Tag

Security Flaw

All articles tagged with #security flaw

Major React Native Security Flaws Endanger Millions of Developers
security3 months ago

Major React Native Security Flaws Endanger Millions of Developers

A critical security vulnerability in the '@react-native-community/cli' npm package, affecting millions of developers, allowed remote attackers to execute arbitrary OS commands via the Metro development server. The flaw, tracked as CVE-2025-11953 with a CVSS score of 9.8, has been patched in version 20.0.0, highlighting the importance of security scanning in the software supply chain.

Partiful Did Not Remove GPS Data from User Photos, Exclusive
technology4 months ago

Partiful Did Not Remove GPS Data from User Photos, Exclusive

The social event app Partiful was found to be storing user-uploaded photos with embedded GPS location data, posing privacy risks. After TechCrunch revealed the security flaw, Partiful fixed the issue by removing metadata from existing photos and announced ongoing security reviews. The incident highlights the importance of proper data handling and security practices in social apps.

Neon App's Call Recording Boom Sparks Privacy and Ethical Concerns
technology5 months ago

Neon App's Call Recording Boom Sparks Privacy and Ethical Concerns

The Neon app, a popular call-recording platform that paid users for their data, has been taken offline after a security flaw exposed users' phone numbers, call recordings, and transcripts, raising privacy concerns. The app's servers failed to prevent unauthorized access to user data, prompting the developer to shut down the service temporarily. The incident highlights ongoing issues with app security and oversight in app marketplaces.

Critical Microsoft Entra ID Flaw Poses Global Security Risk
technology5 months ago

Critical Microsoft Entra ID Flaw Poses Global Security Risk

A critical security flaw in Microsoft Entra ID, involving undocumented 'actor tokens' and a vulnerability in the Azure AD Graph API, could have allowed attackers to hijack any company's tenant and gain full administrative access without detection. The issue was discovered by security researcher Dirk-jan Mollema and has since been patched by Microsoft.

Samsung Releases Urgent Security Update to Fix Zero-Day Vulnerability
technology5 months ago

Samsung Releases Urgent Security Update to Fix Zero-Day Vulnerability

Samsung has patched a zero-day security vulnerability in its devices that was exploited to remotely plant malicious code, affecting phones running Android 13 to 16. The flaw was reported by Meta and WhatsApp, and the attack is part of a broader trend of spyware campaigns targeting mobile users. The company did not specify affected models, and the origin of the hacking remains unclear.

Critical Security Flaws in Password Managers Enable Data Theft
technology6 months ago

Critical Security Flaws in Password Managers Enable Data Theft

Several top password managers, including 1Password, Bitwarden, and LastPass, have been found vulnerable to a clickjacking flaw that allows hackers to steal login credentials, 2FA codes, and credit card information by overlaying invisible HTML elements, with all tested managers susceptible to at least one attack method. Users are advised to update their software and disable autofill until patches are released.

Critical WinRAR Vulnerability Used in Malware and Phishing Attacks
technology6 months ago

Critical WinRAR Vulnerability Used in Malware and Phishing Attacks

A critical security vulnerability in Windows WinRAR (CVE-2025-8088) allows attackers to craft malicious archive files that can place malware in system folders, including startup directories, leading to automatic execution of malicious code at startup. The flaw has been exploited in phishing campaigns by the RomCom cyber-espionage group. Users are urged to update to WinRAR version 7.13 Final manually to patch the vulnerability and enhance security.

Microsoft Discloses Critical Exchange Server Vulnerability in Hybrid Setups
security6 months ago

Microsoft Discloses Critical Exchange Server Vulnerability in Hybrid Setups

Microsoft disclosed a high-severity vulnerability in on-premise Exchange Server (CVE-2025-53786) that could allow attackers with admin access to escalate privileges in connected cloud environments, especially in hybrid setups. The flaw, which shares a service principal with Exchange Online, poses risks of undetectable privilege escalation and identity compromise if unpatched. Microsoft recommends applying the latest hotfix, reviewing security configurations, and resetting service principal keys if no longer used. CISA also warns about related malware exploiting recent SharePoint flaws and advises disconnecting outdated or end-of-life Exchange and SharePoint servers from the internet.

Microsoft's AI Web Project Faces Security Flaws
technology6 months ago

Microsoft's AI Web Project Faces Security Flaws

Researchers discovered a critical security flaw in Microsoft's new NLWeb protocol, which allows remote reading of sensitive files, including API keys, due to a path traversal vulnerability. Microsoft patched the issue but has not issued a CVE, raising concerns about security oversight in AI-related protocols. The flaw could have severe consequences for AI agents relying on exposed API keys, emphasizing the need for careful security practices in deploying new AI features.

Vulnerabilities in Cursor IDE's MCP and AI Coding Tools Pose RCE and Supply Chain Risks
technology6 months ago

Vulnerabilities in Cursor IDE's MCP and AI Coding Tools Pose RCE and Supply Chain Risks

A security vulnerability in Cursor IDE's Model Context Protocol (MCP) allows attackers to silently modify trusted configurations to execute arbitrary commands, leading to persistent remote code execution. The flaw stems from the IDE's trust model, which only prompts for approval once, enabling malicious modifications to go unnoticed and be re-executed every time a project is opened or synchronized. The issue was responsibly disclosed and addressed in Cursor version 1.3, with recommendations to update to the latest version to mitigate risks.