❌

Reading view

There are new articles available, click to refresh the page.

Cursor’s Unpatched Zero-Day Lets a Fake git.exe Hijack Any Windows Developer

A Cursor zero-day vulnerability lets a planted git.exe run automatically when a Windows developer opens a repository. Mindgard disclosed it after seven months of silence from Cursor.

Cursor’s Unpatched Zero-Day Lets a Fake git.exe Hijack Any Windows Developer on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.

Shark Vacuum Vulnerability Lets Attackers Hijack Cameras Across an Entire AWS Region

A researcher found that anyone with physical access to one Shark robot vacuum can extract its AWS IoT certificate and use it to take over other Shark vacuums region-wide, with no patch yet available.

Shark Vacuum Vulnerability Lets Attackers Hijack Cameras Across an Entire AWS Region on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.

How the Bing Images RCE Flaws Actually Worked, and How to Check Your Own Pipeline

A three-line SVG gave XBOW SYSTEM access on Bing's servers through a default ImageMagick setting. Here's the exploit chain and a checklist for anyone running a similar image pipeline.

How the Bing Images RCE Flaws Actually Worked, and How to Check Your Own Pipeline on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.

How the Fastjson RCE Vulnerability Actually Works, and How to Check You’re Exposed

A practical checklist for the Fastjson RCE vulnerability (CVE-2026-16723): how the exploit chain works, four questions to answer this week, and how to mitigate it before a patch exists.

How the Fastjson RCE Vulnerability Actually Works, and How to Check You’re Exposed on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.

Two Joomla Extensions Hit by Zero-Day File Upload Attacks Before Patches Landed

CISA added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities catalog after automated attackers exploited file upload flaws in iCagenda and Balbooa Forms weeks before either bug had a CVE number.

Two Joomla Extensions Hit by Zero-Day File Upload Attacks Before Patches Landed on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.

❌