Kaltura Trusted One URL. It Became File Read and Remote Code Execution.

Two unpatched flaws in Kaltura's HTML5 player expose local files and can give unauthenticated attackers code execution as the web-server user.
Vulnerabilities, defensive security, architecture and operational security.

Two unpatched flaws in Kaltura's HTML5 player expose local files and can give unauthenticated attackers code execution as the web-server user.

Linux Foundation's TRACE project does not keep AI agents inside the sandbox. It creates hardware-attested records of what ran, under which policy and which tools were called.

AWS fixed a Strands Agents Tools flaw that let a crafted prompt use the batch tool to bypass human consent and execute Python on the agent host.

AnonyMousKIT combines stolen-device data, phishing pages and low-cost AI voice agents to obtain the credentials needed to disable Activation Lock.

Attackers used npm packages as storage for fake verification pages rendered through trusted mirrors, turning legitimate CDN domains into phishing infrastructure.

Alabama has subpoenaed OpenAI over the Hugging Face agent intrusion, testing whether weak AI evaluation controls can also violate consumer-protection law.

LACMA says a July 2025 network breach exposed identity, financial and medical data. Public notification followed more than 13 months after detection.

SABnzbd 5.1.2 fixes a critical unauthenticated route to code execution, a malicious-download path traversal that can poison trusted job state, and a separate authentication bypass. Internet-facing WebUIs are urgent, but the download-processing flaw can also affect local installations.

Nutex Health has confirmed that an unauthorised party accessed its network and exfiltrated information from company servers. The healthcare operator knows that data left the environment. It does not yet know, or has not publicly disclosed, whether the stolen material…

A distributed denial-of-service attack against infrastructure operated by Digdir’s supplier Vivicta disrupted access to shared digital services used across Norway’s public sector. The incident affected ID-porten and a chain of dependent services, showing how an availability attack against one provider…