Application Security

Australia’s ASD Warns of Active Campaign Exploiting 17 CMS CVEs
Application Security
Australia’s ASD Warns of Active Campaign Exploiting 17 CMS CVEs
Australia's Signals Directorate warned of an active global campaign scanning for 17 known CVEs across WordPress, Joomla, and other public-facing CMS platforms.
Application Security
GhostApproval: Symlink Flaw Lets Attackers Hijack AI Agent Approvals
Wiz Research's GhostApproval attack uses symlinks in cloned repositories to trick six AI coding agents into writing attacker SSH keys behind a fake approval dialog.
Application Security
Socket Finds 17 Malicious Payment SDKs Stealing AWS Keys via npm, PyPI
Socket found 17 malicious npm and PyPI packages impersonating Paysafe, Skrill, and Neteller SDKs that stole AWS keys and payment credentials while returning fake success ...
Application Security
HalluSquatting Turns AI Package Hallucinations Into Botnet Traps
Tel Aviv University and Intuit documented HalluSquatting: AI coding tools hallucinate package names up to 100% of the time, which attackers preregister with malicious payloads.
Application Security
Chrome 150 Patches Two Critical Use-After-Free Flaws in Ozone, Views
Google released Chrome 150.0.7871.114/.115 patching 27 vulnerabilities including two critical use-after-free bugs in Ozone and Views.
Application Security
CMU Research: Copilot’s Safety Refusals Fail 100% in Workflow Mode
Carnegie Mellon researchers found GitHub Copilot refuses harmful prompts 99% of the time in chat but produced harmful code in all 816 workflow-mode tests across ...
Application Security
Friendly Fire PoC Turns Claude Code and Codex Into Malware Launchers
AI Now Institute's Friendly Fire PoC shows Claude Code and Codex in security-audit mode will execute disguised malware when seeded with strings from a legitimate ...
Application Security
Ill Bloom Flaw Drained $3.1M by Breaking Wallet Seed Randomness
Coinspect disclosed Ill Bloom, a weak entropy flaw in cryptocurrency wallet seed phrase generation that let attackers drain $3.1 million from affected wallets.
Application Security
Injective Labs’ npm SDK Poisoned to Steal Crypto Wallet Credentials
Attackers compromised Injective Labs' repository and injected credential-stealing code into the authentic npm SDK packages used by DeFi blockchain developers.
OpenMandriva Linux Contributor Attempted Code Sabotage After Dispute
Application Security
OpenMandriva Linux Contributor Attempted Code Sabotage After Dispute
OpenMandriva Linux caught a contributor sabotage attempt before production, disclosing the insider supply chain attack after an internal community dispute.