ServiceNow Pre-Auth RCE Could Run Commands on Connected Proxy Servers
CVE-2026-6875 chained query evaluation with a sandbox escape, giving an unauthenticated attacker broad control of a ServiceNow instance and its connected proxy servers.
Reader edition
CVE-2026-6875 chained query evaluation with a sandbox escape, giving an unauthenticated attacker broad control of a ServiceNow instance and its connected proxy servers.
Push Security traced sponsored search ads to shared ChatGPT and Claude pages that handed visitors to fake desktop-app downloads.
A civil lawsuit targets a Telegram-based phishing-kit operation that Google links to 2.5 million texts and more than one million fraudulent URLs.
CVE-2025-55241 allowed an Entra actor token from one tenant to impersonate users in another through the legacy Azure AD Graph API.
Researchers put instructions to read .env and encode it into source inside a PNG that text-only pull-request reviewers ignored but vision-capable coding agents later followed.
A Teams lure installed a headless Edge extension and a Python native-messaging host, giving a ransomware access broker a quiet route to local command execution.
A stolen npm publisher account added a malicious dependency to more than 140 Mastra packages, giving Sapphire Sleet an install-time path into developer and CI systems.
AIR says its brand-landingpage experiment reached 26,000 agents after scanners missed a remote instruction source that changed after approval.
CVE-2026-12957 allowed project configuration to start MCP processes with a developer's environment. AWS fixed the flaw in Language Servers for AWS 1.65.0.
A forgotten Klue credential led to customer OAuth token theft and direct access to Salesforce CRM data across several companies.
Island found more than 800 fake skills and MCP servers using credible READMEs and ZIP files to turn capability searches into malware installs.
Five poisoned releases avoided install hooks, launching a detached Node.js process when developer or CI tooling loaded the affected module.
Trend Micro found a Russian-speaking actor using Gemini CLI to rebuild command-and-control infrastructure and operate eight infected computers.