AI agents execute malicious code in manipulated git repositories on startup – without user intervention, but with full rights ...
A critical vulnerability in NASA's open-source AMMOS Instrument Toolkit (AIT)-GUI ground software has been found that could allow unauthenticated attackers to issue spacecraft and instrument commands, ...
Marimo fixes CVE-2026-75149, an 8.7-severity flaw that can launch an MCP command before notebook cells run in edit mode.
Cisco has released security updates to patch a critical vulnerability in the Unified Contact Center Express (UCCX) software, which could enable attackers to execute commands with root privileges. The ...
A flaw in Cursor's command-line coding agent has been found to allow a cloned repository to run any command it chose on a developer's machine before they were asked whether they trusted it, and ...
SOCRadar details E4del and PINHOLE RAT campaigns using FTP banners as dead drop resolvers to fetch commands and C2 details.