Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITYSYSTEM on Microsoft's production image-processing workers, and as root on…
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITYSYSTEM on Microsoft's production image-processing workers, and as root on…
Cybersecurity researchers at Accomplish AI have disclosed a sandbox escape vulnerability in Anthropic's Claude Cowork, tracked as SharedRoot, that allows an AI…
Beginning July 27, 2026, GitHub will reduce public bug bounty payouts by at least 50% across all severity levels, moving top rewards…
OpenAI disclosed that its AI models, including GPT-5.6 Sol and a more capable pre-release model, were responsible for a security incident targeting…
A critical vulnerability in AWS Kiro, an agentic coding IDE, allowed a poisoned web page to rewrite its configuration file and execute…
Researchers have demonstrated that open-source Android AI agent frameworks are vulnerable to a novel attack chain where invisible screen text can lead…
F5 has patched a critical heap buffer overflow vulnerability in NGINX, tracked as CVE-2026-42533, which can crash worker processes and may allow…
SAP has released its July 2026 security updates, addressing multiple vulnerabilities including a critical out-of-bounds write flaw in SAP NetWeaver Application Server…
The cybersecurity landscape is witnessing a surge in vulnerability clearinghouse announcements, but according to this analysis, most will fail because they focus…