Nearly a dozen vulnerable UEFI Shim bootloaders remained trusted for years because revocation mechanisms were not updated in a timely manner, creating a direct path to bypassing Secure Boot.
Malicious browser extensions can leverage Claude Tasks in Chrome to access Gmail, Docs, and Calendar, but already require script execution rights on claude.ai.
A critical vulnerability in Writer AI enabled unauthorized access to session tokens across tenant boundaries, could be triggered via a one-click exploit, and has since been patched.
An anonymous security researcher has disclosed 24 zero-day vulnerabilities in open-source projects including PHP and RustDesk using AI-assisted analysis.