» Tag
vulnerability
39 postsAI Uncovers 15-Year-Old Root Vulnerability in Linux Kernel
GhostLock (CVE-2026-43499): AI tool VEGA found a 15-year-old use-after-free root exploit in Linux kernel futex code. What engineers need to patch now.
RovoBlast: One Click Turns Atlassian's AI Assistant Into a Data Leak
Varonis details RovoBlast, a one-click prompt injection flaw in Atlassian's Rovo AI assistant that can expose sensitive enterprise data.
Microsoft Secure Boot Flaw Persisted for 13 of Its 14 Years
ESET researchers find a Secure Boot vulnerability that went unpatched for 13 years, letting old signed shims bypass UEFI firmware protection.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comShark Vacuum AWS Cert Flaw Lets One Key Hijack an Entire Fleet's Root Shell
A stolen AWS certificate lets attackers run root commands on any Shark robot vacuum in the same cloud region, exposing cameras and Wi-Fi credentials.
GhostApproval: A symlink flaw undermining trust in AI coding assistants
Researchers found a symlink-based flaw in six major AI coding assistants, where approval dialogs hide the real file target, undermining human oversight.
Critical Auth Bypass in Gitea Docker Images Exposed
Learn about the critical authentication bypass in Gitea Docker images. Update promptly to enhance your security.
Hacker with a vendetta against Microsoft reveals new zero-day exploit
Nightmare Eclipse has unveiled ShieldBreak, a new zero-day exploit granting SYSTEM privileges on Windows systems.
VulnHunter: Proactive AI Security Tool
VulnHunter is an open-source AI security tool that detects vulnerabilities through proactive analysis.
Exim CVE-2026-45185 — Unauthenticated RCE in the World's Most Deployed Mail Server
CVE-2026-45185 exposes Exim to unauthenticated remote code execution. Upgrade to version 4.99.3 to secure affected systems.
Google Pays $250K for 16-Year-Old Linux KVM Escape Flaw
Dubbed Januscape, a Linux KVM flaw lets guest VMs break out and hijack the host. Google awarded the discovering researcher a $250,000 bug bounty.