en
DuneSlide: CVE-2026-50548 / CVE-2026-50549 — Zero-Click Prompt Injection to RCE in Cursor IDE
Cato AI Labs discloses DuneSlide: chaining prompt injection to sandbox escape and remote code execution in Cursor IDE.
en
Cato AI Labs discloses DuneSlide: chaining prompt injection to sandbox escape and remote code execution in Cursor IDE.
en
Technical breakdown of the 18-month unpatched zero-authentication RCE in Argo CD enabling full Kubernetes takeover.
en
CVE-2026-8037 (CVSS 9.6) is a pre-auth OS command injection in Kemp LoadMaster rooted in escape_quotes() heap mishandling. watchTowr published a full PoC June 29; exploitation began the same day.
en
How Storm-2603 weaponized a SharePoint deserialization flaw to deploy Warlock ransomware across enterprise networks.
en
Technical analysis of Adobe's emergency bulletin addressing six simultaneous CVSS 10.0 unauthenticated RCE flaws.
en
Weekly briefing: 630GB Apple/Tesla trade secrets leaked, Klue OAuth Salesforce data theft, Cisco UCM webshells, and Atomic Arch.
en
Investigation into Atomic Arch: over 1,500 Arch Linux AUR packages poisoned with eBPF stealth rootkits and credential grabbers.
en
CISA issues urgent warning over critical CVSS 9.8 code injection in Lantronix industrial serial converters.
en
Technical root cause of the Cisco Unified CM SSRF vulnerability exploited in the wild to drop Tor-routed root webshells.
en
How threat group Icarus weaponized Klue OAuth app tokens to silently extract Salesforce data across hundreds of security vendors.
en
How extortion group World Leaks breached Tata Electronics and leaked 630 GB of proprietary Apple and Tesla engineering assets.
en
A week defined by a novel ransomware C2 technique abusing Microsoft's own relay infrastructure, the sixth Cisco SD-WAN zero-day of the year, a coordinated campaign stealing AI API keys from 70,000 developer IDE installs, a supply chain attack backdooring 144 npm packages via a stale contributor account,