Topic: security vulnerability
-
Cursor Origin now default for paid users; data terms undisclosed
Cursor launched Origin, its own code hosting platform, on the same day GitHub suffered a major outage, and while the timing was coincidental, it handed Cursor a significant marketing advantage that most of the internet misreported as deliberate. Origin is designed as a compatible add-on rather th...
Read More » -
Modder breaks GeForce NOW to access Windows desktop
A modder discovered an exploit in Nvidia's GeForce NOW that bypasses the platform's restrictions, allowing access to the underlying Windows desktop and enabling web browsing, app usage, or system tweaks. The method exploits the session's own mechanics rather than external hacks, revealing that th...
Read More » -
Google Pixel August update arrives with bug fixes
Google's August 2026 security update, rolling out today, brings bug fixes, a high-severity video processing vulnerability patch, and Android 17 refinements, with notable performance fixes for the Pixel 10 series including game crashes and touchscreen issues. The update is available in two builds,...
Read More » -
KindaRails2Shell exploit targets Ruby on Rails apps (CVE-2026-66066)
CVE-2026-66066, dubbed "KindaRails2Shell," is a critical Ruby on Rails vulnerability in Active Storage that lets unauthenticated attackers read arbitrary server files via specially crafted image uploads, potentially escalating to remote code execution. The flaw affects Rails apps using the defaul...
Read More » -
Indexed Claude Chats Show Disallow Differs From Noindex
A noindex header exists on Claude's share pages but is hidden behind a robots.txt block, creating a conflict that allows Google to index the URLs if they are linked from other pages. Shared Claude chats and artifacts containing sensitive data like medical information and children's contact inform...
Read More » -
Apple Patches Hide My Email Flaw After Report
Apple fixed a Hide My Email vulnerability in July 2026 after being aware of it for over a year, which could have exposed users' real email addresses when emails were rejected as spam. The flaw was discovered by Tyler Murphy, who found that 100% of tested Hide My Email addresses were exploitable, ...
Read More » -
Apple Sued Over Alleged 'Hide My Email' Security Flaw
Apple is facing a class action lawsuit alleging its Hide My Email feature has a security flaw that can expose users' real email addresses, violating California's false advertising and consumer protection laws. The vulnerability was reported to Apple in June 2025, but there are no confirmed cases ...
Read More » -
Anthropic's Claude Fable 5 Returns With Stricter Usage Limits
Anthropic's Claude Fable 5 launched globally on July 1, with a separate Mythos version available to select US organizations, following US government approval and collaboration with Secretary Howard Lutnick. A new classifier resolves the vulnerability reported by Amazon, catching 99% of malicious ...
Read More » -
Fortibleed Campaign Impact on FortiGate Firewall Users
The Fortibleed credential-harvesting campaign targeted FortiGate firewalls, exploiting vulnerabilities to steal login credentials from high-value organizations like government agencies and critical infrastructure providers. Attackers inadvertently left a server exposed, revealing their tools, scr...
Read More » -
New Windows Zero-Day ‘RoguePlanet’ Exploit Goes Live
A newly disclosed Windows zero-day exploit called ‘RoguePlanet’ targets a race condition in Microsoft Defender, enabling local privilege escalation to SYSTEM-level access. The exploit allows an attacker with limited privileges to execute code with elevated permissions, bypassing security boundari...
Read More » -
Critical Gogs RCE Bug Enables Code Execution for Any Authenticated User
A critical unpatched vulnerability in Gogs (CVSS 9.4) allows any authenticated user to achieve remote code execution by crafting a malicious branch name that injects the `--exec` flag into the `git rebase` command during a rebase merge operation. The exploit requires no admin privileges or user i...
Read More » -
Exploit released for new DirtyDecrypt Linux root flaw
A proof-of-concept exploit called DirtyDecrypt has been released for a Linux kernel privilege escalation vulnerability (CVE-2024-xxxxx) in the rxgk module, allowing attackers to gain full root access on unpatched systems. The vulnerability involves a race condition or memory corruption in cryptog...
Read More » -
Yarbo to remove intentional backdoor from its robot lawn mower
Yarbo reversed its initial stance and now plans to fully eliminate the remote backdoor access that could allow hackers to control its lawn mowers, making it an opt-in feature that customers can choose to install only if they want remote assistance. The company initially resisted removing the back...
Read More » -
Dental Software Patch Secures Exposed Patient Records
A patient discovered a security vulnerability in the Practice by Numbers dental patient management platform, allowing unauthorized access to other patients' sensitive documents by simply altering sequential document numbers in the web address. After the company ignored initial reports, TechCrunch...
Read More » -
PlayStation mandates one-time online check to verify game ownership
Sony clarified that only a one-time online check is required to verify game ownership on PS4 and PS5, contradicting rumors of a recurring monthly internet requirement. The confusion began after a content creator flagged potential DRM changes on April 24th, with screenshots showing a 30-day timer ...
Read More » -
Robinhood account flaw exploited in phishing email attacks
Attackers exploited a flaw in Robinhood's account creation process to inject malicious HTML into legitimate emails from [email protected], which passed SPF and DKIM authentication checks, making the phishing messages appear authentic. The phishing emails claimed an unrecognized device had bee...
Read More » -
Microsoft Defender RedSun Zero-Day Exploit Gains SYSTEM Access
A researcher named "Chaotic Eclipse" has released a second exploit, called RedSun, targeting Microsoft Defender to gain SYSTEM-level access on Windows, protesting Microsoft's security community engagement policies. The exploit works by corrupting a core Defender component, allowing an attacker to...
Read More » -
McGraw-Hill Data Breach Confirmed After Extortion Threat
A cybercriminal group breached McGraw Hill by exploiting a misconfiguration in its Salesforce environment, highlighting the threat of third-party software vulnerabilities. The company confirmed the breach did not compromise student-facing platforms or sensitive student data; only internal corpora...
Read More » -
Hackers Expose 93GB of Anonymous Crime Tip Data
P3 Global Intel, a company providing secure tip management software for law enforcement, suffered a major data breach, with approximately 93 gigabytes of sensitive data stolen and leaked by a hacker group. The leaked data includes highly sensitive personal information on individuals named by tips...
Read More » -
Mazda Employee and Partner Data Exposed in Security Breach
Mazda disclosed a security breach from December involving a vulnerable warehouse management system, which exposed 692 records of employee and partner data but no customer information. The compromised data included user IDs, names, email addresses, and company details; Mazda reported the incident ...
Read More »