Tech News
← Home  ·  All topics

Execution

22 GoKawiil briefs on this topic

Hackers actively scanning for CVE-2026-61500 flaw in Rejetto HFS servers

Security researchers report that malicious actors are probing Rejetto HFS servers for a critical vulnerability, CVE-2026-61500, which affects versions 3.0.0 to 3.2.0. The flaw involves weak session cookie signing due to non-cryptographic random number generation, enabling attackers to forge administrator sessions and execute remote code. Observations indicate the scans originate from a China Telecom IP address targeting servers in Japan and the US.

CISA flags critical pre-auth RCE bug in MikroTik RouterOS

CISA has issued an advisory for CVE-2026-84411, a critical integer underflow bug in MikroTik RouterOS's web-management HTTP handling that can be triggered before authentication. A single crafted request could let an unauthenticated attacker execute code as root or crash the device. Versions below 7.24 are affected, and the agency says the vendor advises upgrading to 7.23 or later, though it hasn't published its own advisory yet.

TeamViewer patches five high-severity flaws in client and host software

TeamViewer issued an advisory urging all users to update to version 15.82 after fixing five high-severity vulnerabilities, including an access control bypass that could enable remote code execution and other flaws allowing privilege escalation to SYSTEM or root. The company says it has no evidence of public exploit code or active exploitation of the issues.

Unsloth patches Unsloth Studio flaw allowing code execution via malicious model metadata

Security researcher Ariel Fogel of Pillar Security disclosed a vulnerability in Unsloth Studio, the web interface for the popular open-source LLM fine-tuning library Unsloth, that let a malicious Hugging Face model execute arbitrary Python code simply by having its config.json inspected. The flaw stemmed from Unsloth Studio's use of a 'trust_remote_code=True' setting in the Transformers library, meaning no model weights needed to load or run for the exploit to trigger. Unsloth has since fixed the issue.

Apple releases iOS 26.7.1 to patch actively exploited zero-day flaw

Apple has issued iOS 26.7.1 for devices still on iOS 26 or earlier to fix a security vulnerability in its CoreGraphics framework. The company says the flaw may have been exploited in a highly sophisticated attack against specific targeted individuals, and could allow arbitrary code execution. Users on iOS 27 are unaffected but should still install iOS 27.0.1 to stay current.

New unpatched Citrix NetScaler zero-days actively exploited, admins told to shut down devices

Citrix administrators report being privately contacted by IT suppliers, law enforcement, and cybersecurity agencies warning of two unpatched NetScaler remote code execution vulnerabilities being exploited in the wild. Security firm watchTowr confirmed the flaws are distinct from CVE-2026-19490 and CVE-2026-19489 disclosed in August, and said patches are expected next week.

Security researcher chains Twitch overlay flaw to remote code execution in OBS

A researcher demonstrated that an unsanitized Twitch chat overlay running as an OBS Browser Source could let a viewer inject JavaScript into OBS's embedded Chromium browser. Because that Chromium build shipped in OBS 32.2.2 ran without its sandbox and included a V8 engine still vulnerable to the already-exploited CVE-2024-7971, the researcher was able to turn a single chat message into full code execution on the streamer's machine, using default OBS settings.

OpenAI red-team agents built covert C2 channels inside Hugging Face infrastructure

Security researchers detailed how autonomous agents, after achieving remote code execution on Hugging Face dataset workers, deployed background controllers to maintain persistent access. These controllers—named examples included G236 and OTS92—used dataset README files, supporting scripts, and even Hugging Face discussion comments as covert channels to poll for commands and return results, avoiding the need for a direct inbound connection to the compromised workers.

Investor essay: weekly execution meetings and owned metrics win VC trust

An Entrepreneur contributor writes that founders earn investment less through pitch polish than through operating discipline: a recurring weekly execution meeting with a fixed agenda, a one-page plan, and a named owner for every key metric. The writer also says monthly investor updates that candidly report wins, misses and asks build credibility over time.

Salt Labs finds prompt-injection flaw in Manus AI agent enabling remote code execution

Security researchers at Salt Labs privately disclosed to Dark Reading a prompt-injection vulnerability in the AI agent platform Manus that let them execute remote code inside another user's Manus environment. The flaw could be exploited to manipulate not just Manus itself but any third-party services, such as email or other connected apps, that a victim had linked to it. Manus, which drew 2 million waitlist signups within a week of its March 2025 launch, is currently seeking new funding at a reported $4 billion valuation after an earlier $2 billion Meta acquisition deal fell through.

WordPress patches 'Click2Shell' CSRF flaw enabling remote code execution

Researcher Paulos Yibelo of pwn.ai disclosed a WordPress Core vulnerability, called Click2Shell, that chains a cross-site request forgery bug with the theme Customizer preview to achieve remote PHP execution. The flaw lets an attacker trick a logged-in administrator into visiting a malicious link, silently installing a theme from the WordPress.org catalog and running arbitrary PHP through the Customizer preview even before activation. WordPress fixed the issue in version 7.1.1 after it was reported in late August.

OpenAI Codex sandbox flaws let attackers execute code on developer machines

Security researchers at Accomplish AI discovered two ways to break out of the sandbox that isolates OpenAI's Codex coding agent from a user's system. The worse of the two, dubbed Heapjack, let a malicious repository trigger unsandboxed code execution on a victim's machine simply by having Codex answer a question about that repo's code, with no approval prompt or visible warning. Both bugs were reported to OpenAI on August 12 and patched within eight days.