Public exploits for four patched Linux kernel flaws let local users gain root; three require unprivileged user namespaces.
WordPress 7.1.1 fixes Click2Shell, which can force theme installs from crafted links and was chained with a theme flaw for code execution.
Transparent Tribe uses four newly identified malware families in attacks on government and defense entities in India and Afghanistan.
Microsoft fixes a CVSS 10.0 Azure AI Foundry flaw enabling network privilege escalation; no exploitation has been observed.
Report URI CSP alerts surfaced a ClickFix campaign on compromised e-commerce sites using Base64 loaders and a fake verification overlay.
Thirteen npm packages deliver WeaselBiscuit, a JavaScript stealer that harvests Chrome extension storage across Windows, macOS, and Linux.
CrowdStrike says PhantomRaven was likely LLM-generated and spread through malicious npm packages that collect developer credentials and CI/CD secrets.
RatHat Android malware abuses Accessibility and ADB pairing to gain shell access and retain control after uninstall.