#web


AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

Jul 21, 2026 // 19:10

Hidden text on a web page was enough to make Kiro, AWS’s agentic coding IDE, rewrite its own configuration file and run an attacker’s code […]

Zimbra urges customers to patch critical web client XSS flaw

Jul 10, 2026 // 16:56

The Zimbra security team urged customers to patch a critical vulnerability affecting the Classic Web Client used to access the Zimbra Collaboration suite. Zimbra is […]

Fake Perplexity extension on Chrome Web Store tracked searches

Jun 30, 2026 // 23:40

A malicious extension in the Chrome Web Store is masquerading as the Perplexity AI answer engine, intercepting search traffic and collecting browsing information. Called “Search […]

CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue

Jun 26, 2026 // 15:38

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise […]

AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution

Jun 19, 2026 // 19:09

Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution. Steer the agent […]

Early Warning Signs of Supply-Chain Attacks Live in the Dark Web

Jun 12, 2026 // 17:16

Supply-chain attacks are usually discussed after they become visible: a malicious package, a compromised software update, a malicious extension, or a breach involving a trusted […]

Dark web Nemesis Market vendor gets 26 years for selling drugs

Jun 5, 2026 // 23:57

A California man was sentenced to more than 26 years in federal prison for trafficking fentanyl and methamphetamine through Nemesis Market, one of the world’s […]

New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework

Jun 5, 2026 // 15:36

Cybersecurity researchers have discovered a previously unreported threat cluster dubbed OP-512 that has been observed targeting Microsoft Internet Information Services (IIS) servers to deploy a […]

New ‘HTTP/2 Bomb’ DoS attack crashes web servers in under a minute

Jun 4, 2026 // 00:37

A new denial-of-service (DoS) attack dubbed HTTP/2 Bomb can be launched from a single machine to take down web servers within seconds. The technique works […]

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

May 29, 2026 // 21:09

Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant’s implicit trust in Markdown links and images […]