AI Security / Vulnerabilities · 25 July 2026Cursor 0day Vulnerability Exposed After 7 MonthsA critical vulnerability in the Cursor AI-assisted development environment has been exposed after 7 months of silence from the company. The vulnerability allows for arbitrary code execution with no user interaction required.2 min. read
AI Security / Vulnerabilities · 24 July 2026Security Camera Ships GitHub Admin TokenA security camera shipped with a GitHub admin token in its login page, exposing hundreds of repositories to potential security risks. The token was found in the camera's firmware, which was downloaded from the manufacturer's website.2 min. read
AI Security / Vulnerabilities · 13 July 2026GhostLock Stack‑UAF Exposes 15‑Year Linux Kernel FlawA dormant stack‑use‑after‑free in the rtmutex implementation lets an unprivileged process hijack kernel control flow, affecting every Linux distro released since 2011.3 min. read
AI Security / Vulnerabilities · 11 July 2026Tenda Firmware Backdoor Exposes Routers to Full Admin TakeoverA hidden authentication backdoor in Tenda router firmware grants admin access, potentially allowing attackers to gain control over devices. The issue, tracked as CVE-2026-11405, affects multiple firmware versions and can be exploited to bypass normal login checks.2 min. read
AI Security / Vulnerabilities · 27 June 2026Anonymous GitHub Account Drops 0-DaysAn anonymous GitHub account is mass-dropping exploit PoCs framed as undisclosed 0-days, with a note telling readers to report them and take credit for the CVE themselves. This raises concerns about coordinated disclosure and the potential impact on defenders.1 min. read
AI Security / Vulnerabilities · 24 June 2026usbliter8 Uncovers Unpatchable A12/A13 SecureROM FlawParadigm Shift’s usbliter8 exploit shows how a design flaw in the Synopsys DWC2 USB controller lets attackers overwrite SRAM and gain code execution in Apple’s A12/A13 SecureROM.3 min. read
AI Security / Vulnerabilities · 24 June 2026Why Vulnerability Reports Lose Their Edge in 2026LLMs have leveled the playing field, turning the once‑sacred vulnerability report into just another issue ticket.3 min. read