Application Security

Application Security
CISA Flags Active Exploitation of TeamCity CVE-2026-63077
CISA added JetBrains TeamCity CVE-2026-63077 to its Known Exploited Vulnerabilities catalog, citing unauthenticated remote code execution in the wild.
Application Security
Meta AI Hacked External Systems During Cybersecurity Testing
Meta admitted its Muse Spark 1.1 model escaped a test environment and breached an unnamed third party's systems during evaluations by startup Irregular.
Application Security
CoreBreak Flaws Let Attackers Invoke AWS, Google, Vercel Tools
Stealth researchers disclosed CoreBreak flaws in AWS Bedrock, Google ADK, and Vercel harnesses that let attackers invoke agent tools without the model.
Application Security
Open VSX Purges 77 Evil-Twin Extensions Stealing Developer Data
Open VSX removed 77 malicious evil-twin extensions impersonating developer tools and exfiltrating machine, Git, and CI/CD data to one attacker domain.
Application Security
ChainDrop npm Worm Poisons 440 Packages, Steals Cloud Credentials
The ChainDrop npm worm, a new Shai-Hulud variant, poisoned over 440 registry packages and uses stolen tokens to republish malware and reach cloud credentials.
Application Security
CISA Adds Exploited Langflow and Tomcat Flaws to KEV Catalog
CISA added actively exploited Langflow and Apache Tomcat vulnerabilities to the KEV catalog, linking the Tomcat flaw to an AI-enabled Chinese hacking campaign.
Application Security
QuickFox VPN Supply-Chain Attack Delivers FDMTP Backdoor
Fortinet disclosed a long-running supply-chain attack on QuickFox VPN that delivers the undocumented FDMTP backdoor through a trojanized Windows installer.
Application Security
Claude Mythos 5 Tried to Backdoor a Project in UK AI Security Test
A Claude Mythos 5 agent spent 34 hours trying to merge malware into an open-source project during a UK AI Security Institute evaluation, then covered ...
Application Security
Google Deletes Three ADK AI Workflows After Prompt-Injection Attack
Google removed three ADK AI workflows after Pillar Security showed a GitHub issue could prompt-inject a triage agent into launching a privileged agent.
Application Security
cPanel Patches Critical Flaw Letting Customers Run SQL as Root
cPanel patched CVE-2026-58048, a CVSS 9.4 privilege-escalation flaw letting an authenticated hosting customer execute SQL in the database root context.