Security news.
Today's security brief highlights critical vulnerabilities, active exploitation, and significant legal actions against cybercriminals. AI-related risks, including zero-click browser hijacking and token jacking, continue to be a prominent theme, alongside important patches from major vendors like Cisco and JetBrains.
CISA Flags TeamCity RCE Flaw (CVE-2026-63077) Under Active Exploitation
CISA has added a critical JetBrains TeamCity vulnerability (CVE-2026-63077) to its Known Exploited Vulnerabilities Catalog, warning of active exploitation for remote code execution.
Zero-Click AI Browser Hacking Affects Claude and ChatGPT
Researchers uncovered unpatched zero-click vulnerabilities allowing threat actors to hijack AI browsers like Claude and ChatGPT Atlas through malicious emails and X posts.
CryptoJS Weak RNG Leads to $5.7 Million in Crypto Wallet Drains
A weak random number generator in the 12-year-old CryptoJS library, specifically `CryptoJS.lib.WordArray.random()`, has been linked to over $5.7 million in crypto wallet drains due to insufficient entropy for generating recovery phrases.
Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses
A security flaw in Apple's iCloud Private Relay, introduced with iOS 15, can potentially expose users' real IP addresses through WebKit proxy bypasses, despite its dual-hop architecture designed for privacy.
Token Jacking: Cybercriminals Stealing AI Resources
Attackers are exploiting vulnerabilities to hijack AI tokens and developer API keys, fueling gray market transfer stations and stealing AI resources.
Attackers Compile 'khunt' Toolkit Inside Oracle for Windows SYSTEM Access
Threat actors exploited a SQL injection vulnerability in a public-facing web application to breach an Oracle database and compile the "khunt" post-exploitation toolkit directly within the database engine, achieving Windows SYSTEM access.
Ransom Cartel Mastermind Sentenced to 16 Years in Prison
Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware-as-a-service operation, has been sentenced to 16 years in prison for his involvement in attacks against at least 18 companies.
Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities
Cisco has released patches for two dozen vulnerabilities across its SD-WAN, IOS XE, and FMC products, including a critical bug with public proof-of-concept code.