AutoJack Attack: One Malicious Web Page Can Hijack AI Agents for Remote Code Execution
Microsoft researchers have disclosed a novel exploit chain named AutoJack that allows a single malicious web page to hijack an AI browsing…
Microsoft researchers have disclosed a novel exploit chain named AutoJack that allows a single malicious web page to hijack an AI browsing…
AutoGen Studio versions 0.4.3.dev1 and 0.4.3.dev2 contain an unauthenticated MCP WebSocket route that allows command execution. The stable release 0.4.2.2 is not…
CVE-2013-3307 is a vulnerability in certain Linksys router models that allows remote attackers to execute arbitrary code. This flaw, dating from 2013,…
CVE-2016-5681 is a vulnerability in D-Link router models that allows remote attackers to execute arbitrary code. This flaw is exploited by the…
CVE-2025-24813 is a remote code execution flaw in Apache Tomcat disclosed in March 2025 and added to CISA's Known Exploited Vulnerabilities catalog.…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding active exploitation of a critical vulnerability in Lantronix EDS5000…