The Repository Was Data. Amazon Kiro Treated It as Instructions.

A crafted workspace could steer Amazon Kiro into reading local data and triggering its transmission without a malicious user prompt. Amazon fixed the issue in Kiro IDE 0.8.140.

A crafted workspace could steer Amazon Kiro into reading local data and triggering its transmission without a malicious user prompt. Amazon fixed the issue in Kiro IDE 0.8.140.

A cybersecurity incident disrupted Boston Scientific's global operations and business applications used to process and ship orders. The company has not provided a restoration timetable.

Wordfence's Argus found and reproduced a six-step unauthenticated RCE chain in Avada in about two hours. Avada 7.16.1 and Fusion Builder 3.16.1 fix it.

NVIDIA fixed 18 NemoClaw and OpenShell vulnerabilities, including two network-reachable 9.9 flaws that can escape the sandbox. OpenShell 0.0.34 and specific NemoClaw commits contain the fixes.

GPUThor defeats ECC on four NVIDIA Ampere workstation GPUs, causes resets and escalates an unprivileged CUDA program to host root. NVIDIA now recommends ECC plus verified IOMMU isolation.

Ubiquiti Bulletin 067 fixes 22 vulnerabilities across UniFi. Three unauthenticated flaws score 10.0, while the wider set reaches network, access, video, voice and appliance trust boundaries.

QTFY combined more than 200 exploits, millions of automated scanning tasks and a distributed edge-device proxy network into a reusable platform for China-linked cyber operations.

A US national-emergency order treats power-grid security as a hardware, firmware, maintenance and remote-access supply-chain problem.

CISA says attackers targeted more than 100 internet-exposed water systems, often reaching PLCs through cellular modems.

Google patched CVE-2026-85046 in Chrome 152.0.7977.82/.83 after confirming an exploit in the wild. CISA set a federal deadline of 18 September.