A vulnerability in n8n's token exchange mechanism could allow attackers to log in as users from a different issuer, bypassing authentication boundaries. The flaw affects how tokens are validated across identity providers, potentially leading to unauthorized account access. This issue highlights risks in cross-issuer token handling for workflow automation platforms.
A new malware strain named TELEPUZ is spreading through the ClickFix technique, allowing attackers to steal sensitive data and run arbitrary commands on infected systems. The malware exploits social engineering to trick users into executing malicious code, posing a significant threat to data security. This discovery highlights the evolving tactics of cybercriminals and the need for heightened vigilance.
Sony has deleted additional movies from the digital libraries of customers who believed they had bought the titles. The removals underscore the ongoing issue of digital ownership, where retailers can revoke access to purchased content due to licensing changes. This affects consumer trust in digital purchases.
The Daxin hacking group has been detected operating in Taiwan again, using a new backdoor named Stupig that activates before user login. This resurgence highlights continued cyberespionage activity in the region and poses a significant threat to targeted systems.
AI tools are increasingly used to detect software vulnerabilities, but a new analysis shows that human knowledge is still essential to verify and understand the root cause of these bugs. This underscores the ongoing need for skilled human oversight in cybersecurity, despite advances in automation.
A security vulnerability in Shark vacuum cleaners remains unpatched, potentially allowing attackers to take control of other vacuums in the same region. The flaw could be exploited remotely, posing risks of unwanted operation or access to network-connected devices in homes. Users are urged to check for updates or take precautionary measures until a fix is issued.
OpenAI has released GPT-Red, a new tool that automates the testing of prompt injection vulnerabilities in its upcoming GPT-5.6 model. This helps identify and patch security flaws before deployment, making the model more robust against adversarial attacks.
Cybersecurity researchers have discovered that the TuxBot v3 botnet shows signs of being developed with assistance from large language models (LLMs). This evolution suggests that AI tools are increasingly being used to automate and accelerate the creation of sophisticated IoT malware. The trend could lower the barrier for threat actors to develop advanced botnets, posing greater risks to connected devices.
CISA, along with partner organizations, published guidance aimed at helping software manufacturers and online service providers effectively collaborate with security researchers. The guidance outlines best practices for vulnerability disclosure and researcher engagement. This helps improve product security by fostering constructive relationships with the research community.