» Tag
vulnerability
45 postsPromptFiction Flaw: Auto-Submitted Hidden Prompts in Claude Desktop
Oasis Security's research uncovered the PromptFiction flaw in Claude Desktop, enabling commands to be executed without user approval.
The Advisory Said It Was Fixed. I Didn't Believe It Until I Broke It Myself.
An engineer tested the CVE-2026-39973 vulnerability in apktool, emphasizing the importance of real testing over mere advisories.
Insecure Argument Handling in Tailscale SSH Allowed Root Access
A vulnerability in Tailscale SSH allowed root access via usernames with a leading '-'. Upgrade recommended.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comAI Discovered a Linux Bug Missed for 15 Years
AI has identified a bug in the Linux kernel that has existed for 15 years. This discovery is critical for system security.
Docker Hypervisor Sandbox Escape Patched
Docker patched a sandbox escape in its Mac hypervisor. Details on CVE-2026-77179 and affected versions are included.
AutoGPT Email Block: SSRF Vulnerability and Its Implications
The SSRF vulnerability in AutoGPT's `SendEmailBlock` feature allows internal network scanning and service information exfiltration.
0-day security update available for Metabase
Update your Metabase instance following the newly discovered 0-day vulnerability.
Cursor 0day: When Full Disclosure Becomes the Only Protection Left
A critical vulnerability in Cursor IDE allows automatic execution of malicious git.exe files, posing significant risks for users.
Spectre Bug Returns, This Time Haunting JIT Engines
The Spectre vulnerability reemerges, threatening JIT engines with new attack vectors. Researchers highlight risks of sensitive data leakage.
Deepsec: On-Demand Vulnerability Scanning for Your Infrastructure
Deepsec is an agent-powered vulnerability scanner optimized for uncovering security issues.