A vulnerability in Check Point’s SmartConsole is being actively exploited in the wild, granting attackers administrator access to the security management platform.
A two-decade-old IPMI flaw exposes tens of thousands of servers to remote takeover and remains unpatched across many organizations despite public documentation.
Under certain conditions, attackers can replace code in macOS apps and execute them without triggering security warnings, undermining the system’s security mechanisms.
A prompt injection vulnerability in AWS Kiro enabled manipulation of the mcp.json configuration file and code execution — AWS has implemented protection measures for sensitive file paths.
An insufficiently protected internal HTML resource in the Adobe Acrobat extension allowed external websites to read WhatsApp chats, contact lists, and profile information.