The Latest Security News and Analysis – AiRc

The Latest Security News and Analysis

software security news

Checkmarx has confirmed that a modified version of the Jenkins AST plugin was published to the Jenkins Marketplace. RubyGems , the standard package manager for the Ruby programming language, has temporarily paused account sign ups following what has been described as a “major malicious attack.” “We’re dealing with a major malicious attack on RubyGems right now,” Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, said in a post on X. Its purpose is to reconcile what access policy intends with how identities are actually used at runtime. As enterprise access spans more cloud services and automated workloads, identity security depends less on static configuration and more on https://holidaynewsletters.com/python-tester-jobs-your-path-into-automation-testing-careers.html runtime visibility.

WiFi users didn’t have to travel very far to get caught up in this breach. Veeam has released security updates to address multiple critical vulnerabilities in its Backup & Replication software that, if successfully exploited, could result in remote code execution. “In ShowDoc version before 2.8.7, an unrestricted and unauthenticated file upload issue is found and an attacker is able to upload a web shell and execute arbitrary code on server,” according to an advisory released by Vulhub. “The malware could generate an uncensored scan report, encrypt it, and send it to an external endpoint, creating a serious risk for teams using KICS to scan infrastructure-as-code files that may contain credentials or other sensitive configuration data.” Further analysis of the incident has uncovered that related Ch… “Analysis of the poisoned image indicates that the bundled KICS binary was modified to include data collection and exfiltration capabilities not present in the legitimate version,” Socket said. In an alert published today, software supply chain security company Socket revealed that unknown threat actors managed to have overwritten existing tags, including v2.1.20 and alpine, while also introducing a new v2.1.21 tag that does not correspond to an official release.

software security news

Laflamme published the research on August 27, 2026, describing the two issues as separate root-RCE paths. As of the August 27 disclosure, the current cloud-assisted route requires an account bound to the target G1 or the relevant key material already in hand. Laflamme said Unitree patched the cloud account-to-robot ownership check in July 2026. An exact fixed firmware release has not been verified in any accessible Unitree guidance, leaving G1 EDU owners without a confirmed release target for either vulnerability. Cybersecurity researchers http://spacehike.com/flightmech.html have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. “This new privacy standard works in tandem with private DNS to obscure the domain names you visit, hiding metadata that can be used to profile you,” Google’s Bram Bonné and Shuaibo Huang said .

Hasbro Data Breach Exposed Employee Personal Information

Security teams must treat autonomous agents as highly privileged identities.

  • Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU , including a Bluetooth Low Energy (BLE) path that can reach root on the robot’s Locomotion PC.
  • Its purpose is to reconcile what access policy intends with how identities are actually used at runtime.
  • Splashtop Shield lets tech-savvy users remotely fix family PC issues with ease, but actual virus protection tanked in my hands-on security tests.
  • Trellix did not disclose the exact nature of the data that may have been accessed by the attackers.
  • And increasingly, it’s the question leaders are forced to answer after an incident.
  • Local boy and 4-time F1 champ Max Verstappen has just extended his Red Bull contract through 2030.

The company did not share any details about who may be behind the incident, and for how long the attackers had access to its systems. Trellix did not disclose the exact nature of the data that may have been accessed by the attackers. Cybersecurity company Trellix has announced that it suffered a breach that enabled unauthorized access to a “portion” of its source code. While DAEMON Tools is also available for Mac, Kaspersky told The Hacker News that only the Windows version was compromised. A newly identified supply chain attack targeting DAEMON Tools software has compromised its installers to serve a malicious payload, according to findings from Kaspersky. It’s assessed that the malicious code was published after obtaining credentials from a previous supply chain attack that took place in March 2026.

Shadow AI Agents Are Multiplying. Here’s How to Find and Secure Them

software security news

“A malicious unauthenticated actor may exploit this issue to execute arbitrary commands, which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress,” the company said in an advisory released late last month. “We found no evidence that OpenAI user data was accessed, that our systems or intellectual property were compromised, or that our software was altered.” The disclosure comes a little over a week after Google Threat Intelligence Group (GTIG) attributed the supply chain compromise of the popular npm package to a North Korean hacking group it tracks as UNC1069 . OpenAI revealed a GitHub Actions workflow used to sign its macOS apps led to the download of the malicious Axios library on March 31, but noted that no user data or internal system was compromised. Once the extensions begin to gather user downloads, a new version with the malicious behavior is published. In a post-mortem published August 28 , Cosmos Labs said the flaw was reported through its bug bounty program on April 25 and was assessed at the time as posing no risk to funds on live networks. The campaign, targeting organizations across multiple sectors, leverages compromised websites as a starting point to serve fake Cloudflare CAPTCHA verifications that prompt unsuspecting site visitors to copy and execute a malicious PowerShell command.

  • It’s assessed that the malicious code was published after obtaining credentials from a previous supply chain attack that took place in March 2026.
  • “This new privacy standard works in tandem with private DNS to obscure the domain names you visit, hiding metadata that can be used to profile you,” Google’s Bram Bonné and Shuaibo Huang said .
  • It relates to a case of unrestricted file upload that stems from improper validation of file extension, allowing an attacker to upload arbitrary PHP files and achieve remote code execution.
  • Chrome users were caught off guard by a 4-GB Google AI model baked into Chrome, sparking privacy concerns.

“Because the internal header format used a delimiter character that could also appear in user input, an attacker could inject additional metadata fields through crafted push option values.” Google-owned cloud security firm Wiz has been credited with discovering and reporting the issue on March 4, 2026, with GitHub validating and deployi… Cybersecurity researchers have disclosed details of a critical security vulnerability impacting GitHub.com and GitHub Enterprise Server that could allow an authenticated user to obtain remote code execution with a single “git push” command. A new software supply chain attack campaign has been observed using sleeper packages as a conduit to subsequently push malicious payloads that enabled credential theft, GitHub Actions tampering, and SSH persistence. AVB Disc Soft, the developer of the software, has been notified of the breach.

How to Watch the 2026 US Open First Round Live (Even for Free)

And increasingly, it’s the question leaders are forced to answer after an incident. Cybersecurity researchers have disclosed details of two now-patched security flaws in the n8n workflow automation platform, including two critical bugs that could result in arbitrary command execution. “N8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution,” CISA said.

The firm assessed that the hacker group used its foothold to explore paths to connected high-value environments, including critical infrastructure. A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks. CloudSEK said the exposed open directory leaked “months of activity” that was active against more than 20 organizations across nine countries between April and July 2026. “This case is a clear example of how adware and affiliate networks can turn out to be far more dangerous than they appear. ValleyRAT is a sophisticated backdoor capable of… Kaspersky said the attack’s geography and payload point to Silver Fox as the likely group behind it, and urged users to avoid software of questionable reputation and to keep it away from security-tool exclusions. Once installed, ValleyRAT (also tracked as Winos 4.0) hands the operator full control of the compromised machine.

The AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage. Local boy and 4-time F1 champ Max Verstappen has just extended his Red Bull contract through 2030. Splashtop Shield lets tech-savvy users remotely fix family PC issues with ease, but actual virus protection tanked in my hands-on security tests. https://californiarent24.com/studying-in-the-united-arab-emirates-benefits-rules-and-features-for-international-students.html Real Madrid and its bevy of stars, including Mbappé, Bellingham, Vini Jr, and Valverde, will look to keep their winning streak going as they take on Malaga. From AI-generated images to restricted satellite data, the systems used to verify what’s real online are struggling to keep up. Chrome users were caught off guard by a 4-GB Google AI model baked into Chrome, sparking privacy concerns.

Leave a Reply

Your email address will not be published. Required fields are marked *