Tag: software
-
China-Nexus Threat Actor Targeting Critical VMware Flaw
A China-nexus bad actor is likely behind the rapid exploitation of a critical flaw in VMware’s vCenter management software that has spread across 361 victim IP addresses in almost four dozen countries. Exploitation of the vulnerability tracked as CVE-2026-59310 started five days after VMware owner Broadcom first disclosed the security flaw July 29,.. First seen…
-
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data.The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of…
-
Poland probes MyDr healthcare software breach potentially affecting 19 million people
MyDr, a privately-owned Polish company that supplies software to doctors, clinics and other healthcare providers, said on Friday that it had identified and removed the cause of the incident and introduced additional security measures. First seen on therecord.media Jump to article: therecord.media/poland-probes-mydr-healthcare-software-breach
-
LiteLLM Attack Shows AI Infrastructure Is Becoming a Strategic Software Supply Chain Target
Tags: ai, attack, breach, cloud, credentials, cyber, infrastructure, malicious, pypi, software, supply-chain, theftThe March 2026 compromise of LiteLLM was more than a short-lived malicious PyPI upload. It demonstrated how an upstream breach in developer tooling can turn AI infrastructure into a high-value conduit for credential theft, cloud intrusion, and downstream software supply chain abuse. The packages were available for roughly 40 minutes before quarantine, but their brief…
-
Kein Klick nötig: PlugPwn-Angriff kapert Windows-Systeme per USB
Windows lädt beim Anschließen neuer USB-Geräte oft Software nach. Angreifer können dadurch Systemrechte erlangen – manchmal sogar aus der Ferne. First seen on golem.de Jump to article: www.golem.de/news/kein-klick-noetig-plug-and-pwn-angriff-kapert-windows-systeme-per-usb-2608-211809.html
-
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine.The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB…
-
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform’s plugins team to temporarily disable their downloads.”Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository,” Wordfence researcher Paolo Tresso said. First seen on thehackernews.com Jump to…
-
An AI tool found 84 flaws in 5G network software and 23 of them still have no fix
Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/11/5g-core-network-vulnerabilities-research/
-
Kostenlose Software ist nicht immer risikofrei: Was Nutzer vor dem Download wissen sollten
Tags: softwareShareware und Freeware wirken ähnlich, weil beide zunächst kostenlos verfügbar sind. Doch sie funktionieren unterschiedlich und können Nutzer versteckten Sicherheitsrisiken aussetzen. Shareware ist Software, die Nutzer für eine bestimmte Zeit oder mit eingeschränkten Funktionen kostenlos testen können, bevor sie für die Vollversion bezahlen. Freeware kann dagegen dauerhaft kostenlos genutzt werden, auch wenn der Entwickler… First…
-
Gym Booking Task Turns Into Real-World AI Cyberattack
An AI agent hacked a gym booking system while trying to help a user, booking early and removing another person from the waitlist. An Australian man asked his AI assistant to book him into a gym class. He didn’t ask it to hack the booking software, and he definitely didn’t ask it to remove another…
-
NATO and an AI startup can now name and track software vulnerabilities
Tags: ai, communications, cyber, cybersecurity, defense, flaw, intelligence, software, startup, vulnerabilityNATO’s cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws, the European Union Agency for Cybersecurity announced last week. The NATO Cyber Security Centre, part of the NATO Communications and Information Agency, and AISLE, a cybersecurity company…

