CVE-2026-32194: Bing Images Command Injection via SVG Upload
A critical command injection vulnerability in Bing's image processing pipeline allows unauthenticated attackers to execute arbitrary commands as SYSTEM on Microsoft's servers…
A critical command injection vulnerability in Bing's image processing pipeline allows unauthenticated attackers to execute arbitrary commands as SYSTEM on Microsoft's servers…
A critical OS command injection vulnerability in Bing's image processing pipeline allows unauthenticated attackers to execute arbitrary commands as SYSTEM by hosting…
Cybersecurity researchers at Zenity Labs have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents, codenamed AgentForger, that could allow a single…
German and US law enforcement, in coordination with Indonesian authorities, have dismantled the infrastructure behind Kratos, a sophisticated phishing kit designed to…
A critical vulnerability in Microsoft's official Azure DevOps MCP server allows attackers to inject hidden HTML comments into pull request descriptions, which…
A critical remote code execution vulnerability in Microsoft SharePoint Server, CVE-2026-50522 (CVSS 9.8), is being actively exploited in the wild following the…
A new attack technique called Bit2Watt, detailed by researchers from Zhejiang University in a paper accepted to CHES 2026, demonstrates how a…
Researchers have demonstrated that open-source Android AI agent frameworks are vulnerable to a novel attack chain where invisible screen text can lead…
Microsoft's AI agent framework that had similar command injection vulnerabilities (CVE-2026-25592, CVE-2026-26030) patched in May 2026.
A malware operator left its delivery server exposed, allowing Rapid7 to recover a full toolkit of 1,048 files including lure templates, filename-spoofing…