#commands


Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

Sep 22, 2026 // 19:47

A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary […]

Researchers escape OpenAI Codex sandbox to run commands on host

Sep 20, 2026 // 15:16

Security researchers found two ways out of the OpenAI Codex sandbox, one of them capable of running commands on a developer’s machine from Codex’s most […]

GiveWP WordPress donation plugin flaw lets hackers execute server commands

Aug 28, 2026 // 21:37

A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. The security issue is […]

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

Aug 25, 2026 // 15:48

Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in […]

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

Aug 25, 2026 // 14:39

Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access […]

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

Aug 20, 2026 // 14:14

Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL’s open-source AMMOS Instrument Toolkit, that allow an […]

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

Aug 11, 2026 // 21:46

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT […]

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

Aug 5, 2026 // 19:06

Two security flaws in Paperclip could let attackers execute commands on a network server or a developer’s computer. Paperclip is an open-source control plane for […]

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

Aug 5, 2026 // 19:05

Two security flaws in Paperclip could let attackers execute commands on a network server or a developer’s computer. Paperclip is an open-source control plane for […]

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Jul 31, 2026 // 14:27

Palo Alto Networks’ Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial […]

1 2 3 Next