BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

Also reported by 1 other source
Also reported by 1 other source
Also reported by 2 other sources (4 articles)
Also reported by 1 other source
CyberScoop·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu78b58p0c78hmu2itb003x4

Researchers use AI to find widespread software decoder flaw

The bug, since patched, gave attackers remote code execution privileges and access to user accounts and production environments, including Meta’s core product suite and an OpenAI software repository. The post Researchers use AI to find widespread software decoder flaw appeared first on CyberScoop.

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu793fyv0douhmu26pbt383f

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install. The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu775zut09muhmu2a09tx041

CISA is ending its monthly vulnerability bulletin

The rise in AI-generated security threats may just have generated one casualty: the death of the weekly bulletin of security threats from the US Cybersecurity Infrastructure and Security Agency (CISA). The agency will discontinue its weekly bulletin of known vulnerabilities from September 28. It said that it is taking this step because of the recently introduced Binding Operational Directive (BOD 26-04), which compels US agencies to prioritize patching vulnerabilities according to real-world…

Also reported by 1 other source