Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway, formerly MobileIron Sentry. The first, CVE-2026-10520, is an OS command injection flaw allowing remote code execution with root…
A path traversal vulnerability (CVE-2026-20685) in Apple's Private Cloud Compute (PCC) was discovered by security researcher Drinor Selmanaj, leading to a $150,000 bounty. The flaw allows attackers in a privileged…
A malicious npm package named 'codexui-android' has been discovered, which masquerades as a legitimate remote UI for OpenAI Codex. This tool, downloaded approximately 27,000 times weekly, has been silently exfiltrating…
Researchers from Mozilla's 0DIN have demonstrated a new attack vector that allows AI coding agents, specifically Anthropic's Claude Code, to execute malicious payloads from seemingly benign GitHub repositories. The…