DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

A flaw in DeepSeek Harness, DeepSeek’s open-source tool for running AI coding agents on a developer’s machine, let a sandboxed agent turn off its own sandbox with a single command.

The tool runs an agent’s commands inside an operating-system sandbox, … Continue reading DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

Posted in Uncategorized

Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet.

Alby Hub is a self-hosted Lig… Continue reading Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

Posted in Uncategorized

U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting “systematic extraction” of proprietary functionalities and capabilities of American frontier models through distillation attacks…. Continue reading U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

Posted in Uncategorized

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild.

The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been des… Continue reading Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Posted in Uncategorized

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run… Continue reading New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

Posted in Uncategorized

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7.

When Apache loads any of the three appliances’ own PHP sc… Continue reading F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

Posted in Uncategorized

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender.

The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also… Continue reading Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

Posted in Uncategorized

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application

T… Continue reading SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

Posted in Uncategorized