Any other app on the same phone could ask for the signed-in user’s token and get it, then read email, open files, browse the calendar, and send messages as that user. No password, no login screen, no permission prompt.
Category Added in a WPeMatico Campaign
Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)
Tracked as CVE-2026-23479, the flaw was introduced in Redis 7.2.0 and remained in every stable branch until the May 5 fixes, unnoticed for over two years.
One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens
“Just by clicking a link, it’s possible for an attacker to steal a GitHub token that can read and write to your repos, including private ones,” security researcher Ammar Askar said.
GitHub supports a feature called GitHub.dev that runs as
Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes
Like in the case of CVE-2026-33829, which impacted the Windows Snipping Tool’s ms-screensketch: URI handler, the newly flagged issue resides in the search: URI handler, per Huntress.
CVE-2026-33829 refers to a spoofing vulnerability that could expose
New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
The vulnerability has been codenamed HTTP/2 Bomb by Calif.
“The vulnerable behavior exists in each server’s default HTTP/2 configuration,” the company said, adding it was discovered by OpenAI Codex by chaining
Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
The Minecraft-focused malware-as-a-service (MaaS) campaign has been codenamed Weedhack by McAfee Labs, stating the activity has been active since January 2026 and impersonates Minecraft clients and mods to infect users. In all, 3820
Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited
Tracked as CVE-2025-48595 (CVSS score: 8.4), the security flaw has been described as a case of privilege escalation without requiring any user interaction. The
Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
Per Sekoia, the activity involves the weaponization of CVE-2025-8088, a path traversal flaw in WinRAR, to launch an HTML Application payload dubbed GammaPhish, which is then used to retrieve an
Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation
The vulnerability, CVE-2024-21182 (CVSS score: 7.5), allows an unauthenticated attacker with network access to take control of susceptible servers. It was
AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.
The industry’s
