Cybersecurity News
-
NVIDIA OpenShell Flaws Put AI Agent Sandboxes at Risk
A pair of near-maximum-severity vulnerabilities in NVIDIA OpenShell could allow attackers to escape an AI-agent sandbox or interfere with how that sandbox is created. Both flaws, CVE-2026-65093 and CVE-2026-65083, carry CVSS scores…
-
Hugging Face Breach Occurred During OpenAI Internal Security Tests
OpenAI has published new details about a July 2026 security incident in which experimental AI agents escaped intended evaluation boundaries, coordinated through unauthorized channels and compromised parts of Hugging Face’s infrastructure. The…
-
WhatsApp Says 1 Billion Users Have Set Up Passwordless Sign-In as It Expands Security Features
WhatsApp said more than 1 billion people have now set up passkeys for their accounts, marking a major adoption milestone for the passwordless sign-in technology. Passkeys allow users to verify their identity…
-
Two Flaws in WordPress Plugin miniOrange SSO Could Allow Admin Takeover
Two critical authentication bypass vulnerabilities in the miniOrange SAML Single Sign On plugin could allow unauthenticated attackers to access affected WordPress sites as existing users, including administrators. Tracked as CVE-2026-61979 and CVE-2026-15981,…
-
Malware Hijacks Android Car Update System for Ad Fraud and Proxy Botnet
Cybersecurity researchers have uncovered malware spreading through the built-in software update system of Android-based car head units, turning infected devices into tools for ad fraud and a proxy botnet. Kaspersky discovered the…
-
Microsoft Defender Driver Can Be Repurposed to Weaken Security Protections
Security researchers have found that a legitimate Microsoft Defender driver can be repurposed to perform highly privileged file and Registry operations, potentially allowing attackers with existing administrator access to weaken security protections.…
-
Why You Should Avoid Replying to Suspicious Texts
A text arrives from an unfamiliar number and appears to have been sent to the wrong person. Replying with a polite “wrong number” may seem harmless, but security researchers say some of…
-
Isolated-vm Flaw Could Let Sandboxed JavaScript Escape to Host
Security researchers at Endor Labs have disclosed a vulnerability in the popular isolated-vm Node.js library that can allow sandboxed JavaScript to break out of its restricted environment and interfere with the host…
-
Critical Elementor Pro Vulnerability Could Allow Remote Code Execution
A critical security flaw in Elementor Pro could allow unauthenticated attackers to upload malicious files to vulnerable WordPress websites and potentially take control of the underlying server. Tracked as CVE-2026-32475, the vulnerability…
