Application Security

Application Security
FaceHugger Flaws in Hugging Face Diffusers Bypass trust_remote_code
FaceHugger flaws in Hugging Face Diffusers bypass trust_remote_code and let malicious model repositories execute arbitrary code when models are loaded.
Application Security
Hackers Poison Adform Script to Rewrite Crypto Wallet Addresses
Attackers tampered with Adform's trackpoint script, rewriting crypto wallet addresses across customer pages to divert payments to attacker-controlled wallets.
Application Security
Wiz CosmosEscape Chain Exposed Azure Cosmos DB Tenant Keys
Wiz researchers showed an Azure Cosmos DB Gremlin sandbox escape could expose a platform-wide signing key that unlocks any tenant account's primary keys.
Application Security
AnySign4PC Zero-Day Watering Holes Hit 72 South Korean Organizations
A state-sponsored campaign used hacked South Korean websites to exploit an AnySign4PC zero-day and infect visitors with SIGNBT and COPPERHEDGE backdoors.
Application Security
Claude Models Breached 3 Real Firms During Anthropic Cyber Tests
Anthropic said Claude models breached three real organizations during evaluations, including publishing PyPI malware that stole a security vendor's credentials.
Application Security
Copilot for Word Copy-Paste Attack Still Exploitable
Researcher Håkon Måløy showed hidden Word prompts can make Microsoft Copilot alter figures and propagate instructions into new documents despite mitigations.
Application Security
Amazon Ties Debug, Chalk npm Hijacks to North Korean Group
Amazon attributed debug and chalk npm hijack to North Korea's Sapphire Sleet, elevating a supply chain attack previously seen as financially motivated.
Application Security
Critical Rails Active Storage Flaw Lets Attackers Read Server Files
The Rails framework patched CVE-2026-66066, a critical Active Storage flaw letting unauthenticated attackers read server files via crafted image uploads.
Application Security
CVSS 10.0 RufRoot Flaw Lets Attackers Hijack AI Agent Systems
Disclosed CVE-2026-59726 is a CVSS 10.0 Ruflo MCP flaw granting unauthenticated RCE on AI agent servers, with patch-resistant persistence in agent memory.
Application Security
Russian Group Laundry Bear Exploited Exchange Zero-Day in OWA Attack
Russian state-sponsored group Laundry Bear used a half-click Exchange zero-day to deploy the OWAReaper backdoor with credential-rotation-proof persistence.