Security insights, vulnerability roundups, and updates from the Agent Breach team.
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
Microsoft reveals TerminalFix, a new ClickFix variant that uses fake Cloudflare CAPTCHAs to trick users into executing malicious PowerShell commands. The campaign targets Windows Terminal and PowerShell to establish reverse-tunnel backdoors.
Multiple high-severity vulnerabilities in OpenJDK 26 affect core components like JSSE, ImageIO, and Security libraries. These flaws could allow remote attackers to steal data or crash applications.
Three critical vulnerabilities in ServiceNow's AI Platform could allow unauthenticated attackers to execute code and perform SQL injection. Patches are available but require immediate deployment.
As enterprises adopt more cloud services, securing identities across applications and infrastructure becomes increasingly complex. Identity Fabric offers a unified approach to managing and monitoring identity behavior in real time.
Two root-level remote code execution vulnerabilities were discovered in the Unitree G1 EDU robot, one of which is exploitable over Bluetooth. These flaws could allow attackers to fully compromise the device.
Researchers found 19 malicious browser extensions designed to steal cryptocurrency wallets. These extensions targeted users through deceptive downloads and code injection.
Five popular WordPress plugins contain severe vulnerabilities enabling authentication bypass and remote code execution. Immediate updates are required to prevent site compromise.
A critical ownCloud vulnerability was used by a Chinese-speaking group to steal sensitive nuclear research data from a Philippine institute. CISA has added the flaw to its KEV catalog.
Google introduces system-wide ECH in Android 17 to prevent network providers from seeing which sites users visit. This update strengthens connection privacy and protects against cellular-based tracking.
Attackers are chaining two flaws in PaperCut print management software to gain remote control without authentication. Organizations should patch immediately.