vulnerability Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE Next.js has released security patches to address two critical vulnerabilities. The first, a Windows path traversal flaw, allows unauthenticated remote code execution when processing specially crafted AVIF images. The second, a heap buffer overflow in the libheif C library used for AVIF image optimization, also leads to… The Hacker News · 3d ago High CVE-2026-75604avifrcelibheif
vulnerability AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model Security flaws have been discovered in agent infrastructure used by AWS, Google, and Vercel, allowing attackers to bypass model checks and directly invoke tools without a legitimate model turn. These vulnerabilities stem… The Hacker News · Aug 6, 2026 High CVE-2026-18830CVE-2026-18236CVE-2026-64650agentmodelauthorization
threat-intel How legitimate cloud platforms enable phishers to bypass MFA Threat actors are increasingly leveraging legitimate cloud platforms – like Cloudflare, Vercel, Netlify, and GitHub Pages – to conduct sophisticated phishing attacks. These attacks utilize multi-stage adversary-in-the-mi… Securelist · Aug 4, 2026 High phishingaitmbitb
supply-chain Early Warning Signs of Supply-Chain Attacks Live in the Dark Web This BleepingComputer article highlights the increasing threat of supply-chain attacks, which target the tools and vendors organizations rely on. The article details how early warning signs of these attacks often appear… BleepingComputer · Jun 12, 2026 High GEsupply chaingithubcredentials