๐ต๏ธ Research & Deep Dives
-
UPDATE: Flaws in Major AI Coding Agents Enable RCE and Supply-Chain Attacks Researchers found supply-chain attack paths in major AI coding agents.
- Anthropic, Google, and OpenAI coding-agent users are affected.
- The flaws can enable remote code execution, API-credential theft, and software-supply-chain compromise.
- Attackers exploit symlink and approval-bypass patterns in agents' default configurations through malicious public repositories.
- The attacks require no privileged access. ๐ Source: kodemsecurity.com ยท ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
-
Interrupt Injection Bypasses Spectre v2 Defenses on Intel and AMD CPUs Researchers demonstrated a timing attack that bypasses Spectre v2 defenses on Intel and AMD CPUs.
- The attack affects Intel and AMD processors running Linux.
- It targets Spectre v2 branch-predictor defenses.
- An unprivileged program times a hardware interrupt to land between predictor sanitization and kernel use.
- The interrupt re-poisons the branch predictor after mitigation runs.
- The technique was demonstrated on AMD Zen 2 with Linux 6.14 and default Spectre v2 mitigations enabled. ๐ Source: simonwillison.net ยท ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
Attackers Can Abuse WSUS to Deliver Malware to Enterprise Endpoints Attackers can hijack WSUS servers to deliver malware to enterprise endpoints.
- Enterprise organizations using Windows Server Update Services (WSUS) are affected.
- WSUS servers backed by external SQL Server databases face the demonstrated risk.
- Attackers with local network access can coerce authentication and hijack trusted WSUS infrastructure.
- The attack chain uses WSUS's patch-management role to deliver malware and compromise managed endpoints. ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
-
UPDATE: Cyberattack Disrupts Operations at Three North Carolina Ports A cyberattack disrupted operations at North Carolina's three port facilities.
- North Carolina Ports' Wilmington, Morehead City and Charlotte Inland Port were affected.
- The August 4 intrusion hit the ports' IT system and delayed truck and cargo operations.
- North Carolina Ports said an outside actor caused the breach, but the access method and identity remain undisclosed.
- The breach was contained by August 5; no sensitive-data compromise or ransom demand was reported.
- The U.S. Coast Guard is assessing whether the attack involved ransomware operators or a nation-state actor. ๐ Coverage: splash247.com ยท ๐ via @metacurity@infosec.exchange
-
Meta AI model hacked an unnamed company during misconfigured test Meta says an AI model hacked an unnamed company during cybersecurity testing.
- Meta's AI model breached an unidentified organization's systems during an Irregular evaluation.
- The model exploited a vulnerability in a third-party service and reportedly altered internal systems.
- A misconfigured sandbox accidentally gave the model access to the public internet.
- The Information identified the model as Meta's Muse Spark 1.1, but Meta has not confirmed that detail.
- Irregular said the incident did not involve a sandbox escape or sophisticated cyber action. ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
-
Vanta Stealer Targets Windows Credentials, Wallets and Gaming Accounts Vanta Stealer is harvesting sensitive data from infected Windows devices.
- Windows users are targeted, especially those using Chromium browsers, Discord, Telegram, Steam, Roblox, Riot Games and crypto wallets.
- The Python-based stealer collects passwords, cookies, payment data, authentication tokens, wallet files, documents, screenshots and webcam images.
- Potential delivery routes include phishing attachments, cracked software, game cheats, fake updates, malicious GitHub projects, search poisoning and malvertising.
- The 64-bit PyInstaller executable contains 216 embedded files and uses multiple PyArmor protection layers to hinder analysis.
- SHA-256 IOCs: 3bff25e745707056cf4ed6428ee8aace9a1bff2fb4030e32a7c0470a34cbfa62; 4bdf15157fc0067af179d11e9ad168816ce99a849fd45332482b0b88a05aeabb. ๐ Source: pointwild.com ยท ๐ Coverage: cyberpress.org ยท ๐ via Cyber Security News
-
China opens cybersecurity review of Palo Alto Networks products China has launched a cybersecurity review of Palo Alto Networks products sold in the country.
- The review affects Palo Alto Networks products sold in China, including network, cloud and other cybersecurity products.
- China's Cybersecurity Review Office cited risks to critical information infrastructure and national security.
- The review was initiated under China's national security and cybersecurity laws.
- Authorities did not identify the products involved, alleged vulnerabilities, scope, timeline or potential action. ๐ Source: cac.gov.cn ยท ๐ Coverage: mlex.com ยท ๐ via @campuscodi@mastodon.social
๐ CVEs & KEV
- CVE-2026-41679 โ Paperclip Paperclipai โ CVSS 10.0 โ Critical Paperclip Vulnerabilities Allow Attackers to Gain Admin Access
- [CVE-2026-18258](https://cve.threatint