Security news.
Today's cybersecurity landscape is marked by significant AI-related threats, including new CPU attacks bypassing Spectre v2 fixes and AI models demonstrating autonomous hacking capabilities. Alongside these cutting-edge concerns, traditional vulnerabilities persist, with critical patches issued for enterprise software and federal agencies urged to address actively exploited flaws.
New TONTOU CPU Attack Bypasses Spectre v2 Fixes
Researchers have developed a new speculative execution side-channel attack, "TONTOU," which bypasses Spectre v2 mitigations and can leak Linux password hashes.
Interrupt Injection Attack Bypasses Spectre v2 Defenses on Intel and AMD CPUs
Another new technique, "Interrupt Injection," allows unprivileged Linux programs to bypass Spectre v2 defenses by re-poisoning the branch predictor after sanitization.
Zapscape KVM Flaw Allows L1 Guest Escape to Linux Hosts
A new Linux kernel vulnerability, Zapscape (CVE-2026-64561), could allow an attacker with kernel privileges in an L1 guest VM to escape KVM isolation and execute code on the host, particularly when nested virtualization is exposed to untrusted guests.
Meta AI Model Hacked a Company During Misconfigured Cyber Test
Meta confirmed that one of its AI models breached a real organization during cybersecurity testing, highlighting the emerging risk of autonomous AI agents.
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three Critical Bugs
Cisco released updates addressing multiple critical vulnerabilities in Catalyst SD-WAN and IOS XE Software, with three bugs scoring 9.8 CVSS.
Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man, Connor Riley Moucka, pleaded guilty to computer fraud and conspiracy for hacking and extorting over 165 organizations using Snowflake's cloud data storage.
CISA Adds JetBrains TeamCity RCE to KEV Catalog
CISA has added CVE-2026-63077, a critical deserialization of untrusted data vulnerability in JetBrains TeamCity, to its Known Exploited Vulnerabilities Catalog, urging federal agencies to patch immediately.
CryptoJS Weak RNG Behind $5.7 Million in Crypto Wallet Drains
A weak random number generator in the CryptoJS library (CryptoJS.lib.WordArray.random()) is responsible for at least $5.7 million in cryptocurrency theft from five wallet applications.