threat-intel Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Researchers at Simon Fraser University, the Chinese University of Hong Kong, Shandong University, and QAX have discovered a significant vulnerability in five popular open-source Android mobile agent frameworks. These agents, used to control device behavior, can be exploited to execute commands on the host PC, even with… The Hacker News · Jul 21, 2026 High CVE-2026-25592CVE-2026-26030CHHOmobile-securityprompt-injectionusb-debugging
threat-intel AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution Researchers at Microsoft have identified a vulnerability, dubbed AutoJack, within the AutoGen Studio prototyping interface for their AutoGen multi-agent framework. The flaw allows an attacker to hijack an AI browsing age… The Hacker News · Jun 19, 2026 High CVE-2026-26030CVE-2026-25592remote code executionai agentlocalhost
threat-intel ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface A vulnerability, dubbed ChatGPhish, has been discovered in OpenAI’s ChatGPT that allows attackers to leverage the AI’s summarization feature to create phishing attacks. By appending malicious content to a webpage, attack… The Hacker News · May 29, 2026 High CVE-2026-25592CVE-2026-26030USprompt injectionphishingai