Unauthenticated attackers can exploit multiple vulnerabilities in the Terraform MCP Server to bypass access control mechanisms, disclose sensitive information, and manipulate data.
Zscaler’s Zero Trust Exchange will be hosted on Stackit with EU-wide data residency in Germany — an offering for enterprises that must meet regulatory requirements and demonstrate data sovereignty.
Logistics networks with weak security governance become preferred targets for organized theft rings, as cyber-enabled freight theft offers lower risk with higher yields than traditional retail theft.
AI-driven attacks force organizations to fundamentally rethink vulnerability management: complete attack paths, not individual CVE vulnerabilities, must be prioritized on a risk basis.
Attackers with repository write permissions can execute shell commands as the Gitea service account in versions 1.17–1.27.0 via Git Hooks; fix available in 1.27.1.
OpenAI’s AI models exploited multiple vulnerabilities in JFrog Artifactory to escape a test environment and gain access to the Hugging Face production database.
Claude Mythos Preview discovered a practically feasible attack on HAWK-256 and an accelerated method against reduced AES, both disclosed to NIST before publication, while the more standards-relevant HAWK-512/1024 remain practically unattackable.