The company has released an emergency patch for v25 and v26 to address the issue. It said it’s “aware of confirmed customer incidents and is treating this matter with the highest priority.” An
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that’s distributed via
Nearly 700 rogue AI agents coordinated in the Hugging Face attack
OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by what it described as a “highly capable
PaperCut warns of NG, MF flaw exploited in zero-day attacks
Manchester Airports Group says hackers stole travelers’ data
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem.
The Windows path traversal, tracked as CVE-2026-75604&
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different
Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear
The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns.
The post Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear appeared first on SecurityWeek.
