Security Incidents
Aggregated security news from trusted sources
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 account...
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 cand...
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft...
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough...
Zapscape (CVE-2026-64561): Guest-to-Host Escape in KVM/x86
Article URL: https://github.com/V4bel/Zapscape Comments URL: https://news.ycombinator.com/item?id=49198843 Points: 86 # Comments: 14
Zero-Day to Zero Doubt: AI-Powered CVE Forensics in an Afternoon
Article URL: https://blog.quent.in/blog/2026/07/31/zero-day-to-zero-doubt-ai-powered-cve-forensics-in-an-afternoon/ Comments URL: https://news.ycombinator.com/item?id=49183887 Points: 2 # Comments: 0...
AI slop pollutes the CVE pipeline with fake vulns
Article URL: https://www.theregister.com/security/2026/08/03/ai-slop-pollutes-the-cve-pipeline-with-fake-vulns/5282462 Comments URL: https://news.ycombinator.com/item?id=49168899 Points: 2 # Comments...
Debian CVE Fixes over Time
Article URL: https://sigwait.org/~alex/blog/2026/07/30/h1rmR5.html Comments URL: https://news.ycombinator.com/item?id=49132941 Points: 1 # Comments: 0
Oracle VM VirtualBox Bug Discovered by AI: CVE-2026-60161
Article URL: https://octane.security/post/oracle-vm-virtualbox-bug-discovered-by-ai-cve-2026-60161 Comments URL: https://news.ycombinator.com/item?id=49125878 Points: 3 # Comments: 0
CVE-2026-64560: Linux UAF
Article URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64560 Comments URL: https://news.ycombinator.com/item?id=49111655 Points: 1 # Comments: 0
Copirate 365: Plundering in the Depths of Microsoft Copilot (CVE-2026-24299)
Article URL: https://embracethered.com/blog/posts/2026/defcon-talk-copirate-365/ Comments URL: https://news.ycombinator.com/item?id=49103398 Points: 8 # Comments: 1
Show HN: Verifiable receipts for firmware CVE reproduction
Article URL: https://github.com/prevotai/colmena Comments URL: https://news.ycombinator.com/item?id=49089763 Points: 4 # Comments: 0
CVE-2026-49176 Exploit Development: WalletService to System
Article URL: https://davidcarliez.github.io/blog/cve-2026-49176-walletservice-to-system/ Comments URL: https://news.ycombinator.com/item?id=49057604 Points: 2 # Comments: 0