GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code
The models they tested through Copilot, Claude from Anthropic, and Gemini from Google, refused
CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
Two newly disclosed critical vulnerabilities in Adobe ColdFusion and Langflow join two Joomla extension flaws in CISA’s Known Exploited Vulnerabilities catalog, with federal agencies given until July 10 to patch.
The post CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws appeared first on SecurityWeek.
Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection
Researchers show how attackers can use a crafted public GitHub Issue to trick AI-powered workflows into exposing data from private repositories without authentication.
The post Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection appeared first on SecurityWeek.
CISA orders feds to prioritize patching Langflow auth bypass flaw
China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
According to findings from Cisco Talos, UAT-7810 is an advanced persistent threat (APT) actor that’s responsible for maintaining and proliferating LapDogs, an ORB network that first came to light in June 2025.
Ubiquiti warns of new max severity UniFi OS vulnerability
CISA orders feds to patch max severity ColdFusion flaw by Friday
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
The vulnerabilities are listed below –
CVE-2026-48282 (CVSS score: 10.0) – A path traversal vulnerability in Adobe ColdFusion that could lead to arbitrary code execution in the context of the
