executive. According to Symantec, the campaign focused relentlessly on a singular objective. Specifically, the adversaries sought continuous access...
The post Persistent Espionage: Covert Campaign Targets Global Stock Exchange Executive appeared first on Information Security News.
QuadRF: 4-Element Beamforming SDR Tile Coming to Crowd Supply
Cryptographic Stealth: The BYORWXDLL Technique Bypasses EDR Controls via Signed Libraries
The novel BYORWXDLL technique injects code into Windows processes by leveraging existing memory regions within legitimate, signed DLLs. Consequently, this method sharply reduces the number of anomalous operations tracked by Endpoint Detection and Response...
The post Cryptographic Stealth: The BYORWXDLL Technique Bypasses EDR Controls via Signed Libraries appeared first on Information Security News.
The WeedHack Contagion: Malicious Minecraft Modifications Deploy Large-Scale Infiltration
The insidious WeedHack malware campaign has transformed popular Minecraft modifications into vectors for widespread system compromise. Consequently, McAfee Labs investigators have documented over 116,000 compromised devices since January 2026. Furthermore, daily infection metrics currently...
The post The WeedHack Contagion: Malicious Minecraft Modifications Deploy Large-Scale Infiltration appeared first on Information Security News.