#securityvulnerabilities — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #securityvulnerabilities, aggregated by home.social.
-
JFrog Security Research has disclosed PixelSmash - a 16-year-old FFmpeg vulnerability that can enable Remote Code Execution (RCE) and Denial of Service (DoS) attacks.
The flaw impacts desktop video players, cloud media pipelines, and media servers.
Learn who's affected and how to patch it 👉 https://bit.ly/4g8bn5h
-
JFrog Security Research has disclosed PixelSmash - a 16-year-old FFmpeg vulnerability that can enable Remote Code Execution (RCE) and Denial of Service (DoS) attacks.
The flaw impacts desktop video players, cloud media pipelines, and media servers.
Learn who's affected and how to patch it 👉 https://bit.ly/4g8bn5h
-
https://winbuzzer.com/2026/07/06/ai-bug-hunters-coincide-with-record-cve-disclosures-xcxwbn/
Epoch AI data points to a record June surge in public software-flaw disclosures as AI bug-hunting expands, but the data cannot prove which flaws AI found.
#AI #SecurityVulnerabilities #Cybersecurity #SecurityResearch #OpenAI #Anthropic #ClaudeMythos #ProjectGlasswing #OpenAIDaybreak
-
https://winbuzzer.com/2026/07/06/ai-bug-hunters-coincide-with-record-cve-disclosures-xcxwbn/
Epoch AI data points to a record June surge in public software-flaw disclosures as AI bug-hunting expands, but the data cannot prove which flaws AI found.
#AI #SecurityVulnerabilities #Cybersecurity #SecurityResearch #OpenAI #Anthropic #ClaudeMythos #ProjectGlasswing #OpenAIDaybreak
-
Arm has open-sourced Metis - an #AgenticAI security framework built to autonomously identify complex software vulnerabilities.
Metis uses semantic reasoning to analyze cross-component dependencies and provides clear, natural language explanations for its findings.
🔗 Learn more: https://bit.ly/4uTai7o
#InfoQ #AI #OpenSource #LLMs #AIagents #SecurityVulnerabilities
-
Arm has open-sourced Metis - an #AgenticAI security framework built to autonomously identify complex software vulnerabilities.
Metis uses semantic reasoning to analyze cross-component dependencies and provides clear, natural language explanations for its findings.
🔗 Learn more: https://bit.ly/4uTai7o
#InfoQ #AI #OpenSource #LLMs #AIagents #SecurityVulnerabilities
-
https://winbuzzer.com/2026/06/03/toronto-ai-worm-prototype-tests-adaptive-malware-risk-xcxwbn/
Researchers built a contained AI powered malware worm that adapts attacks across lab hosts, exposing how local open-weight models complicate malware containment.
#AI #AIAgents #AISecurity #AIResearch #Cybersecurity #Malware #SecurityVulnerabilities #CyberThreats #SecurityResearch
-
https://winbuzzer.com/2026/06/03/toronto-ai-worm-prototype-tests-adaptive-malware-risk-xcxwbn/
Researchers built a contained AI powered malware worm that adapts attacks across lab hosts, exposing how local open-weight models complicate malware containment.
#AI #AIAgents #AISecurity #AIResearch #Cybersecurity #Malware #SecurityVulnerabilities #CyberThreats #SecurityResearch
-
GitHub's Copilot app is here to help developers write better code with AI... because apparently, human intelligence is just too old-fashioned 🧠🤖. It's like having a backseat driver for coding, but this one loves to remind you of security vulnerabilities you never asked for 🚨🔐. Who knew that merging issues could be so... automated? 😏
https://github.com/features/preview/github-app #GitHubCopilot #AIinCoding #DeveloperTools #CodeAutomation #SecurityVulnerabilities #HackerNews #ngated -
GitHub's Copilot app is here to help developers write better code with AI... because apparently, human intelligence is just too old-fashioned 🧠🤖. It's like having a backseat driver for coding, but this one loves to remind you of security vulnerabilities you never asked for 🚨🔐. Who knew that merging issues could be so... automated? 😏
https://github.com/features/preview/github-app #GitHubCopilot #AIinCoding #DeveloperTools #CodeAutomation #SecurityVulnerabilities #HackerNews #ngated -
Two recent #Linux kernel vulnerabilities have been disclosed:
➡️ Copy Fail (CVE-2026-31431)
➡️ Dirty Frag (CVE-2026-43284 & CVE-2026-43500)Both vulnerabilities exploit flaws in the page cache via different subsystems, necessitating immediate patching by affected organizations.
More details on #InfoQ ➡️ https://bit.ly/4dHOx47
-
Two recent #Linux kernel vulnerabilities have been disclosed:
➡️ Copy Fail (CVE-2026-31431)
➡️ Dirty Frag (CVE-2026-43284 & CVE-2026-43500)Both vulnerabilities exploit flaws in the page cache via different subsystems, necessitating immediate patching by affected organizations.
More details on #InfoQ ➡️ https://bit.ly/4dHOx47
-
An attacker purchased the entire Essential Plugin portfolio - 30+ WordPress plugins with ~400k installs - on Flippa.
➡️ First code commit introduced a PHP deserialization backdoor
➡️ Dormant for 8 months
➡️ Activated in April 2026, injecting cloaked SEO spam across thousands of sites.
➡️ WordPress shut down all 31 plugins in a single dayFind out more: https://bit.ly/4u9pJb9
-
An attacker purchased the entire Essential Plugin portfolio - 30+ WordPress plugins with ~400k installs - on Flippa.
➡️ First code commit introduced a PHP deserialization backdoor
➡️ Dormant for 8 months
➡️ Activated in April 2026, injecting cloaked SEO spam across thousands of sites.
➡️ WordPress shut down all 31 plugins in a single dayFind out more: https://bit.ly/4u9pJb9
-
🍎🥕 'Carrot Disclosure'? More like 'Carrot Top's Comedy Hour' — turns out, if you squint hard enough at Forgejo's security, it looks like Swiss cheese. 🤦♂️ Fedora's move just opened Pandora's Box of the Tech World's most nuanced vulnerabilities, perfect for those who want their software to be 'edgy'... literally. 🧀🔓
https://dustri.org/b/carrot-disclosure-forgejo.html #CarrotDisclosure #SwissCheese #SecurityVulnerabilities #FedoraTech #EdgySoftware #HackerNews #ngated -
🍎🥕 'Carrot Disclosure'? More like 'Carrot Top's Comedy Hour' — turns out, if you squint hard enough at Forgejo's security, it looks like Swiss cheese. 🤦♂️ Fedora's move just opened Pandora's Box of the Tech World's most nuanced vulnerabilities, perfect for those who want their software to be 'edgy'... literally. 🧀🔓
https://dustri.org/b/carrot-disclosure-forgejo.html #CarrotDisclosure #SwissCheese #SecurityVulnerabilities #FedoraTech #EdgySoftware #HackerNews #ngated -
Oh also, you have to be living under a cyber rock to have missed the recent hoopla around #ProjectGlasswing and #Mythos. This is not the end of the story. The AI landscape is vast and evolving and our challenge to you is to tell or show us something about #AI and #securityvulnerabilities that we haven’t already seen or heard…
-
Oh also, you have to be living under a cyber rock to have missed the recent hoopla around #ProjectGlasswing and #Mythos. This is not the end of the story. The AI landscape is vast and evolving and our challenge to you is to tell or show us something about #AI and #securityvulnerabilities that we haven’t already seen or heard…
-
AI Vendors Downplay Role in Security Vulnerabilities
AI vendors are caught in a contradictory spin cycle, urging companies to rely on AI to combat threats while downplaying security flaws, leaving customers wondering who's truly responsible for safeguarding their systems. When vulnerabilities arise, these vendors often claim it's simply their AI working as intended - a…
#AiSecurity #ArtificialIntelligence #VendorManagement #SecurityVulnerabilities #EmergingThreats
-
Log4Shell - Spring4Shell - The XZ Backdoor
These aren't just headlines - they are wake-up calls! As the software ecosystem grows more complex, the question remains: Are we ready for the next #CyberSecurity crisis?
In this #InfoQ video, Soroosh Khodami shares practical strategies to secure your development lifecycle, whether you're a lean startup or a global enterprise.
🎬 Watch now: https://bit.ly/4cq4DxN
📄 #transcript included
-
Log4Shell - Spring4Shell - The XZ Backdoor
These aren't just headlines - they are wake-up calls! As the software ecosystem grows more complex, the question remains: Are we ready for the next #CyberSecurity crisis?
In this #InfoQ video, Soroosh Khodami shares practical strategies to secure your development lifecycle, whether you're a lean startup or a global enterprise.
🎬 Watch now: https://bit.ly/4cq4DxN
📄 #transcript included
-
#ClaudeOpus 4.6 discovered 22 Firefox vulnerabilities in just 2 weeks - 14 of them high- severity bugs. That’s nearly 20% of all critical Firefox bugs fixed in 2025!
And it didn’t stop at detection - #Anthropic reports #Claude generated working exploits for some of these issues.
More on #InfoQ ⇨ https://bit.ly/4rJlBMW
-
#ClaudeOpus 4.6 discovered 22 Firefox vulnerabilities in just 2 weeks - 14 of them high- severity bugs. That’s nearly 20% of all critical Firefox bugs fixed in 2025!
And it didn’t stop at detection - #Anthropic reports #Claude generated working exploits for some of these issues.
More on #InfoQ ⇨ https://bit.ly/4rJlBMW
-
Glassworm Hides Malware in Invisible Unicode Across 151+ Repos
#GitHub #Cybersecurity #Malware #VSCode #npm #OpenSource #Developers #SoftwareDevelopment #Cybercrime #Hackers #SecurityVulnerabilities #Microsoft #Software #BigTech #VSCodeExtension #GlassWorm #OpenVSX
-
Glassworm Hides Malware in Invisible Unicode Across 151+ Repos
#GitHub #Cybersecurity #Malware #VSCode #npm #OpenSource #Developers #SoftwareDevelopment #Cybercrime #Hackers #SecurityVulnerabilities #Microsoft #Software #BigTech #VSCodeExtension #GlassWorm #OpenVSX
-
Microsoft Issues Emergency KB5084597 Hotpatch for RRAS Flaws
#Microsoft #Windows1124H2 #Windows11 #Cybersecurity #SecurityVulnerabilities #SecurityFlaws #RemoteCodeExecution #SoftwareUpdates #WindowsUpdate ##WindowsServer #Windows1125H2 #RRAS #Kb5084597
-
Microsoft Issues Emergency KB5084597 Hotpatch for RRAS Flaws
#Microsoft #Windows1124H2 #Windows11 #Cybersecurity #SecurityVulnerabilities #SecurityFlaws #RemoteCodeExecution #SoftwareUpdates #WindowsUpdate ##WindowsServer #Windows1125H2 #RRAS #Kb5084597
-
https://winbuzzer.com/2026/03/16/qualcomm-gbl-exploit-bootloader-unlock-android-16-xcxwbn/
Qualcomm GBL Exploit Unlocks Bootloaders on Android 16 Flagships
#Qualcomm #Android #Exploits #Cybersecurity #SecurityVulnerabilities #Smartphones #Xiaomi #Android16 #Snapdragon8Elite #Bootloaders
-
https://winbuzzer.com/2026/03/16/qualcomm-gbl-exploit-bootloader-unlock-android-16-xcxwbn/
Qualcomm GBL Exploit Unlocks Bootloaders on Android 16 Flagships
#Qualcomm #Android #Exploits #Cybersecurity #SecurityVulnerabilities #Smartphones #Xiaomi #Android16 #Snapdragon8Elite #Bootloaders
-
Usually when I see a #securityvulnerabilities being talked about, I think "I should warn people - but this is probably too complex for me."
I had the same thought with the recent #Notepad #vulnerability, because it might have been some complex model based parser thing or something... but:
Notepad passed hidden links to WHAT NOW?!?! What a clown show Microsoft has become.
Why is #Microsoft updating their text editors!? | TheStandup
https://www.youtube.com/watch?v=OgfdyH4iaps -
Usually when I see a #securityvulnerabilities being talked about, I think "I should warn people - but this is probably too complex for me."
I had the same thought with the recent #Notepad #vulnerability, because it might have been some complex model based parser thing or something... but:
Notepad passed hidden links to WHAT NOW?!?! What a clown show Microsoft has become.
Why is #Microsoft updating their text editors!? | TheStandup
https://www.youtube.com/watch?v=OgfdyH4iaps -
https://winbuzzer.com/2026/03/04/chrome-gemini-flaw-rogue-extensions-hijack-ai-panel-xcxwbn/
Chrome Gemini Flaw Let Rogue Extensions Hijack Chrome AI Panel
#AI #Google #GoogleChrome #Gemini #GoogleGemini #WebBrowsers #Cybersecurity #BrowserExtensions #SecurityVulnerabilities #SecurityFlaws #Exploits #SecurityPatches #AgenticBrowsers #RogueExtensions
-
https://winbuzzer.com/2026/03/04/chrome-gemini-flaw-rogue-extensions-hijack-ai-panel-xcxwbn/
Chrome Gemini Flaw Let Rogue Extensions Hijack Chrome AI Panel
#AI #Google #GoogleChrome #Gemini #GoogleGemini #WebBrowsers #Cybersecurity #BrowserExtensions #SecurityVulnerabilities #SecurityFlaws #Exploits #SecurityPatches #AgenticBrowsers #RogueExtensions
-
https://winbuzzer.com/2026/02/21/anthropic-launches-claude-code-security-desktop-automation-xcxwbn/
Anthropic Debuts Claude Code Security, JFrog Falls 25%
#AI #Anthropic #Claude #ClaudeCode #Cybersecurity #AISecurity #SecurityVulnerabilities #GitHub #CrowdStrike #JFrog #AICoding #AIAgents #AgenticAI
-
https://winbuzzer.com/2026/02/21/anthropic-launches-claude-code-security-desktop-automation-xcxwbn/
Anthropic Debuts Claude Code Security, JFrog Falls 25%
#AI #Anthropic #Claude #ClaudeCode #Cybersecurity #AISecurity #SecurityVulnerabilities #GitHub #CrowdStrike #JFrog #AICoding #AIAgents #AgenticAI
-
https://winbuzzer.com/2026/02/19/microsoft-edge-145-password-manager-security-fixes-xcxwbn/
Edge 145 Rolls Out with Password Upgrades and Security Patches
#Edge145 #MicrosoftEdge #Microsoft #WebBrowsers #PasswordManagers #SecurityVulnerabilities #BrowserExtensions #PDF #ReadAloud #Chromium
-
https://winbuzzer.com/2026/02/19/microsoft-edge-145-password-manager-security-fixes-xcxwbn/
Edge 145 Rolls Out with Password Upgrades and Security Patches
#Edge145 #MicrosoftEdge #Microsoft #WebBrowsers #PasswordManagers #SecurityVulnerabilities #BrowserExtensions #PDF #ReadAloud #Chromium
-
https://winbuzzer.com/2026/02/04/critical-ai-agent-flaws-exposed-in-microsoft-and-servicenow-xcxwbn/
Critical AI Agent Flaws Exposed in Microsoft and ServiceNow Platforms
#AI #Cybersecurity #Microsoft #ServiceNow #AgenticAI #AIAgents #Copilot #CopilotStudio #MicrosoftCopilot #SecurityVulnerabilities #EnterpriseAI
-
https://winbuzzer.com/2026/02/04/critical-ai-agent-flaws-exposed-in-microsoft-and-servicenow-xcxwbn/
Critical AI Agent Flaws Exposed in Microsoft and ServiceNow Platforms
#AI #Cybersecurity #Microsoft #ServiceNow #AgenticAI #AIAgents #Copilot #CopilotStudio #MicrosoftCopilot #SecurityVulnerabilities #EnterpriseAI
-
https://winbuzzer.com/2026/02/03/openclaw-security-crisis-rce-malicious-skills-api-costs-xcxwbn/
OpenClaw Security Fallout: 341 Malicious Skills and Enabling One-Click Remote Code Execution
#AIAgents #OpenClaw #Cybersecurity #SecurityVulnerabilities #Malware #AgenticAI #OpenSource #ClawHub
-
https://winbuzzer.com/2026/02/03/openclaw-security-crisis-rce-malicious-skills-api-costs-xcxwbn/
OpenClaw Security Fallout: 341 Malicious Skills and Enabling One-Click Remote Code Execution
#AIAgents #OpenClaw #Cybersecurity #SecurityVulnerabilities #Malware #AgenticAI #OpenSource #ClawHub
-
#AWS published a security bulletin acknowledging a configuration issue affecting several popular AWS-managed open-source #GitHub repositories.
The critical vulnerability - dubbed CodeBreach - could have allowed attackers to inject malicious code and hijack repositories using AWS CodeBuild.
Learn more via InfoQ 👉 https://bit.ly/3LSGE0R
#CloudComputing #Security #SecurityVulnerabilities #DevSecOps
-
#AWS published a security bulletin acknowledging a configuration issue affecting several popular AWS-managed open-source #GitHub repositories.
The critical vulnerability - dubbed CodeBreach - could have allowed attackers to inject malicious code and hijack repositories using AWS CodeBuild.
Learn more via InfoQ 👉 https://bit.ly/3LSGE0R
#CloudComputing #Security #SecurityVulnerabilities #DevSecOps
-
Instagram Password Reset Bug Sparks Conflicting Breach Claims
#MetaInc #Instagram #Cybersecurity #DataBreaches #SecurityBreach #SecurityVulnerabilities #DataProtection #DataPrivacy #Privacy #DataSecurity #Authentication #Hackers #SocialMedia
-
Instagram Password Reset Bug Sparks Conflicting Breach Claims
#MetaInc #Instagram #Cybersecurity #DataBreaches #SecurityBreach #SecurityVulnerabilities #DataProtection #DataPrivacy #Privacy #DataSecurity #Authentication #Hackers #SocialMedia
-
DeepSeek-R1 Makes Code for Prompts With Severe Security Vulnerabilities https://cybersecuritynews.com/deepseek-r1-code-vulnerabilities/ #SecurityVulnerabilities #CyberSecurityNews #VulnerabilityNews #cybersecuritynews #cybersecurity
-
DeepSeek-R1 Makes Code for Prompts With Severe Security Vulnerabilities https://cybersecuritynews.com/deepseek-r1-code-vulnerabilities/ #SecurityVulnerabilities #CyberSecurityNews #VulnerabilityNews #cybersecuritynews #cybersecurity
-
Perplexity Calls Comet RCE Vulnerability 'Fake News' Despite Evidence of Silent Patch
#AI #Cybersecurity #PerplexityAI #WebBrowsers #SecurityVulnerabilities #AgenticAI #RCE #Privacy #SquareX #CometBrowser #AISecurity #BrowserSecurity
-
Perplexity Calls Comet RCE Vulnerability 'Fake News' Despite Evidence of Silent Patch
#AI #Cybersecurity #PerplexityAI #WebBrowsers #SecurityVulnerabilities #AgenticAI #RCE #Privacy #SquareX #CometBrowser #AISecurity #BrowserSecurity
-
#F5 disclosed a #breach by #nationstate #hackers who stole undisclosed #BIGIP #securityvulnerabilities and #sourcecode. The breach, discovered on 9 August 2025, involved long-term access to F5’s systems, including its BIG-IP product development environment. While the stolen data includes source code and vulnerability information, F5 claims there’s no evidence of attackers exploiting these flaws or compromising its software supply chain. https://www.bleepingcomputer.com/news/security/hackers-breach-f5-to-steal-undisclosed-big-ip-flaws-source-code/?eicker.news #tech #media #news
-
#F5 disclosed a #breach by #nationstate #hackers who stole undisclosed #BIGIP #securityvulnerabilities and #sourcecode. The breach, discovered on 9 August 2025, involved long-term access to F5’s systems, including its BIG-IP product development environment. While the stolen data includes source code and vulnerability information, F5 claims there’s no evidence of attackers exploiting these flaws or compromising its software supply chain. https://www.bleepingcomputer.com/news/security/hackers-breach-f5-to-steal-undisclosed-big-ip-flaws-source-code/?eicker.news #tech #media #news
-
:blobcoffeeraccoon: Embracing that feeling when u know that #Microsoft #Windows is gonna spend the next week getting FLOODED with #Malware as #cybercrime groups try to get in whatever #SecurityVulnerabilities they can find knowing that a bunch of computers aren't gonna be patched after this, but you're using #Linux and feeling that #virus-free chill. :blobcoffeeraccoon: :tux: :archlinux: :kde:
:windows: To everyone still on Windows though, a #PSA:
For real, backup your files, and go grab Rufus and LinuxMint and make a bootable USB: if you use Windows 10 (or even 11), you might need it. Watch your downloads and even the links you click extra-close right now.
Be careful out there!
-
:blobcoffeeraccoon: Embracing that feeling when u know that #Microsoft #Windows is gonna spend the next week getting FLOODED with #Malware as #cybercrime groups try to get in whatever #SecurityVulnerabilities they can find knowing that a bunch of computers aren't gonna be patched after this, but you're using #Linux and feeling that #virus-free chill. :blobcoffeeraccoon: :tux: :archlinux: :kde:
:windows: To everyone still on Windows though, a #PSA:
For real, backup your files, and go grab Rufus and LinuxMint and make a bootable USB: if you use Windows 10 (or even 11), you might need it. Watch your downloads and even the links you click extra-close right now.
Be careful out there!
-
⚠️ As #Ransomware attacks grow in frequency, scale, and sophistication, endpoint security & reactive backups are no longer enough.
🔐 Defense has moved beyond traditional antivirus - the new focus is the storage layer:
✅ Immutable backups
✅ AI-powered detection
✅ Isolated vaults📰 Read the #InfoQ article by Arjun Mullick (Engineering Manager, Meta): https://bit.ly/4623E3x
#CloudSecurity #ThreatDetection #AI #SecurityVulnerabilities
-
⚠️ As #Ransomware attacks grow in frequency, scale, and sophistication, endpoint security & reactive backups are no longer enough.
🔐 Defense has moved beyond traditional antivirus - the new focus is the storage layer:
✅ Immutable backups
✅ AI-powered detection
✅ Isolated vaults📰 Read the #InfoQ article by Arjun Mullick (Engineering Manager, Meta): https://bit.ly/4623E3x
#CloudSecurity #ThreatDetection #AI #SecurityVulnerabilities
-
Perplexity’s Comet AI browser is making headlines for all the wrong reasons—tricked into clicking phishing links and even putting orders on fake sites. Can our smart tech really stay one step ahead of cyber crooks?
https://thedefendopsdiaries.com/security-challenges-in-perplexitys-comet-ai-browser/
#ai
#cybersecurity
#phishing
#securityvulnerabilities
#promptinjection -
🚨 A Security Nightmare?
AI-powered developer tools built on the #ModelContextProtocol (MCP) are introducing critical #SecurityVulnerabilities like:
➡️ Credential leaks
➡️ Unauthorized file access
➡️ Remote code executionDetails on #InfoQ: https://bit.ly/3Jako0A