Researchers escape OpenAI Codex sandbox to run commands on host
BragJack attacks hijack AI browser agents through malicious extensions
TigerByte Cyber Emerges From Stealth With $3 Million in Funding
The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA.
The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.
North Korean WaterPlum hackers infected 30,000 devices worldwide
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
Calling viral AI actress Tilly Norwood? Agree to a face scan first
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
The chain began with a bug in the software that runs OpenAI’s public help forum and moved through a weakness in OpenAI’s own login system.
This was security research,
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior.
“SolarWinds
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution.
“Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote
