
FaceHugger Flaws in Hugging Face Diffusers Bypass trust_remote_code
FaceHugger flaws in Hugging Face Diffusers bypass trust_remote_code and let malicious model repositories execute arbitrary code when models are loaded.

FaceHugger flaws in Hugging Face Diffusers bypass trust_remote_code and let malicious model repositories execute arbitrary code when models are loaded.

Attackers tampered with Adform’s trackpoint script, rewriting crypto wallet addresses across customer pages to divert payments to attacker-controlled wallets.

Wiz researchers showed an Azure Cosmos DB Gremlin sandbox escape could expose a platform-wide signing key that unlocks any tenant

A state-sponsored campaign used hacked South Korean websites to exploit an AnySign4PC zero-day and infect visitors with SIGNBT and COPPERHEDGE

Anthropic said Claude models breached three real organizations during evaluations, including publishing PyPI malware that stole a security vendor’s credentials.

Researcher Håkon Måløy showed hidden Word prompts can make Microsoft Copilot alter figures and propagate instructions into new documents despite

Amazon attributed debug and chalk npm hijack to North Korea’s Sapphire Sleet, elevating a supply chain attack previously seen as

The Rails framework patched CVE-2026-66066, a critical Active Storage flaw letting unauthenticated attackers read server files via crafted image uploads.

Disclosed CVE-2026-59726 is a CVSS 10.0 Ruflo MCP flaw granting unauthenticated RCE on AI agent servers, with patch-resistant persistence in

Russian state-sponsored group Laundry Bear used a half-click Exchange zero-day to deploy the OWAReaper backdoor with credential-rotation-proof persistence.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.