Local AI Agent Hijacked via Browser: researchers Uncovers Critical “OpenClaw” WebSocket Flaw Enabling Remote Takeover
In late February 2026, security researchers publicly disclosed a critical vulnerability in OpenClaw, a rapidly adopted open…
continue reading..
Zero-Day in MSHTML Exploited by APT28 Before Patch: Microsoft Fixes Critical CVE-2026-21513 Security Bypass
On Microsoft’s February 2026 Patch Tuesday, a particularly dangerous vulnerability — CVE-2026-21513 — was addressed in the…
continue reading..
Iran-Linked “Dust Specter” APT Targets Iraqi Government Officials with Custom .NET Malware and AI-Assisted Tooling
In January 2026, security researchers identified a sophisticated cyber-espionage operation targeting high-value individuals — explicitly government officials…
continue reading..
Cyber War in the Middle East: Infrastructure Disruption, Hacktivism, and State-Sponsored Operations (Feb 27–Mar 1, 2026)
In late February 2026, an unprecedented hybrid conflict erupted in the Middle East following joint military strikes…
continue reading..
CVE-2026-2914: Critical Elevation Flaw in CyberArk EPM Agent Lets Local Users Gain Admin Rights
CVE-2026-2914 Product: CyberArk Endpoint Privilege Manager (EPM) AgentAffected Versions: 25.10.0 and earlierSeverity: HighCVSS v3.1: 7.8 (High)CVSS v4.0:…
continue reading..
Microsoft Warns: OAuth Redirection Abuse Powers New Wave of Phishing and Malware Attacks
OAuth 2.0 is one of the most widely used authorization protocols, allowing users to grant applications limited…
continue reading..
CVE-2026-27595: Unauthenticated AI Agent Flaw in Parse Dashboard Exposes Master Key, Enables Full Database Takeover
Parse Dashboard AI Agent Endpoint – Unauthenticated Master Key Access Product Name: Parse DashboardVendor / Maintainer: Parse…
continue reading..
CVE-2026-27615: Remote Code Execution Flaw in ADB Explorer Lets Attackers Run Malicious Binaries via Network Share
CVE-2026-27615 CVE ID: CVE-2026-27615Product: ADB ExplorerAffected Versions: All versions prior to Beta 0.9.26022Fixed Version: Beta 0.9.26022CVSS v3.1…
continue reading..
CVE-2026-27809: Malformed PSD Files Can Crash psd-tools — Remote DoS Risk in Image Processing Pipelines
Overview CVE ID: CVE-2026-27809Affected component: psd-tools (Python library for Adobe Photoshop PSD files)Affected versions: Versions prior to…
continue reading..
