OpenAI Breach: libheif Heap Overflow Chained with SSO MisconfigSECURITY Desk · Set in type · No PhotographSecurity / Vulnerabilities · 18 September 2026OpenAI Breach: libheif Heap Overflow Chained with SSO MisconfigHacktron researchers chained a libheif heap buffer overflow in Discourse with an OpenAI SSO misconfiguration to takeover employee accounts and access internal repositories, demonstrating how AI accelerates exploit development.3 min. read
Cursor 0day Vulnerability Exposed After 7 MonthsSECURITY Desk · Set in type · No PhotographSecurity / Vulnerabilities · 25 July 2026Cursor 0day Vulnerability Exposed After 7 MonthsA critical vulnerability in the Cursor AI-assisted development environment has been exposed after 7 months of silence from the company. The vulnerability allows for arbitrary code execution with no user interaction required.2 min. read
Security Camera Ships GitHub Admin TokenSECURITY Desk · Set in type · No PhotographSecurity / Vulnerabilities · 24 July 2026Security Camera Ships GitHub Admin TokenA security camera shipped with a GitHub admin token in its login page, exposing hundreds of repositories to potential security risks. The token was found in the camera's firmware, which was downloaded from the manufacturer's website.2 min. read
GhostLock Stack‑UAF Exposes 15‑Year Linux Kernel FlawSECURITY Desk · Set in type · No PhotographSecurity / Vulnerabilities · 13 July 2026GhostLock Stack‑UAF Exposes 15‑Year Linux Kernel FlawA dormant stack‑use‑after‑free in the rtmutex implementation lets an unprivileged process hijack kernel control flow, affecting every Linux distro released since 2011.3 min. read
How Prompt Injection Can Leak Private YouTube VideosSECURITY Desk · Set in type · No PhotographSecurity / Vulnerabilities · 12 July 2026How Prompt Injection Can Leak Private YouTube VideosA flaw in YouTube Studio’s Ask Studio AI lets a comment control the assistant, exposing private video titles to attackers.3 min. read
Tenda Firmware Backdoor Exposes Routers to Full Admin TakeoverSECURITY Desk · Set in type · No PhotographSecurity / Vulnerabilities · 11 July 2026Tenda Firmware Backdoor Exposes Routers to Full Admin TakeoverA hidden authentication backdoor in Tenda router firmware grants admin access, potentially allowing attackers to gain control over devices. The issue, tracked as CVE-2026-11405, affects multiple firmware versions and can be exploited to bypass normal login checks.2 min. read
usbliter8 Uncovers Unpatchable A12/A13 SecureROM FlawSECURITY Desk · Set in type · No PhotographSecurity / Vulnerabilities · 24 June 2026usbliter8 Uncovers Unpatchable A12/A13 SecureROM FlawParadigm Shift’s usbliter8 exploit shows how a design flaw in the Synopsys DWC2 USB controller lets attackers overwrite SRAM and gain code execution in Apple’s A12/A13 SecureROM.3 min. read
Why Vulnerability Reports Lose Their Edge in 2026SECURITY Desk · Set in type · No PhotographSecurity / Vulnerabilities · 24 June 2026Why Vulnerability Reports Lose Their Edge in 2026LLMs have leveled the playing field, turning the once‑sacred vulnerability report into just another issue ticket.3 min. read