A security vulnerability in Shark vacuum cleaners remains unpatched, potentially allowing attackers to take control of other vacuums in the same region. The flaw could be exploited remotely, posing risks of unwanted operation or access to network-connected devices in homes. Users are urged to check for updates or take precautionary measures until a fix is issued.
OpenAI has released GPT-Red, a new tool that automates the testing of prompt injection vulnerabilities in its upcoming GPT-5.6 model. This helps identify and patch security flaws before deployment, making the model more robust against adversarial attacks.
Cybersecurity researchers have discovered that the TuxBot v3 botnet shows signs of being developed with assistance from large language models (LLMs). This evolution suggests that AI tools are increasingly being used to automate and accelerate the creation of sophisticated IoT malware. The trend could lower the barrier for threat actors to develop advanced botnets, posing greater risks to connected devices.
CISA, along with partner organizations, published guidance aimed at helping software manufacturers and online service providers effectively collaborate with security researchers. The guidance outlines best practices for vulnerability disclosure and researcher engagement. This helps improve product security by fostering constructive relationships with the research community.
New display technology enables screens to capture video and images without separate cameras. This raises significant privacy and surveillance concerns as the same surface used for viewing can now record users. The development could change how devices are designed and how privacy is protected in public and private spaces.
Two previously unknown vulnerabilities in SonicWall's SMA 1000 series have been actively exploited in attacks. One of the flaws could allow attackers to execute arbitrary commands with administrative privileges. Organizations using the affected devices should apply patches immediately to prevent compromise.
Security researchers identified a vulnerability in the Claude for Chrome extension that lets malicious browser extensions access Gmail data without proper authorization. The flaw stems from incorrect permission handling in the AI assistant tool. This matters because it could expose sensitive email content, emphasizing the security risks of third-party browser extensions.
A new remote access trojan, LabubaRAT, is being distributed disguised as legitimate NVIDIA software to infect Windows hosts. Once installed, attackers can gain full control over the compromised system, including executing commands and stealing data. Users should verify software sources carefully to avoid infection.
A study of 85 cryptocurrency browser extensions found that many leak wallet addresses and allow cross-site tracking of users. This poses privacy and security risks for individuals using these extensions to manage digital assets. The findings highlight the need for users to be cautious about the extensions they install.