Category: Vulnerabilities
Critical Cursor AI Editor Flaws Enable OS-Level Remote Code Execution
Two vulnerabilities in the Cursor AI code editor, collectively dubbed DuneSlide, allow attackers to escape the IDE sandbox and execute arbitrary code…
Critical Cursor AI Editor Flaws Allow Prompt Injection to Escape Sandbox
Two near-perfect-severity vulnerabilities in the Cursor AI code editor, dubbed DuneSlide, can be triggered by a single malicious prompt to break out…
DHS Confirms Breach of HSIN Sensitive Information-Sharing Platform
An unknown threat actor compromised the Homeland Security Information Network between late May and early June, targeting servers and a SharePoint collaboration…
Opera Adds Paste Protect to Block ClickFix Clipboard Attacks
Opera's new Paste Protect feature intercepts malicious commands before they reach the clipboard, offering browser-level defense against the increasingly popular ClickFix social…
CISA Warns of Auth Bypass and CSRF Flaws in iDirect Satellite Terminals
Two high-severity vulnerabilities in ST Engineering iDirect iQ-Series terminals could expose sensitive satellite credentials and allow unauthenticated denial-of-service attacks. Patches are available…
CISA Warns of Critical Hardcoded Credential Flaw in Gardyn IoT Hub
Three vulnerabilities in Gardyn's IoT Hub platform, including a CVSS 10 hardcoded credential bug, could let unauthenticated attackers access and control connected…
CISA Advisory: CubeSpace Reaction Wheel Vulnerable to Unsigned Firmware Upload
A missing cryptographic signature check in CubeSpace CW0057 Reaction Wheel firmware lets a physically present attacker flash arbitrary firmware. A patch is…
Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
Adobe released security updates for ColdFusion and Campaign Classic addressing 12 vulnerabilities, including seven rated at maximum severity with CVSS scores of…
CISA Adds Exploited SharePoint RCE Flaw to KEV, Orders Federal Patch
A high-severity deserialization vulnerability in Microsoft SharePoint is now actively exploited, prompting CISA to mandate federal agencies patch within three days under…
Quest NetVault Backup SQL Injection Flaw Enables Remote Code Execution
A high-severity SQL injection vulnerability in Quest NetVault Backup allows authenticated attackers to execute arbitrary code remotely, with the added complication that…
Unraid File Upload Flaw Enables Authenticated RCE, Patched in 7.3.0
A command injection vulnerability in Unraid's FileUpload.php allows authenticated remote attackers to execute arbitrary code. A fix is available in Unraid version…
X.Org Server Use-After-Free Bug Enables Local Privilege Escalation to Root
A use-after-free vulnerability in X.Org Server's SyncAwait object handling allows a local attacker with low privileges to escalate to root. A patch…