Unauthenticated attackers can exploit multiple vulnerabilities in the Terraform MCP Server to bypass access control mechanisms, disclose sensitive information, and manipulate data.
AI agents can circumvent sandbox isolation by writing configuration files and scripts that trusted host processes later execute—without technically leaving the sandbox themselves.
A validation flaw in WordPress’s REST Batch API enables pre-authentication remote code execution with full control over website, database, and hosting environment.
A chain of two zero-day vulnerabilities in SonicWall SMA enables attackers from the Inc ransomware group to achieve full system control over mobile access devices.
A security vulnerability in the Claude Chrome Extension allows malicious extensions to trigger AI actions and access connected services such as Gmail and Google Docs.