Tag

Security

All articles tagged with #security

technology2 days ago

Meta’s Muse AI Agent Faces Security Backlash and Privacy Concerns

Meta’s Muse AI agent, launched in September 2026, has become the top app in the U.S. but faces severe criticism over privacy and security flaws. Reports reveal it builds detailed dossiers on users and their contacts, while internal documents show rushed fixes for critical virtual machine vulnerabilities before launch. Despite Meta’s claims of privacy-first design, users report unauthorized access to messages and data, prompting Apple to adjust macOS privacy settings.

Atlassian CVE-2026-21589: Critical File-Read Flaw in Eight Data Center Products Faces Rapid Exploitation
security2 days ago

Atlassian CVE-2026-21589: Critical File-Read Flaw in Eight Data Center Products Faces Rapid Exploitation

Atlassian disclosed a critical vulnerability, CVE-2026-21589, affecting eight self-hosted Data Center products. The flaw allows unauthenticated attackers to read specific files in the web root if they know the exact path. While Atlassian initially reported no evidence of exploitation, security firms confirmed active attempts within hours of technical details emerging. Cloud users are patched, but self-hosted admins must update immediately or apply temporary mitigations.

Attackers Forge Google Certificates via Hijacked Country Code Domains
security2 days ago

Attackers Forge Google Certificates via Hijacked Country Code Domains

Hackers compromised the .gh, .sl, and .as country code top-level domains to issue unauthorized TLS certificates for Google and other major brands. Google updated Chrome to block these forged credentials and advised domain owners to monitor certificate transparency logs, noting that browser-side fixes alone are insufficient for long-term protection.

BYOD hackers claim live access to Trump Mobile after exposing 3,615 users' data
security2 days ago

BYOD hackers claim live access to Trump Mobile after exposing 3,615 users' data

A hacking group called BYOD claims to have breached Trump Mobile, exposing the personal data of 3,615 individuals. The leaked information includes names, home addresses, email addresses, phone numbers, and order details. The group states they gained access by installing a remote access trojan on an employee of Liberty Mobile, the carrier powering Trump Mobile's network. Cybernews researchers confirmed the leaked samples appear legitimate and are not linked to previous breaches. Notably, the data includes information for Eric Brunnett, the chief information technology officer at The Trump Organization. Trump Mobile has not yet responded to requests for comment.

Atlassian patches critical unauthenticated file-read flaw across eight self-hosted products
security3 days ago

Atlassian patches critical unauthenticated file-read flaw across eight self-hosted products

Atlassian disclosed CVE-2026-21589 on October 5, a critical path traversal flaw affecting eight self-hosted Data Center products. The vulnerability allows unauthenticated attackers to read specific files in the web application root directory if they know the exact file path. Atlassian rated the flaw 9.3/10 on the CVSS scale. Cloud versions are already patched, but self-hosted users must upgrade to specific fixed versions or apply temporary mitigations. Atlassian has not confirmed active exploitation but advises users to check logs for suspicious requests.

AI-discovered flaw in Rejetto HFS triggers active exploitation from China
security4 days ago

AI-discovered flaw in Rejetto HFS triggers active exploitation from China

Anthropic's Mythos AI model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), now under active exploitation. The flaw, CVE-2026-61500, allows attackers to forge admin sessions and execute remote code by exploiting a weak random number generator. Vulnerability researchers confirmed that Mythos used advanced mathematical reasoning to reverse-engineer the session key, marking a significant shift in AI-driven security discovery. Exploitation attempts have been detected from Chinese IP addresses targeting US and Japanese hosts, prompting urgent patching to version 3.2.1.

Flydubai co-pilot targeted Tel Aviv airport in 9/11-style plot, reports reveal
security4 days ago

Flydubai co-pilot targeted Tel Aviv airport in 9/11-style plot, reports reveal

The co-pilot accused of hijacking a Flydubai flight to Tel Aviv intended to crash the aircraft into Ben Gurion airport or a tower block, according to US and Israeli reports. The Omani national, identified as Hamam al-Hammami, acted as a lone wolf extremist after attacking the captain with an axe. Security lapses are under scrutiny, including why the pilot was hired despite prior concerns and why he was allowed to fly to Israel despite diplomatic restrictions.

Five Years After Amess Murder, UK Politicians Face Escalating Threats
politics5 days ago

Five Years After Amess Murder, UK Politicians Face Escalating Threats

Katie Amess, daughter of murdered MP Sir David Amess, warned that politicians remain at high risk five years after her father's death in 2021. She criticized the lack of change despite increased threats, including the recent death of former MP Ann Widdecombe. A government review led by Sir Robert Buckland is underway to improve safety, while Conservative leader Kemi Badenoch confirmed she received threats from a man also targeting her family. Other figures, including Reform UK's Richard Tice, acknowledged rising dangers but argued for balancing accessibility with protection.

Apple Tightens macOS Permissions to Curb AI Agent Data Access
technology5 days ago

Apple Tightens macOS Permissions to Curb AI Agent Data Access

Apple announced new restrictions on macOS 'Full Disk Access' permissions to prevent AI agents from accessing sensitive user data without explicit consent. The move follows privacy concerns regarding autonomous AI tools like Meta's Muse, which critics argue can access messages and browsing history beyond their stated opt-in requirements. Apple stated that current permissions allow developers to bypass privacy controls, exposing files, mail, and messages. The company will require 'very explicit user action' to grant such access but has not specified a rollout timeline.

GitLab Patches Critical AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
security5 days ago

GitLab Patches Critical AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

GitLab has released patches for CVE-2026-90970, a critical vulnerability in its AI Gateway service that allows authenticated users to execute arbitrary commands. The flaw, rated 9.9 on the CVSS scale, affects only self-hosted instances; GitLab-managed services are already secured. Users must update to versions 19.2.4, 19.3.2, or 19.4.1 immediately.

ChatGPT Mac App Flaw Exposed Deep System Access Risks
security7 days ago

ChatGPT Mac App Flaw Exposed Deep System Access Risks

A critical vulnerability in the macOS version of ChatGPT, discovered by Objective-See Foundation researchers, could have allowed attackers to access sensitive user data and execute commands. The flaw, which required only about ten lines of code to exploit, was patched by OpenAI on September 25, 2026. It highlighted the security risks of granting AI agents broad system permissions.

Proof-of-Concept Reveals How Malicious PDFs Trigger Apple CoreGraphics Crash
security7 days ago

Proof-of-Concept Reveals How Malicious PDFs Trigger Apple CoreGraphics Crash

Security researchers have released a proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw patched on September 28. The vulnerability, triggered by a malicious PDF with a crafted font, causes a crash on unpatched iOS and macOS devices. While Apple confirmed the flaw was used in targeted attacks, the new analysis demonstrates only a memory corruption crash, not full code execution. CISA mandated federal agencies patch by October 2, and researchers noted potential links to WhatsApp delivery mechanisms, though Meta has not confirmed involvement.