GPUThor Rowhammer Attack Bypasses ECC on NVIDIA RTX A6000 to Achieve Host Root Access
Academic researchers at the University of Toronto have disclosed a new Rowhammer attack, dubbed GPUThor, that defeats error correction codes (ECC) on…
Academic researchers at the University of Toronto have disclosed a new Rowhammer attack, dubbed GPUThor, that defeats error correction codes (ECC) on…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released advisory AA26-237A, titled "A Tale of Two SOCs," on August 25, 2026, detailing…
Amazon CloudFront is a fast CDN service that securely delivers data, videos, applications, and APIs to customers globally. It was found susceptible…
Security researchers have uncovered a class of vulnerabilities in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel that allow attackers…
AgentCore's InvokeHarness API had a vulnerability allowing tool-use block injection, fixed by AWS. The underlying open-source Strands code remains vulnerable.
The open-source Strands Python code, which underpins AWS AgentCore, contains a model-skipping path that remains unpatched. AWS documented the behavior instead of…
A Chinese-speaking threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the…
Device code phishing, which abuses the OAuth 2.0 device authorization grant to steal access tokens, has rapidly evolved from a niche technique…
Amazon Inspector is a vulnerability management service from AWS that identified the typo-crypto package as malicious, leading to the OSV record MAL-2026-3400.
A Linux distribution by Amazon Web Services, affected by CVE-2026-64600. Default installations with reflink-enabled XFS are vulnerable.