#enable


Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence

May 15, 2026 // 16:35

Cybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence. The […]

vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution

May 7, 2026 // 10:54

A dozen critical security vulnerabilities have been disclosed in the vm2 Node.js library that could be exploited by bad actors to break out of the […]

Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution

Apr 30, 2026 // 11:42

Google has addressed a maximum severity security flaw in Gemini CLI — the “@google/gemini-cli” npm package and the “google-github-actions/run-gemini-cli” GitHub Actions workflow — that could […]

New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released

Apr 14, 2026 // 19:00

Two high-severity security vulnerabilities have been disclosed in Composer, a package manager for PHP, that, if successfully exploited, could result in arbitrary command execution. The vulnerabilities have been described as […]

Stolen GitHub tokens enable GlassWorm attack. Python repos force-pushed with malware.

Mar 18, 2026 // 13:26

The GlassWorm malware is being exploited in an active attack that uses compromised GitHub tokens to inject malicious code into hundreds of Python software collections. […]