ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do.

Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort needed to cause damage.

Nothing here needs

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Microsoft Defender’s Own Driver Can Be Weaponized to Delete Security Software at Boot

Microsoft Defender’s Own Driver Can Be Weaponized to Delete Security Software at Boot Check Point Research has disclosed a technique that uses Microsoft Defender’s own legitimately signed boot-time remediation driver

AI companies leak data to advertisers [pdf]

AI companies leak data to advertisers [pdf] Source: Hacker News

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT)