Security researchers report that threat actors known as Kimi K3 discovered multiple zero-day vulnerabilities in the Redis database system. They then developed a remote code execution (RCE) exploit targeting these flaws. This is significant because Redis is widely used for caching and data storage, making many systems potentially vulnerable to attack.
A security flaw in Anthropic's Claude Cowork feature could allow an AI agent to break out of its virtual machine and access files on a Mac system. The vulnerability, if exploited, could lead to unauthorized data exposure. Users should apply patches promptly.
A threat actor linked to China, known as JadeProx, has been using a new malware loader called TriBack to target government and healthcare organizations. The loader enables remote access and data theft, posing a serious risk to critical infrastructure and sensitive data. This development underscores ongoing cyber espionage efforts by state-affiliated groups.
US cybersecurity agencies, including CISA, NSA, FBI, and international partners, have issued a warning about ongoing malicious cyber activity by Russian state-supported actors targeting Zimbra Collaboration Suite users. The threat involves exploitation of vulnerabilities to gain unauthorized access to email and sensitive data. This alert underscores the persistent risk of nation-state cyber espionage against widely used collaboration platforms.
A nine-year-old vulnerability in RefluXFS, a Linux filesystem driver, allows local users to gain full root privileges on default Red Hat Enterprise Linux installations. The flaw, which has existed since RHEL 6, enables attackers with local access to escalate their rights and take complete control of the system. This affects many enterprise servers running default RHEL configurations, posing a serious security risk.
Check Point released a security patch for a critical SmartConsole vulnerability that was actively exploited in the wild. The flaw could allow an attacker to gain full administrative access to the security management system. Organizations using Check Point's network security products should apply the patch immediately to prevent unauthorized control.
A vulnerability in Ubuntu's snap-confine component allows local users to escalate privileges to root on default desktop installations. The flaw, present in the snap package manager, could enable an attacker with local access to gain full system control. Users should apply security updates promptly to mitigate the risk.
A security flaw in the Adobe Acrobat browser extension allows malicious websites to access and read WhatsApp Web data. The vulnerability exploits the extension's permissions to intercept sensitive information. This poses a significant privacy risk for users who have the extension installed.
Attackers are exploiting a vulnerability in Windmill, an open-source job scheduler, to read arbitrary server files without authentication. The flaw, which affects unpatched versions, allows remote file access by bypassing security checks. This highlights the critical need for prompt patching to prevent data breaches.