🕵️ RESEARCH & DEEP DIVES
-
Escape found stored XSS in two AI chatboxes via Markdown rendering
Escape found stored XSS in two customer-facing AI chatboxes.- The issue affected two customer-facing AI chat products from unrelated companies.
- Chat messages containing model-generated Markdown could execute JavaScript in users’ browsers.
- The attack used raw HTML rendering without a sanitizer in the Markdown frontend.
- Escape’s AI pentesting agent induced the chat models to emit the malicious content.
📎 Coverage: securityboulevard.com · 👁 via securityboulevard.com (discovered)
-
Peer2Profit Turns Employee Devices Into Gateways to Internal Networks
Peer2Profit can expose internal network resources through residential proxy networks.- Corporate and remote-work devices running Peer2Profit are affected.
- Peer2Profit supplies user bandwidth to AstroProxy’s residential, mobile, and datacenter proxy pools.
- Silent Push identified 117,224 unique AstroProxy IPs over 72 hours, including 60,247 residential IPs.
- The app is installed with user consent through official channels and may evade antivirus detection.
- AstroProxy’s private-IP filter was bypassed with a domain resolving to an internal IP address, exposing a router interface through an enrolled proxy node.
📄 Source: silentpush.com · 📎 Coverage: cyberpress.org · 👁 via Cyber Security News
🔓 CVEs & KEV
- CVE-2026-77710 — CVSS 6.9 — STIX2 Parser Confusion and Mass Assignment Allow Unauthorized MISP Attribute ...