Security researchers demonstrated manipulation of macOS apps through local package tampering without Gatekeeper blocking it, but Apple does not classify this as a security vulnerability.
The wp2shell core vulnerability in WordPress 6.9 and 7.0 enables code execution through anonymous HTTP requests and has been patched by security updates 6.9.5 and 7.0.2 with forced auto-updates.
An unpatched vulnerability in Cursor enables attackers to execute arbitrary malicious code when a developer opens a prepared repository with a manipulated git.exe.
GuardFall exploits decades-old Bash techniques such as quoting tricks and environment variables to bypass security filters and execute arbitrary commands in AI agents.