Tag: code execution
38 articles

Gitea Servers Exposed to Ongoing Code Execution Attacks
Thousands of Gitea servers remain vulnerable to code execution attacks, with 8393 Internet-exposed IPs still susceptible to CVE-2026-60004, a code injection bug that lets attackers execute arbitrary shell commands. This flaw can be easily exploited by anyone with write access to a repository, which is especially concerning since Gitea enables self-registration by default.

Microsoft patches exploited Entra ID flaw amid rising attacks
Microsoft has patched a critical vulnerability in its Entra ID platform, known as CVE-2026-69836, which allowed attackers to execute code remotely with ease, and has already been exploited in recent attacks. This flaw enabled unauthorized threat actors to gain control and wreak havoc, making swift action crucial to prevent further damage.

Apple patches image-processing flaw exploited in spyware campaigns
Apple just patched a major security flaw in its ImageIO system that could let attackers run code on your device - and it's already been used in sneaky spyware campaigns targeting high-profile targets.

Hugging Face Diffusers Flaws Expose AI Supply Chain to Code Execution Risk
Three high-severity vulnerabilities, dubbed "FaceHugger," have been discovered in the popular Hugging Face Diffusers library, which has been downloaded over 8.1 million times, putting the AI supply chain at risk of code execution attacks. These flaws can bypass a key safeguard, highlighting the urgent need for users to take action.

Broadcom Fixes VMware Flaws That Allow Auth Bypass and Code Execution
Broadcom has patched critical VMware vCenter flaws, including a severe authentication-bypass vulnerability that could let hackers gain unauthorized access to your system. This game-changing flaw, rated 9.8 in severity, can be exploited by malicious actors with network access to wreak havoc on your VMware environment.

Exploit for Patched vBulletin Flaw Disclosed
A newly disclosed exploit for a patched vBulletin flaw shows how an unauthenticated request can be used to execute code on an unpatched forum server, putting vulnerable sites at risk. This security threat was made public on July 27, highlighting the importance of keeping software up to date.

7-Zip Flaw Exposes Systems to Code Execution Risk
A newly discovered flaw in 7-Zip, tracked as CVE-2026-14266, leaves systems vulnerable to code execution attacks, allowing hackers to execute code in the context of the current process. Fortunately, a fix is available in 7-Zip version 26.02, which patches the heap-based buffer overflow issue.

Hugging Face Breach Exposes AI Model Risks
Hugging Face revealed a shocking breach that highlights the hidden dangers of AI models, admitting to unauthorized access to internal datasets and credentials used by its services. The attack began with a malicious dataset that exploited vulnerabilities in the company's data processing pipeline.

U-Boot Flaws Expose Devices to Code Execution, Crashes
Six newly discovered flaws in U-Boot, a widely used bootloader, leave devices from home routers to data-center servers vulnerable to code execution and crashes, posing a significant risk to everything that loads after it. These vulnerabilities can be exploited before the operating system even starts, undermining the entire security chain.

OpenClaw Flaws Expose Hosts to Code Execution via WhatsApp
Three newly patched flaws in the OpenClaw personal AI assistant could let hackers execute code on your device via WhatsApp, putting sensitive data like SSH keys, AWS credentials, and GPG secrets at risk. This alarming vulnerability was addressed in OpenClaw version 2026.6.6.

AI Security Tools Expose Vulnerability to Cyber-Attacks
Researchers have uncovered a chilling vulnerability in AI-powered security tools, allowing hackers to remotely execute malicious code and wreak havoc on even the most secure systems. This shocking exploit, demonstrated through a proof-of-concept attack on popular AI coding agents, highlights a critical weakness that leaves defenses wide open.

CISA Mandates Patching of Exploited Adobe ColdFusion Flaw
Adobe has issued a warning to patch a critical flaw, CVE-2026-48282, in ColdFusion versions 2025.9, 2023.20, and earlier, as attackers have already begun exploiting it just two hours after disclosure. Admins are urged to deploy the updates within 72 hours to prevent code execution on unpatched systems.

Vulnerabilities in FatFs Filesystem Expose Millions of Embedded Devices to Code Execution
Millions of embedded devices are at risk of code execution due to seven vulnerabilities in the widely-used FatFs filesystem, which can be easily exploited with physical access, effectively leading to a jailbreak. This set of flaws, ranging from medium to high severity, poses a significant threat to device security.

libssh2 Flaw Exposes Clients to Code Execution Risk
A critical flaw in libssh2, known as CVE-2026-55200, can be exploited by a malicious SSH server to trigger memory corruption on a connecting client, with no credentials or user interaction required. This vulnerability can be easily triggered with a public proof-of-concept now available.

Amazon Q Developer Flaw Lets Malicious Repos Run Code via MCP Configs
A high-severity flaw in Amazon Q Developer, tracked as CVE-2026-12957, allowed malicious repositories to run commands and steal cloud credentials simply by being opened in an IDE. This vulnerability put developers at risk of having their sensitive AWS keys, cloud CLI tokens, and API secrets compromised.

Cordyceps Flaws Compromise 300+ GitHub Repositories
A newly discovered flaw, dubbed Cordyceps, has left over 300 GitHub repositories vulnerable to exploitation by unauthenticated users, allowing for code execution, credential theft, and supply-chain compromise. This critical weakness can be easily exploited, putting countless open-source projects at risk.

Microsoft Fixes AutoGen Studio Flaw That Enabled Code Execution
Microsoft swiftly squashed a potential code execution flaw in AutoGen Studio, ensuring the vulnerable code never made it to users via a PyPI release. The fix addressed a sneaky three-part vulnerability chain, dubbed AutoJack, that could have been exploited to run malicious code.

Google Vertex AI SDK Flaw Exposes Model Uploads to Hijacking
A newly discovered flaw in the Google Vertex AI SDK for Python left model uploads vulnerable to hijacking, allowing attackers to swap models and execute code within Google's serving infrastructure in a matter of seconds. This vulnerability, found by Palo Alto Networks Unit 42, could be exploited in just 2.5 seconds - a window of opportunity for attackers to wreak havoc.

GitHub Disrupts Supply Chain Attacks by Blocking npm Install Scripts
GitHub is taking a bold step to safeguard the npm ecosystem by blocking install scripts from running by default, tackling the single largest code-execution surface in the ecosystem. This move, part of npm 12's release, aims to prevent supply chain attacks by requiring explicit permission for scripts to run.

GitHub Bolsters npm Security to Thwart Supply-Chain Attacks
GitHub's upcoming npm v12 update is a game-changer for supply-chain security, as it will require explicit approval for automated actions like install scripts and dependency resolution that are often exploited by attackers. This move aims to shut down common code-execution paths and give developers, CI/CD pipelines, and security teams greater control over their code.

GitHub Overhauls npm Defaults to Thwart Script-Based Attacks
GitHub is taking a major step to boost npm security by changing its default settings to block automatic execution of install-time lifecycle scripts, a common vulnerability exploited in script-based attacks. Starting with npm 12, these scripts will require explicit permission to run, unless explicitly allowed via a new allowlist mechanism.

Protobuf.js Vulnerabilities Expose Node.js Apps to Code Execution, DoS
A single malicious protobuf schema could be all it takes to trigger crashes, corrupt runtimes, or even execute code in vulnerable Node.js apps, warns Cyera security researcher Assaf Morag. Six newly identified vulnerabilities in protobuf.js, known as Proto6, carry high severity scores and could put your app at risk.

Google patches actively exploited Android zero-day flaw amid June security updates
Google just patched a high-severity Android flaw that's being actively exploited by hackers, allowing them to gain control of devices running Android 14 or later. The June security update fixes this zero-day vulnerability, along with 123 others, to keep your device safe.

AI Agent Executes End-to-End Cyberattack in Under an Hour
In a chilling demonstration of speed and stealth, a sophisticated AI agent executed a devastating cyberattack from start to finish in under an hour, exploiting a vulnerable marimo notebook to gain code execution and ultimately exfiltrating a PostgreSQL database. This alarming intrusion highlights the lightning-fast potential of modern cyber threats.