Cybersecurity News
-
Telegram Desktop Vulnerability Could Expose Messages Through Malicious HTML Chat Exports
A high-severity vulnerability in Telegram Desktop could allow malicious code hidden in a chat message to run when a user exports the conversation as HTML and opens the resulting file in a…
-
Security Vulnerability in LiteSpeed Enterprise Could Allow Root Access on Shared Hosting Servers
A critical security vulnerability affecting LiteSpeed Web Server Enterprise could allow a low-privilege website user to gain root-level access to a server, according to a security advisory published by cPanel. The issue…
-
Critical Langflow Flaw Allowed Unauthenticated AI Workflow Execution
A critical vulnerability in Langflow could allow an unauthenticated attacker to trigger AI workflows through exposed webhook endpoints, potentially leading to remote code execution, denial of service or unauthorized actions on connected…
-
GiveWP Fixes Critical WordPress Flaw Allowing Remote Code Execution
Security researchers at Patchstack has disclosed a critical vulnerability in the popular GiveWP WordPress donation plugin that could allow an unauthenticated attacker to execute commands on an affected website’s server. GiveWP is…
-
PaperCut Releases Emergency Patch as Attackers Exploit Critical Security Flaws
PaperCut has released a second emergency security update for its widely used NG and MF print management software after confirming that attackers are actively exploiting vulnerabilities in customer environments. The incident involves…
-
Anthropic Says Claude Can Automate Parts of AI Safety Research
Anthropic says Claude can automate parts of AI safety research, including independently finding and testing methods for reducing several kinds of problematic AI behavior, suggesting that some alignment research could be automated…
-
Brave Browser Adds Built-In Email Aliases to Hide Your Real Address
Brave has added an email alias feature to its desktop browser, giving users a way to sign up for websites without handing over their primary email address. The new Email Aliases feature…
-
19 Chrome and Edge Extensions Found Carrying Password & Crypto-Stealing Malware
Researchers at Socket have uncovered 19 malicious browser extensions capable of stealing login information, targeting cryptocurrency wallets and delivering additional malicious code. The investigation identified 18 Chrome extensions and one Microsoft Edge…
-
Android 17 Adds New Network Protections Against Snooping and Text Scams
Google is introducing four new network protections in Android 17 designed to make web browsing, Wi-Fi connections and mobile networks more private and harder for attackers to exploit. The changes address several…
