generalnews.media
All World Business Technology Science Health Sports Entertainment Security
311 stories
Exclusive

n8n Token Exchange Vulnerability Allows Attackers to Impersonate Users from Different Issuers

A vulnerability in n8n's token exchange mechanism could allow attackers to log in as users from a different issuer, bypassing authentication boundaries. The flaw affects how tokens are validated across identity providers, potentially leading to unauthorized account access. This issue highlights risks in cross-issuer token handling for workflow automation platforms.

security

TELEPUZ Malware Uses ClickFix to Steal Data and Execute Commands

A new malware strain named TELEPUZ is spreading through the ClickFix technique, allowing attackers to steal sensitive data and run arbitrary commands on infected systems. The malware exploits social engineering to trick users into executing malicious code, posing a significant threat to data security. This discovery highlights the evolving tactics of cybercriminals and the need for heightened vigilance.

security technology

Sony Removes More Movies from Accounts of Users Who 'Purchased' Them

Sony has deleted additional movies from the digital libraries of customers who believed they had bought the titles. The removals underscore the ongoing issue of digital ownership, where retailers can revoke access to purchased content due to licensing changes. This affects consumer trust in digital purchases.

Exclusive

Daxin Hacking Group Resurfaces in Taiwan with New Pre-Login Backdoor

The Daxin hacking group has been detected operating in Taiwan again, using a new backdoor named Stupig that activates before user login. This resurgence highlights continued cyberespionage activity in the region and poses a significant threat to targeted systems.

Exclusive

AI Finds Bugs, But Humans Still Need to Prove Them

AI tools are increasingly used to detect software vulnerabilities, but a new analysis shows that human knowledge is still essential to verify and understand the root cause of these bugs. This underscores the ongoing need for skilled human oversight in cybersecurity, despite advances in automation.

Exclusive

Unpatched Shark Vacuum Bug Allows Remote Control of Other Vacuums Across a Region

A security vulnerability in Shark vacuum cleaners remains unpatched, potentially allowing attackers to take control of other vacuums in the same region. The flaw could be exploited remotely, posing risks of unwanted operation or access to network-connected devices in homes. Users are urged to check for updates or take precautionary measures until a fix is issued.

Exclusive

OpenAI's GPT-Red Automates Prompt Injection Testing for GPT-5.6

OpenAI has released GPT-Red, a new tool that automates the testing of prompt injection vulnerabilities in its upcoming GPT-5.6 model. This helps identify and patch security flaws before deployment, making the model more robust against adversarial attacks.

Exclusive

TuxBot v3 Indicates Use of LLMs in IoT Botnet Development

Cybersecurity researchers have discovered that the TuxBot v3 botnet shows signs of being developed with assistance from large language models (LLMs). This evolution suggests that AI tools are increasingly being used to automate and accelerate the creation of sophisticated IoT malware. The trend could lower the barrier for threat actors to develop advanced botnets, posing greater risks to connected devices.

Exclusive

Guidance Released for Software Makers on Working With Security Researchers

CISA, along with partner organizations, published guidance aimed at helping software manufacturers and online service providers effectively collaborate with security researchers. The guidance outlines best practices for vulnerability disclosure and researcher engagement. This helps improve product security by fostering constructive relationships with the research community.