Tag: injection
-
PHP Patches 3 Security Flaws Enabling SQL Injection, Memory Corruption and DoS Attacks
PHP maintainers have released security updates to address three vulnerabilities affecting the PostgreSQL, BCMath, and Phar extensions. These vulnerabilities could potentially lead to SQL injection attacks, out-of-bounds memory writes, and denial-of-service attacks in vulnerable applications. The issues impact several actively maintained PHP release branches and have been resolved in versions PHP 8.2.338.2, 8.3.338.3, 8.4.248.4, and…
-
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild.The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution.”VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue First…
-
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/
-
Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code
Tags: apache, authentication, cve, cyber, flaw, injection, remote-code-execution, service, sql, vulnerabilityApache Syncope has released versions 4.1.24.1, 4.1.24.1.2, and 4.0.74.0.7 to address six security vulnerabilities affecting the 4.1, 4.0, and 3.0 release branches. These vulnerabilities include a self-service privilege escalation bug, multiple post-authentication remote code execution (RCE) pathways, authenticated server-side request forgery (SSRF), and SQL injection issues. Apache Syncope Flaws CVE-2026-62183 affects deployments that utilize the…
-
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
Most of this week’s trouble came dressed as something useful.A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic. The threats change every week. Subscribe, and we’ll alert you…
-
Mobile Synthetic Identity Scams Can Outscore Real Borrowers
Point Predictive’s Matt Vega on Detecting Identity Fraud and $30 Liveness Kits. Injection kits selling for about $30 enable fraud rings hot-wire a mobile device’s camera feed or inject a deepfake stream into the verification process, bypassing checks many institutions still rely on, said Matt Vega, chief fraud strategist at Point Predictive. First seen on…
-
Künstliche Intelligenz hat Hugging Face nicht an Cleverness übertroffen, sie hat das Mittelmaß optimiert
Die in der Diskussion stehende Attacke einer OpenAI-KI auf Hugging Face hat eine Zero-Day-Lücke in einem Package-Registry-Proxy ausgenutzt, um die Isolation zu durchbrechen. Die KI eskalierte in der Folge Privilegien, startete Seitwärtsbewegungen und erreichte so einen Knotenpunkt mit Internetzugang. Sie nutzte einen bösartigen Datensatz, um über unsichere Loader und Template-Injection die Ausführung von Remote-Code auszulösen.…
-
Microsoft Adds Prompt Injection Protection to Defender for Office 365
Microsoft has introduced prompt injection protection in Defender for Office 365, representing a significant advancement in securing enterprise email environments against emerging AI-targeted threats. As organizations increasingly adopt AI assistants like Microsoft 365 Copilot to summarize, triage, and respond to emails, attackers are shifting their tactics from traditional phishing methods to manipulating AI systems directly.…
-
Azure DevOps Prompt Injection Targets AI Coding Agents
Hidden prompt injections in Azure DevOps can manipulate AI coding agents into accessing sensitive data using a developer’s permissions. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/azure-devops-prompt-injection-targets-ai-coding-agents/
-
CISA Warns WordPress Core SQL Injection Vulnerability Is Actively Exploited in Attacks
Tags: attack, cisa, cve, cyber, cybersecurity, exploit, infrastructure, injection, kev, sql, vulnerability, wordpressThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has classified a critical SQL injection vulnerability in WordPress Core, tracked as CVE-2026-60137, as one of its Known Exploited Vulnerabilities (KEV) due to its active exploitation in real-world attacks. This vulnerability affects the core functionality of WordPress when themes or plugins fail to properly validate untrusted input…
-
Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws
Zimbra has released version 10.1.20 of its Collaboration Suite (ZCS) to address multiple high-severity security vulnerabilities. This release includes a critical command injection flaw in the SNMP monitoring component and several cross-site scripting (XSS) issues affecting the Classic Web Client. The update, published on July 20, 2026, provides a permanent fix for a previously disclosed…
-
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
A single invisible comment in an Azure DevOps pull request can turn a reviewer’s own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds.The flaw is in Microsoft’s official Azure DevOps MCP server, and it works because one of its tools returns…
-
Zimbra 10.1.20 patches multiple security issues, including a critical command injection bug
Zimbra patched nine flaws in version 10.1.20, including a critical SNMP monitoring command injection issue enabling arbitrary command execution. Zimbra released version 10.1.20 to fix nine security vulnerabilities, including a critical command injection flaw in the SNMP monitoring component. The vulnerability affects systems with SNMP notifications enabled and could allow attackers to execute arbitrary commands.…
-
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component.As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled.Also patched…
-
SSRF und Code Injection – SonicWall warnt vor Zero-Day-Angriffen auf SMA1000-Serie
First seen on security-insider.de Jump to article: www.security-insider.de/sonicwall-sma1000-zero-day-ssrf-code-injection-aktiv-ausgenutzt-a-8f7983e5666a6c63dc3fb556e9e6c379/
-
GPT-5.6 Sol Ultra Discovers WordPress Pre-Auth SQL Injection Leading to RCE
Tags: authentication, cyber, exploit, flaw, injection, rce, remote-code-execution, sql, vulnerability, wordpressA critical vulnerability chain in WordPress, called wp2shell, that allegedly allows unauthenticated attackers to exploit a pre-authentication SQL injection flaw to achieve remote code execution (RCE) on typical WordPress installations running MySQL. Security researcher Adam Kues discovered this vulnerability chain using GPT-5.6 Sol Ultra during a multi-agent audit of the WordPress source code. GPT-5.6 Sol…
-
Prompt Injection Attacks Are Thwarting AI Hacking Agents
“Context bombing” tricks malicious AI agents into shutting down before they can do harm. First seen on wired.com Jump to article: www.wired.com/story/prompt-injection-attacks-are-thwarting-ai-hacking-agents/
-
CISA Adds FortiSandbox Bugs to KEV Catalog
Agencies Have Until Sunday to Patch Two Critical Command Injection Flaws. CISA added two critical FortiSandbox command injection vulnerabilities to its Known Exploited Vulnerabilities catalog after evidence of active attacks. Experts warn that unauthenticated remote code execution could let attackers compromise malware analysis systems and pivot deeper into enterprise networks. First seen on govinfosecurity.com Jump…
-
Prompt injection is becoming the XSS of the web agent era
Autonomous web agents read whatever a page displays, and much of that content comes from strangers. Product reviews, seller listings, and advertisements sit beside trusted … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/17/xss-web-agent-prompt-injection/
-
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click “Buy Now” instead. Ask a coding assistant to apply a maintainer’s fix from a GitHub thread, and a fake comment can make it run a stranger’s command on your computer.Neither trick hijacks the agent’s…
-
Hackers Exploit SonicWall SMA1000 Zero-Days to Execute Commands as Root
Hackers are actively exploiting two zero-day vulnerabilities in the SonicWall SMA 1000 Series remote access appliances. They are chaining a critical server-side request forgery flaw with a local code injection bug to execute commands with root privileges. Rapid7’s Managed Detection and Response team detected targeted attacks before SonicWall publicly disclosed these vulnerabilities on July 14,…
-
OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol
OpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery with an aim to fix issues before the tools are deployed widely.”GPT”‘Red is a strong red-teamer, and our previous models are highly vulnerable to its prompt injection attacks,” the artificial intelligence (AI) company said. “We use GPT”‘Red to…
-
Now, defenders are embracing the prompt injection, too
“Context bombing” tricks hacking agents into shutting down before they can do harm. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/now-defenders-are-embracing-the-prompt-injection-too/
-
Operation Capsule Vault Uses Malicious ISO Files and Process Injection to Deliver RokRAT
Operation Capsule Vault began with spear-phishing emails sent on June 22, 2026, posing as notices distributing materials from a legitimate academic event. The lures referenced the “Why Wonsan-Kalma Tourism Now?” conference, held at Seoul COEX on June 12, and incorporated publicly available event details, including its subject matter and host organizations. By reusing real-world conference…
-
New GhostCommit Technique Hides Exploits in Images to Evade AI Code Reviewers
Researchers have revealed a technique called >>GhostCommit,<< which involves prompt injection by hiding malicious instructions within images included in pull requests. This technique has the potential to bypass text-only AI code reviewers and later manipulate coding agents into exposing repository secrets. The ASSET Research Group explained that this technique leverages the widening gap between automated…
-
Claude AI Prompt Injection Attack Turns Chatbot Into Stealthy C2 Agent to Achieve Remote Code Execution
Claude Desktop’s synced Personal Preferences feature can be exploited as a covert prompt-injection vector, transforming the AI assistant into a de facto command-and-control (C2) agent. This method allows for remote code execution on a compromised user workstation without the need for phishing emails or traditional malware delivery. In this attack chain, the initial access is…
-
Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation
Ubiquiti patched seven UniFi OS flaws, including critical CVE-2026-50746, which allows command injection in UniFi Connect Application. Ubiquiti released security updates for seven critical UniFi OS vulnerabilities, including a maximum-severity flaw, tracked as CVE-2026-50746 (CVSS score of 10.0), enabling command injection attacks. The issue affects UniFi Connect Application versions 3.4.16 and earlier, a platform used…

