generalnews.media
All World Business Technology Science Health Sports Entertainment Security
311 stories
Exclusive

Zapscape KVM Flaw Lets Privileged Guests Escape to Linux Host

A newly disclosed vulnerability named Zapscape affects KVM, allowing privileged code in L1 guest virtual machines to break out and compromise the underlying Linux host. This virtualization escape poses a serious risk to cloud providers and multi-tenant environments, potentially enabling full host takeover from a guest.

Exclusive

Cisco Fixes 12 Flaws in SD-WAN and IOS XE, Three Rated Critical 9.8

Cisco has released security updates addressing 12 vulnerabilities in its SD-WAN and IOS XE software. Three of these flaws carry the maximum CVSS base score of 9.8, indicating they are critical and could allow remote attackers to take full control of affected devices. Organizations using these Cisco products should apply the patches immediately to prevent potential network compromise.

Exclusive

New Attack Bypasses Spectre v2 Defenses on Intel and AMD CPUs

Researchers have unveiled a novel interrupt injection attack that can bypass existing Spectre v2 mitigations on Intel and AMD processors. This technique exploits interrupt handling to leak sensitive data even when protections are enabled. The discovery underscores persistent security gaps in modern CPU speculative execution defenses.

Exclusive

4,400+ Rockwell PLCs Exposed Online, 22 at Water Facilities in Attack Areas

Researchers found over 4,400 Rockwell Automation programmable logic controllers (PLCs) exposed to the internet, with 22 of them located in cities recently targeted by water system attacks. These unpatched or unprotected industrial controllers are critical to water treatment and other infrastructure, making them a serious security risk. The findings highlight the vulnerability of critical infrastructure to remote cyberattacks.

Exclusive

Weak CryptoJS RNG Behind $5.7M Crypto Drain in Five Wallet Apps

A weak random number generator in the widely used CryptoJS library allowed attackers to predict private keys and drain approximately $5.7 million from five cryptocurrency wallet applications. The flaw stems from an outdated RNG, and users of affected wallets are urged to transfer funds immediately. This incident underscores the critical need for auditing cryptographic dependencies.

Exclusive

AI Recommendation Poisoning: How Ask AI Buttons Can Alter LLM Memory

Researchers have uncovered a technique called AI recommendation poisoning, where malicious "Ask AI" buttons can silently manipulate how large language models remember and retrieve information. The attack exploits recommendation systems to embed biased or false data into an LLM's long-term memory, potentially affecting users who rely on AI advice. This matters because it introduces a new supply-chain risk for AI assistants and decision-making tools.

Exclusive

Attackers Use Oracle to Compile Khunt, Escalate SQL Injection to Windows SYSTEM

Attackers exploited an Oracle database via SQL injection to compile a tool called khunt inside the database environment, enabling a path to full Windows SYSTEM-level access. This technique turns a database vulnerability into a serious operating system compromise, raising concerns for organizations using Oracle.

Exclusive

CISA Warns of Actively Exploited TeamCity RCE Vulnerability

CISA has flagged a critical remote code execution vulnerability in TeamCity, tracked as CVE-2026-63077, as being actively exploited in the wild. Attackers can leverage this flaw to take over vulnerable JetBrains TeamCity servers, which are widely used for software development and CI/CD pipelines. Organizations using TeamCity should apply available patches immediately to prevent compromise.

security technology

Hacker pleads guilty to Snowflake breaches affecting 100M people

A hacker has pleaded guilty to orchestrating data breaches against Snowflake customers, compromising the personal information of at least 100 million people. The guilty plea marks a major legal resolution in a case that highlighted serious risks in cloud data security. This outcome underscores the ongoing threat of large-scale data theft and the importance of robust access controls.