Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration

Ravie LakshmananFeb 25, 2026Artificial Intelligence / Vulnerability Cybersecurity researchers have disclosed multiple security vulnerabilities in Anthropic’s Claude Code, an artificial intelligence (AI)-powered coding assistant, that could result in remote code execution and theft of API credentials. “The vulnerabilities exploit various configuration mechanisms, including Hooks, Model Context Protocol (MCP) servers, and environment variables – executing arbitrary […]

Continue Reading

Malicious NuGet Packages Stole ASP.NET Data; npm Package Dropped Malware

Ravie LakshmananFeb 25, 2026Cybersecurity / Malware Cybersecurity researchers have discovered four malicious NuGet packages that are designed to target ASP.NET web application developers to steal sensitive data. The campaign, discovered by Socket, exfiltrates ASP.NET Identity data, including user accounts, role assignments, and permission mappings, as well as manipulates authorization rules to create persistent backdoors in […]

Continue Reading

Manual Processes Are Putting National Security at Risk

Why automating sensitive data transfers is now a mission-critical priority More than half of national security organizations still rely on manual processes to transfer sensitive data, according to The CYBER360: Defending the Digital Battlespace report. This should alarm every defense and government leader because manual handling of sensitive data is not just inefficient, it is […]

Continue Reading

Xiaomi HyperOS 3.1 Leak Reveals iOS Bridge Feature With Support for iPhone and AirPods Integration

Xiaomi may unveil HyperOS 3.1 at Mobile World Congress 2026, according to a new report. The update is rumoured to introduce an iOS Bridge feature designed to improve connectivity between Xiaomi devices and Apple products. Expected features include iPhone call notifications on Xiaomi devices, improved AirPods integration and direct wireless file sharing between platfor…

Continue Reading

SolarWinds Patches 4 Critical Serv-U 15.5 Flaws Allowing Root Code Execution

Ravie LakshmananFeb 25, 2026Vulnerability / Windows Security SolarWinds has released updates to address four critical security flaws in its Serv-U file transfer software that, if successfully exploited, could result in remote code execution. The vulnerabilities, all rated 9.1 on the CVSS scoring system, are listed below – CVE-2025-40538 – A broken access control vulnerability that […]

Continue Reading

CISA Confirms Active Exploitation of FileZen CVE-2026-25108 Vulnerability

Ravie LakshmananFeb 25, 2026Vulnerability / Software Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a recently disclosed vulnerability in FileZen to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-25108 (CVSS v4 score: 8.7), is a case of operating system (OS) command injection that […]

Continue Reading

Head of Amazon’s AGI lab is leaving the company

Amazon logo on brick office building facade with windows, San Francisco, California, Aug. 29, 2025. Smith Collection | Gado | Archive Photos | Getty Images The head of Amazon’s artificial general intelligence lab is leaving the company less than two years after joining through a so-called acqui-hire deal of his startup Adept. David Luan announced […]

Continue Reading

Workday stock sinks on weak revenue guidance

Aneel Bhusri, co-founder of Workday, speaks at the Workday Charity Classic on the Stanford University golf course in Stanford, California, on Aug. 28, 2024. David Paul Morris | Bloomberg | Getty Images Workday shares fell 10% in extended trading on Tuesday after the human resources and finance software maker reported light quarterly guidance. Here’s how […]

Continue Reading